• File

Марія

IT Auditor

Considering positions:
IT Auditor, Information Technology Auditor, GRC Specialist, IT Risk Analyst
City of residence:
Kyiv
Ready to work:
Remote

Contact information

The job seeker has provided: Phone number

Name, contacts and photo are only available to registered employers. To access the candidates' personal information, log in as an employer or sign up.

Uploaded file

Quick view version

This resume is posted as a file. The quick view option may be worse than the original resume.

Mariia Shukalovych
Kyiv, Ukraine | [open contact info](look above in the "contact info" section) | [open contact info](look above in the "contact info" section) | [open contact info](look above in the "contact info" section)

PROFESSIONAL SUMMARY

IT audit and technology risk professional with 1.5 years at EY (Big Four) and 5 IT audit engagements delivered for clients
in banking, metallurgy and IT. Experienced in IT general controls (ITGC) testing, cybersecurity risk assessments and
compliance reviews under NIST CSF, ISO/IEC 27001, PCAOB standards and SWIFT CSCF. Cybersecurity BSc (2026) and
current MSc student whose AWS, SQL, network and malware analysis skills add technical depth to control testing.

PROFESSIONAL EXPERIENCE

Computer Systems Analyst Mar 2025 – Present
EY (Ernst & Young) Ukraine | Digital Risk, IT Audit | Kyiv, Ukraine
• Delivered 5 IT audit engagements for clients in the banking, metallurgy and IT sectors, covering walkthroughs,
control testing, findings and reporting.
• Tested the design and operating effectiveness of IT general controls (ITGC) across access management, change
management and IT operations, supporting financial statement audits performed under PCAOB standards.
• Assessed cybersecurity posture and IT risks against NIST CSF and ISO/IEC 27001, identifying control gaps and drafting
remediation recommendations.
• Evaluated client controls against the SWIFT Customer Security Controls Framework (CSCF) as part of SWIFT Customer
Security Programme (CSP) assessment work.
• Prepared audit workpapers and analytical reports to tight deadlines, using Excel for data analysis and sampling.
• Worked with client IT and security teams and EY audit teams to obtain evidence and clarify findings.

CORE SKILLS

IT Audit & Assurance: IT general controls (ITGC), access management, change management, IT operations, control
design and operating effectiveness testing, walkthroughs, audit workpapers, findings and reporting
GRC & Risk: IT and cybersecurity risk assessment, security controls evaluation, control gap analysis, compliance reviews
Frameworks & Standards: NIST CSF, NIST SP 800-series, ISO/IEC 27001, PCAOB standards, SWIFT CSCF
Data & Cloud: Microsoft Excel (data analysis), SQL (MySQL), Python (Boto3), AWS EC2, AWS S3, AWS CLI
Security & Systems: Wireshark, malware analysis, reverse engineering, Windows, Linux

EDUCATION

Master of Science in Cybersecurity 2026 – Present
National Technical University of Ukraine “Igor Sikorsky Kyiv Polytechnic Institute”, Kyiv
Bachelor of Science in Cybersecurity 2022 – 2026
National Technical University of Ukraine “Igor Sikorsky Kyiv Polytechnic Institute”, Kyiv

TECHNICAL PROJECTS & ACTIVITIES

• Malware research: analyzed ransomware and trojans, including mechanisms of operation, distribution methods and
protection-bypass techniques.
• Cloud labs: managed AWS EC2 instances with Python (Boto3) and AWS CLI; configured AWS S3 storage management
and access control.
• Capture the Flag (CTF): participant in picoCTF and academic CTF-style challenges.

LANGUAGES

Ukrainian, English

Similar candidates

All similar candidates

Candidates at categories

Candidates by city


Compare your requirements and salary with other companies' jobs: