Сервіс пошуку роботи №1 в Україні
Марія
IT Auditor
- Розглядає посади:
- IT Auditor, Information Technology Auditor, GRC Specialist, IT Risk Analyst
- Місто проживання:
- Київ
- Готовий працювати:
- Дистанційно
Контактна інформація
Шукач вказав: Телефон
Прізвище, контакти та світлина доступні тільки для зареєстрованих роботодавців. Щоб отримати доступ до особистих даних кандидатів, увійдіть як роботодавець або зареєструйтеся.
Отримати контакти цього кандидата можна на сторінці https://www.work.ua/resumes/18552012/
Завантажений файл
Версія для швидкого
перегляду
Це резюме розміщено у вигляді файлу. Ця версія для швидкого перегляду може бути гіршою за оригінал резюме.
Mariia Shukalovych
Kyiv, Ukraine | [відкрити контакти ](див. вище в блоці «контактна інформація») | [відкрити контакти ](див. вище в блоці «контактна інформація») | [відкрити контакти ](див. вище в блоці «контактна інформація»)
PROFESSIONAL SUMMARY
IT audit and technology risk professional with 1.5 years at EY (Big Four) and 5 IT audit engagements delivered for clients
in banking, metallurgy and IT. Experienced in IT general controls (ITGC) testing, cybersecurity risk assessments and
compliance reviews under NIST CSF, ISO/IEC 27001, PCAOB standards and SWIFT CSCF. Cybersecurity BSc (2026) and
current MSc student whose AWS, SQL, network and malware analysis skills add technical depth to control testing.
PROFESSIONAL EXPERIENCE
Computer Systems Analyst Mar 2025 – Present
EY (Ernst & Young) Ukraine | Digital Risk, IT Audit | Kyiv, Ukraine
• Delivered 5 IT audit engagements for clients in the banking, metallurgy and IT sectors, covering walkthroughs,
control testing, findings and reporting.
• Tested the design and operating effectiveness of IT general controls (ITGC) across access management, change
management and IT operations, supporting financial statement audits performed under PCAOB standards.
• Assessed cybersecurity posture and IT risks against NIST CSF and ISO/IEC 27001, identifying control gaps and drafting
remediation recommendations.
• Evaluated client controls against the SWIFT Customer Security Controls Framework (CSCF) as part of SWIFT Customer
Security Programme (CSP) assessment work.
• Prepared audit workpapers and analytical reports to tight deadlines, using Excel for data analysis and sampling.
• Worked with client IT and security teams and EY audit teams to obtain evidence and clarify findings.
CORE SKILLS
IT Audit & Assurance: IT general controls (ITGC), access management, change management, IT operations, control
design and operating effectiveness testing, walkthroughs, audit workpapers, findings and reporting
GRC & Risk: IT and cybersecurity risk assessment, security controls evaluation, control gap analysis, compliance reviews
Frameworks & Standards: NIST CSF, NIST SP 800-series, ISO/IEC 27001, PCAOB standards, SWIFT CSCF
Data & Cloud: Microsoft Excel (data analysis), SQL (MySQL), Python (Boto3), AWS EC2, AWS S3, AWS CLI
Security & Systems: Wireshark, malware analysis, reverse engineering, Windows, Linux
EDUCATION
Master of Science in Cybersecurity 2026 – Present
National Technical University of Ukraine “Igor Sikorsky Kyiv Polytechnic Institute”, Kyiv
Bachelor of Science in Cybersecurity 2022 – 2026
National Technical University of Ukraine “Igor Sikorsky Kyiv Polytechnic Institute”, Kyiv
TECHNICAL PROJECTS & ACTIVITIES
• Malware research: analyzed ransomware and trojans, including mechanisms of operation, distribution methods and
protection-bypass techniques.
• Cloud labs: managed AWS EC2 instances with Python (Boto3) and AWS CLI; configured AWS S3 storage management
and access control.
• Capture the Flag (CTF): participant in picoCTF and academic CTF-style challenges.
LANGUAGES
Ukrainian, English
Kyiv, Ukraine | [
PROFESSIONAL SUMMARY
IT audit and technology risk professional with 1.5 years at EY (Big Four) and 5 IT audit engagements delivered for clients
in banking, metallurgy and IT. Experienced in IT general controls (ITGC) testing, cybersecurity risk assessments and
compliance reviews under NIST CSF, ISO/IEC 27001, PCAOB standards and SWIFT CSCF. Cybersecurity BSc (2026) and
current MSc student whose AWS, SQL, network and malware analysis skills add technical depth to control testing.
PROFESSIONAL EXPERIENCE
Computer Systems Analyst Mar 2025 – Present
EY (Ernst & Young) Ukraine | Digital Risk, IT Audit | Kyiv, Ukraine
• Delivered 5 IT audit engagements for clients in the banking, metallurgy and IT sectors, covering walkthroughs,
control testing, findings and reporting.
• Tested the design and operating effectiveness of IT general controls (ITGC) across access management, change
management and IT operations, supporting financial statement audits performed under PCAOB standards.
• Assessed cybersecurity posture and IT risks against NIST CSF and ISO/IEC 27001, identifying control gaps and drafting
remediation recommendations.
• Evaluated client controls against the SWIFT Customer Security Controls Framework (CSCF) as part of SWIFT Customer
Security Programme (CSP) assessment work.
• Prepared audit workpapers and analytical reports to tight deadlines, using Excel for data analysis and sampling.
• Worked with client IT and security teams and EY audit teams to obtain evidence and clarify findings.
CORE SKILLS
IT Audit & Assurance: IT general controls (ITGC), access management, change management, IT operations, control
design and operating effectiveness testing, walkthroughs, audit workpapers, findings and reporting
GRC & Risk: IT and cybersecurity risk assessment, security controls evaluation, control gap analysis, compliance reviews
Frameworks & Standards: NIST CSF, NIST SP 800-series, ISO/IEC 27001, PCAOB standards, SWIFT CSCF
Data & Cloud: Microsoft Excel (data analysis), SQL (MySQL), Python (Boto3), AWS EC2, AWS S3, AWS CLI
Security & Systems: Wireshark, malware analysis, reverse engineering, Windows, Linux
EDUCATION
Master of Science in Cybersecurity 2026 – Present
National Technical University of Ukraine “Igor Sikorsky Kyiv Polytechnic Institute”, Kyiv
Bachelor of Science in Cybersecurity 2022 – 2026
National Technical University of Ukraine “Igor Sikorsky Kyiv Polytechnic Institute”, Kyiv
TECHNICAL PROJECTS & ACTIVITIES
• Malware research: analyzed ransomware and trojans, including mechanisms of operation, distribution methods and
protection-bypass techniques.
• Cloud labs: managed AWS EC2 instances with Python (Boto3) and AWS CLI; configured AWS S3 storage management
and access control.
• Capture the Flag (CTF): participant in picoCTF and academic CTF-style challenges.
LANGUAGES
Ukrainian, English
Схожі кандидати
-
Аудитор IT
150000 грн, Дистанційно, Київ, Рівне -
Аудитор
15000 грн, Дистанційно -
Аудитор ІТ
Дистанційно, Київ -
Внутрішній аудитор
Дистанційно, Дніпро , ще 5 міст -
Аудитор
Дистанційно, Київ, Львів