IT Auditor & Cybersecurity Consultant
Aniket Walia

Aniket Walia

CISSP  ·  Toronto, Canada

IT Auditor and Cybersecurity Consultant with over 7 years delivering risk, governance, and compliance solutions for financial services, healthcare, aerospace, defense, and public sector clients across North America and Europe. CISSP-certified with expertise in AI Governance, SOX, SOC 2, ITGC/ITAC, cyber risk reporting, and third-party risk management.

7+
Years of Experience
Big 4
KPMG · Deloitte Background
CISSP
ISC2 Certified · 2025
Multi-sector
Finance · Health · Aerospace · Defence

Work Experience

Oct 2025 – Present
Laurentian Bank
Toronto, ON
Senior Auditor, IT
Led audits of AI Governance, 52-109 Financial Certification ITGC testing, SDLC, Business Continuity Planning, and Disaster Recovery exercises by developing audit plans, conducting detailed walkthroughs, evaluating risk exposures, and performing control testing. Delivered insightful audit reports with recommendations to enhance regulatory compliance and improve organizational resilience. Drove issue tracking and remediation efforts by partnering with cross-functional stakeholders to define actionable plans, monitor progress, and report status updates to the Audit Committee, enhancing transparency and accountability in risk remediation. Developed AI-powered control testing templates aligned with IIA standards to automate audit workpapers, improving documentation consistency, reducing manual effort, and increasing overall audit efficiency.
AI Governance52-109 ITGCSDLCBCP/DRIT AuditAI ToolsIIA Standards
Aug 2022 – Oct 2025
KPMG LLP
Toronto, ON
Senior Cybersecurity Consultant, Strategy & Governance
Designed and developed a scalable cyber metric library for first- and second-line technology reporting, aligning metrics with OSFI B-13 guidelines, and built dashboards to visualize risk indicators for quarterly board and committee meetings. Developed enterprise risk management dashboards consolidating Risk Treatment Plans (RTPs) from IA, ORM, ICFR, and RCSA into a single accessible view. Created a data management solution consolidating policies, risks, RCSA and SOX controls, and KRIs aligned with BCBS 239, enabling pre-formed regulatory response packages. Evaluated insider risks using qualitative and quantitative approaches, delivering maturity scores and actionable recommendations. Led strategic transformation of first-line capabilities across risk reporting, control testing, and tech risk training. Established a third-party risk management program including intake forms, SOPs, and governance structures. Automated project workflows using Python, Power Apps, and VBA.
OSFI B-13BCBS 239TPRMPower BIPythonERMInsider RiskRisk Reporting
Dec 2019 – Dec 2020
Deloitte USI
Bangalore, India
Associate Solution Advisor
Led SOX and SOC 2 Type 1 & Type 2 audits for diverse clients across multiple sectors, leveraging expertise in operating systems, databases, firewalls, ERPs, and business processes to ensure regulatory compliance. Managed ITGCs and ITACs in collaboration with senior management to develop detailed audit reports and support risk remediation strategies. Conducted interviews and walkthroughs with key stakeholders to evaluate control design against COBIT, COSO, ISO, and NIST standards and perform control effectiveness testing. Developed detailed audit workpapers documenting findings based on evidence and independent assurance controls, serving as an outsourced IT Internal and External Auditor. Provided recommendations to address identified risks and collaborated on tracking control deficiencies and remediation plans.
SOXSOC 2ITGC/ITACCOBITNISTISO 27001COSO
Apr 2019 – Dec 2019
Deloitte USI
Bangalore, India
SAP Security Consultant
Delivered security role and profile builds in SAP ECC, GRC, and EWM systems aligned with business requirements and organizational security standards. Provided hypercare support by proactively troubleshooting critical issues related to access levels, programs, transactions, and authorization granularity, following the organization's change management process. Maintained overall system security configurations and provisioned critical access for high-privilege IDs including firefighter, SAP*, DDIC, and Debug, while enforcing rigorous SOD checks and approval processes prior to granting access.
SAP GRCSAP ECCIAMSODAccess ControlsChange Management
Jul 2017 – Apr 2019
Deloitte USI
Bangalore, India
Advisory Analyst
Executed multiple assurance and advisory engagements under the guidance of senior managers, adhering to quality standards and firm and regulatory methodologies across varied business processes. Conducted walkthroughs with clients to understand their IT environment and analyzed evidence to ensure completeness and accuracy. Documented control testing reports communicating potential deficiencies and exceptions identified during testing, and provided recommendations to mitigate risks in the system.
AssuranceControl TestingRisk AdvisoryIT Advisory
Apr 2017 – Jul 2017
Infosys
Chandigarh, India
Software Engineer (Apprenticeship)
Contributed to the development of a web application using React, Node.js, and MongoDB, implementing features that improved user experience and reduced bugs. Participated in code reviews and worked with cross-functional teams to design and implement new features, resolving technical issues and improving overall system performance.
ReactNode.jsMongoDBWeb Development

Skills & Capabilities

Frameworks & Compliance
NIST CSF, 800-53, 800-171
COBIT · COSO · ISO 27001
SOC 2 · SOX · PCI-DSS
OSFI B-13, E-21, B-10
BCBS 239
Risk & Governance
Cyber Risk Reporting
Third-Party Risk Management
IT General & Application Controls
Data Governance
Identity & Access Management
Tools & Platforms
SAP GRC · ECC · EWM
Microsoft Purview · Power Apps
Power BI · Tableau
Metasploit · UiPath
MySQL · MongoDB · SAP HANA
Programming & Scripting
Python · R
VBA · UiPath (RPA)
MySQL · Java · C++
React · Node.js · MongoDB

Education & Certifications

Post-Graduate Diploma
Cyber Security
Loyalist College, Toronto
May 2021 – Dec 2022
Post-Graduate Diploma
Business Management (PGDM)
NMIMS Global Access, Bangalore
Sept 2020 – Jul 2021
Bachelor of Engineering
Computer Science
Chandigarh Engineering College
Aug 2013 – Jun 2017
Certification
Agile Project Management
Cybrary
Feb 2023
Certification
Core Java
Society for Promotion of IT in Chandigarh (SPIC)
Sept 2015

Download My Resume

Enter your name and email to get instant access to my full resume — including my experience across KPMG, Deloitte, and Laurentian Bank.

Contact

Whether you're looking to discuss a new opportunity, a consulting engagement, or just want to connect — I'm always open to a conversation.