IT Audit and Cybersecurity Risk Intern
I am an IT Audit and Cybersecurity Risk Intern with over one year of experience at OakNorth Bank plc, where I developed AI-augmented internal audit tools that cut documentation time by 30% and enhanced quality assurance across our team. I've also contributed to projects like the SOC Automation Playbook, leveraging Microsoft Sentinel and Jira to streamline operations. As I continue to deepen my expertise in IT General Controls testing, I am building toward a future role as a cybersecurity audit leader.
Built an end-to-end SOC automation playbook using Azure Logic Apps, automating incident response and reducing triage time by 90%. Integrated Sentinel with VirusTotal, URLScan, AbuseIPDB, and Jira to automate enrichment and case assignment and decreased Mean Time to Acknowledge from 15+ minutes to under 60 seconds.
Developed an automated workflow using Tines and Elastic SIEM, reducing manual alert analysis time by 95%. Deployed Elastic Agents on AWS-hosted Windows Servers for centralized log forwarding and monitoring. Leveraged ChatGPT API to generate concise, human-readable summaries of 100+ line raw alerts, reducing alert fatigue.
Apr '26 — Present
Contributed to an ISO/IEC 27001:2022 internal audit spanning multiple regional offices, participating in Control Design Assessment (CDA) and Control Effectiveness Testing (CET) across ISO 27001 management system clauses and Annex A controls covering people, physical, HR, and organisational information security domains. Supported IT General Controls (ITGC) testing on technology platform audits, evaluating controls across Identity and Access Management, User Access Reviews, joiner-mover-leaver provisioning, Role-Based Access Control, and Single Sign-On, building working knowledge of IAM audit techniques. Liaised with technology and information security stakeholders to gather evidence, walkthrough controls, and clarify audit observations, supporting timely engagement delivery across concurrent audit workstreams. Collected and reviewed audit evidence, drafted Control Design Assessments (CDA), performed Control Effectiveness Testing (CET), and assisted the Q2 enterprise risk assessment refresh in AuditBoard applying IIA methodology (inspect, observe, inquire, reperform); deliverables passed internal QAIP quality reviews across engagements. Built AI-augmented internal audit tools using Claude and ChatGPT, including a workpaper quality-review assistant and a control-narrative drafting assistant, reducing documentation time and standardising quality assurance across the internal audit team.
Jan '26 — Mar '26
Produced market reports, white papers, and points-of-view on cybersecurity, GRC tooling, and enterprise technology risk, supporting client-facing advisory deliverables for global CXOs. Analysed the enterprise GRC and IAM vendor landscape, benchmarking capabilities across risk register management, control testing automation, audit workflow, and third-party risk platforms. Conducted primary and secondary research through CXO briefings and vendor discussions on risk management, control frameworks (ISO 27001, SOC 2, NIST CSF), and information security control maturity. Researched emerging data privacy and compliance trends (GDPR and evolving regional regulations) to inform advisory guidance on enterprise data protection posture and regulatory readiness. Delivered independent research outputs across multi-geography engagements under tight timelines, sharpening working knowledge of enterprise security procurement and control maturity assessment.
Apr '25 — Oct '25
Monitored security events and analysed alerts in a Security Operations Centre (SOC) environment, performing log correlation, triage, and incident escalation across enterprise Windows and network infrastructure. Investigated security incidents through root-cause analysis aligned to the MITRE ATT&CK framework, drafting incident and remediation reports for control owners and technology stakeholders. Created SOC runbooks and playbooks documenting incident-handling procedures for common attack techniques, supporting analyst onboarding and consistency in alert triage. Supported vulnerability assessment activities using Burp Suite, Nmap, Nessus, and Wireshark, feeding identified weaknesses into risk registers with prioritised remediation recommendations. Gained exposure to internal security audits and gap assessments against ISO 27001, SOC 2, and GDPR requirements, drafting control narratives and supporting remediation tracking.
Bachelor's in Electrical and Electronics Engineering • 2021 -2025
80
Awarded "Best Performer" and Intern-Trainee of the Month (July 2025) for exceptional performance and dedication.
Interested in collaboration or just want to say hello? Feel free to reach out!