# Tristan Jones

**Senior IT Audit & Technology Risk Leader**
AI Governance • Responsible AI • SOX • Cybersecurity • Data Analytics

www.tristanjones.ai | tristan@tristanjones.ai | +1 (919) 703-9040
linkedin.com/in/itauditorjones | U.S. and European Citizen

---

## Summary

IT Audit and Technology Risk leader with 15+ years of experience leading technology audits, strengthening SOX compliance, improving cybersecurity governance, and enhancing internal controls across global financial institutions. Trusted by executive stakeholders to assess technology risk, improve control effectiveness, and deliver practical, business-focused assurance.

Building on that foundation, I specialize in AI Governance and Responsible AI, applying proven audit principles to AI risk, governance frameworks, and automated assurance. I help organizations adopt AI with confidence by making governance practical, transparent, and evidence-based. [View AI Governance Expertise & Evidence](https://www.tristanjones.ai/capabilities-evidence.html).

## Selected Achievements

- Reduced SOX control testing time by **40%** by automating audit testing across 50+ enterprise applications.
- Directed cybersecurity, cloud, and technology audits for Citibank, S&P Global, MUFG, Truist, DTCC, and City National Bank.
- Reduced quality-review cycle time by **30%** through improved evidence standards and control documentation.
- Designed City National Bank's first threat-informed CRI coverage assessment methodology.
- Designed executive dashboards that translated complex technology and cybersecurity risks into actionable reporting.
- Expanded IT Audit expertise into AI Governance by earning the **AAIA** and **AWS AI Practitioner** certifications.

## Experience

### IT Risk Consultant — Robert Half / City National Bank
*Remote (Contract) · May 2026 – June 2026*

- Designed the organization's first threat-informed CRI coverage assessment methodology, enabling reproducible evaluation of institutional controls against regulatory response guidance.
- Established evidence traceability from framework requirement through control analysis, rationale, coverage conclusion, and remediation need.
- Partnered with technology, cybersecurity, and risk stakeholders to identify control gaps, assess risk exposure, and develop remediation priorities aligned with CRI and NIST frameworks.

### Independent AI Governance Research — Self-Employed
*North Carolina · Nov 2024 – Apr 2026*

- Designed an AI-assisted governance assessment methodology for regulated financial institutions.
- Extended assessed control deficiencies into threat-informed risk intelligence, connecting gaps to adversary behaviors, detection logic, and prioritized remediation.
- Earned ISACA AAIA and AWS Certified AI Practitioner credentials.

### Technology Risk & Controls Analyst — MUFG
*Remote, North Carolina · May 2022 – Oct 2024*

- Led design and operating-effectiveness testing for 15–20 technology controls per quarter, conducting stakeholder walkthroughs, evaluating supporting evidence, and documenting control deficiencies.
- Assessed control environments for business units being onboarded or integrated, identifying gaps against enterprise risk and control standards.
- Coached first-line control owners on documentation and evidence standards, reducing quality-review cycle time by 30%.
- Managed assessment scheduling and milestone tracking across concurrent engagements, coordinating with control owners, risk partners, and quality reviewers.

### GRC Test Engineer / Technology Risk Consultant — Truist Financial Corporation
*Remote, North Carolina (Contract) · Apr 2020 – Apr 2021*

- Executed design and operating-effectiveness testing of cybersecurity, technology, and data-protection controls to determine whether controls appropriately mitigated identified business and technology risks.
- Developed and executed control test scripts and maintained traceability in RSA Archer between control requirements, evidence reviewed, exceptions, and conclusions.
- Trained and onboarded a fellow GRC tester on control-testing procedures, Archer documentation standards, and findings development.

### Senior IT Auditor — The Depository Trust & Clearing Corporation (DTCC)
*Newark, NJ · May 2019 – Nov 2019*

- Performed deep-dive assessments of firewalls, routers, proxies, and Unix systems using CIS Benchmarks; led walkthroughs with engineering teams to drive remediation.
- Managed end-to-end audit execution for infrastructure assessments, independently planning scope, coordinating stakeholder interviews, and tracking issues through resolution.

### Cybersecurity Audit Manager — S&P Global
*New York, NY · Dec 2014 – Sep 2017*

- Led cybersecurity audits across global business units, managing audit execution, stakeholder engagement, and executive reporting.
- Led AWS security audits and coordinated global teams to evaluate configurations against AWS Security Best Practices, managing assessment timelines across multiple business units.
- Designed executive dashboards in Tableau translating complex technology and cybersecurity risks into actionable management reporting, and automated compliance-testing workflows.

### Blockchain Consultant — Private
*New York, NY · May 2017 – May 2019*

- Evaluated smart-contract security and key-management approaches for early-stage Ethereum deployments, identifying design flaws and recommending architecture changes.

### Audit Automation Consultant — Citibank
*New York, NY · Oct 2012 – Oct 2014*

- Developed automated analytics to detect orphaned accounts and segregation-of-duties conflicts across 50+ applications, enabling earlier detection of identity-related gaps.
- Enhanced SOX control automation using ACL, reducing testing time by 40% and improving identity-governance visibility.

## Skills

| | |
|---|---|
| **IT Audit & Risk** | ITGC • SOX • IT Control Design & Testing • Control Effectiveness • Regulatory Remediation • COBIT |
| **AI Governance** | Responsible AI • AI Risk • AI Controls • Human Oversight • Governance Operating Models • NIST AI RMF |
| **Cybersecurity** | NIST • ISO 27001 • MITRE ATT&CK • Splunk • CRI • CIS Benchmarks |
| **Data & Automation** | Python • SQL • Excel • Power Automate • Microsoft Lists • Alteryx • Power Query • ACL • Claude Code |
| **Data Analytics & Visualization** | Executive Dashboards • Dashboard Design • Executive Reporting • Data Storytelling • Audit Analytics • Tableau • Power BI |
| **AWS** | EC2, VPC, IAM, Route 53, AWS Amplify, API Gateway, and Bedrock |

## Certifications

| Certification | | Body | ID | Period |
|---|---|---|---|---|
| Certified Information Systems Auditor | CISA | ISACA | #252955101 | 2025 – 2028 |
| Advanced in AI Audit | AAIA | ISACA | #263090511 | 2026 – 2029 |
| AWS Certified AI Practitioner | AIF-C01 | AWS | #521927105 | 2025 – 2028 |
| Certified in Risk and Information Systems Control | CRISC | ISACA | Previously certified | 2010 – 2016 |

## Education

**B.S. in Management Information Systems** — Brigham Young University
