John J Puhalla
Senior Manager, IT Internal Audit @MasterBrand, Inc.
Signup · Get unlimited contacts
WORK HISTORY
Senior Manager, IT Internal Audit @MasterBrand, Inc.
Beachwood, OH, US
In my role as Senior Manager, IT Internal Audit at MasterBrand, Inc, I assist in creating an annual audit plan and risk assessment, focusing on technology. I manage department activities, recruitment, training, and performance management of internal audit staff and external audit team. My expertise in Sarbanes-Oxley requirements, COSO framework, ISACA, and IIA Professional Auditing Standards contributes to the success of the department.
EDUCATION
Youngstown State University
BSAS
Youngstown State University
BSBA
SKILLS
ABOUT JOHN J PUHALLA
Dynamic IT Audit and Risk Assurance professional with over 30 years of experience delivering high-quality audit services and advisory support. Proven track record in developing comprehensive risk-based corporate audit plans, conducting assessments of IT risk components in financial audits, and executing IT audits within internal audit outsourcing frameworks. Renowned for providing actionable recommendations that enhance client procedures and mitigate IT-related risks. I was involved with Sarbanes-Oxley (SOx) compliance at the onset of the regulation. I played a key role in the early development and implementation of SOx compliance processes at American Express. As part of the SOx team, I helped design and implement the company\'s framework to comply with the new regulations. I also supported clients across various industries by reviewing and assessing their SOx controls, providing targeted recommendations for improvement. Throughout my internal audit career, I have consistently developed, maintained, and performed comprehensive SOx controls evaluations. I have extensive experience in Statement on Auditing Standards 70 (SAS 70) reporting, having evaluated internal controls over financial reporting (ICOFR) for clients in the Software-as-a-Service (SaaS) industry before ICOFR became a standard practice. As a member of the Pittsburgh Technology Risk Consulting team, I successfully sold and led our first SAS 70 engagement. My role in these engagements continued throughout my time at KPMG, where I provided ICOFR assessments for various clients. As an internal auditor, I transitioned from preparing SAS 70 reports to reviewing those provided by my organizations’ vendors. With the evolution of SAS 70 into Standards for Attestation Engagements (SSAE) 16 and later Service Organization Control (SOC) reports, my responsibilities expanded. In addition to reviewing these reports, I was tasked with developing internal processes and managing relationships with external auditors responsible for SOC engagements.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.