Petaling Jaya, Selangor, Malaysia

Justin Lee

IT auditor bridging technology, risk and assurance.

Monochrome portrait of Justin Lee with an ink collage treatment

IT Audit
& Technology Risk

Computing and Software Systems graduate with a practical focus on cybersecurity, controls and assurance.

IT General Controls*Cybersecurity*Access Management*Technology Risk*COBIT*IT General Controls

01 / Experience

A technical foundation applied through audit, research, mentoring and delivery.

Experience

Oct 2025 — Feb 2026

02

PVH Brands Australia · Contract

Sales Consultant

Built customer understanding and tailored recommendations in a high-tempo retail environment.

Oct 2023 — Dec 2023

03

ASTN · Apprenticeship · Remote

Research Assistant

Analysed potential industry investors, investment trends and market behaviour.

Feb 2023 — Oct 2023

04

University of Melbourne · On-site

Peer Mentor

Supported first-year students through transition guidance, weekly sessions and community-building activities.

Nov 2022 — Feb 2023

05

ELID Sdn Bhd · Internship · Petaling Jaya

Software Developer

Gained hands-on exposure to software development, Azure Cloud Services and database management.

02 / Selected work

Selected anonymised examples of how I approach systems, controls and technology risk.

Control case
studies.

Case 01Access Management Review

Control flow

  1. Request
  2. Approval
  3. Provisioning
  4. Periodic review

Scope

User provisioning, deprovisioning, privileged access and periodic access review.

Approach

  1. Understand process
  2. Identify key controls
  3. Inspect configurations
  4. Test supporting evidence
  5. Document observations

RiskUnauthorised or inappropriate access to systems and data.

Control objectiveAccess is appropriately authorised, provisioned, modified and revoked.

OutputsControl assessment · Process walkthrough · Evidence testing · Risk observations

  • Joiners
  • Movers
  • Leavers
  • Privileged access
Case 02Change Management Review

Control flow

  1. Request
  2. Approval
  3. Testing
  4. Deployment

Scope

Change requests, approvals, testing, deployment and segregation of duties.

Approach

  1. Understand change lifecycle
  2. Identify approval requirements
  3. Review evidence
  4. Trace selected changes
  5. Evaluate control consistency

RiskUnauthorised or inadequately tested changes may affect system integrity or availability.

Control objectiveSystem changes are appropriately authorised, tested and approved before production deployment.

Case 03Computer Operations Review

Control flow

  1. Schedule
  2. Run
  3. Monitor
  4. Resolve

Scope

Job scheduling, batch processing, monitoring, incident handling and operational handovers.

Approach

  1. Map critical operations
  2. Review run procedures
  3. Inspect monitoring evidence
  4. Trace exception handling
  5. Evaluate escalation practices

RiskOperational failures may go undetected or unresolved, affecting system availability and data processing.

Control objectiveComputer operations are scheduled, monitored and escalated in a timely and controlled manner.

  • Batch jobs
  • Monitoring
  • Incidents
  • Escalation
Case 04Third-Party Management Review

Control flow

  1. Assess
  2. Approve
  3. Monitor
  4. Review

Scope

Vendor due diligence, risk assessment, contractual expectations, ongoing monitoring and review.

Approach

  1. Identify in-scope providers
  2. Review risk classification
  3. Inspect due diligence
  4. Assess monitoring evidence
  5. Evaluate review governance

RiskThird parties may introduce unmanaged security, operational or compliance risks.

Control objectiveThird parties are assessed, approved and monitored according to their risk profile.

  • Due diligence
  • Vendor risk
  • Contracts
  • Monitoring

03 / About me

Technical knowledge meets a practical approach to assurance.

I hold a Bachelor of Science in Computing and Software Systems from the University of Melbourne. My technical foundation spans software development, databases, cloud environments and modern development workflows.

That technical background helps me understand how applications, infrastructure, databases and cloud environments operate, and how to evaluate the controls around them.

Technical

  • Python
  • Azure
  • MySQL
  • MongoDB
  • Git
  • Jira

Assurance

  • ITGC
  • Access management
  • Change management
  • Backup & recovery
  • Audit logging
  • Cybersecurity
SoftwareSystemsControlsRiskAssurance

04 / Education & credentials

Continually building capability in technology, audit and cloud.

Education and credentials

Education

University of Melbourne

Bachelor of Science, Computing and Software Systems

Jul 2021 — Sep 2024

Certification

Digital Industry Project

Practera

Issued Nov 2023

05 / Get in touch

Let's talk about
technology risk.

Open to conversations around IT audit, technology risk, cybersecurity and assurance.