IT Audit · Risk · Compliance  •  ServiceNow  •  Applied AI

I turn risk, process, and technology into measurable trust.

I'm Pooja Singh — an IT audit & GRC professional who also builds on ServiceNow and works hands-on with AI. I help organizations see their risks clearly, design the controls that matter, and adopt technology — including AI — responsibly and efficiently.

  • CISA — in progress
  • ServiceNow Certified
  • MS, Management Information Systems (STEM)
  • GPA 3.8 / 4.0
Pooja Singh
Open to full-time roles

About

A rare blend: the auditor's rigor, the builder's hands, the AI adopter's curiosity.

I'm pursuing my Master of Science in Management Information Systems (STEM-designated) at the University at Buffalo, with coursework aligned to CISA, CRISC, Generative AI, and Six Sigma. My work sits at the intersection of three disciplines that rarely live in one person.

On the governance side, I run the full risk lifecycle, design and test IT general controls, and report to management and boards. On the build side, I develop on ServiceNow — from business rules to scoped applications and Performance Analytics dashboards. And on the frontier, I engineer prompts, tune LLMs, and assess AI risk from an auditor's perspective.

That combination is what lets me connect strategy, controls, and working software.

Beyond the résumé

A bit about me

Meet me in person and I'm the one laughing loudest and teasing my friends — greeting people like no time has passed, even after years apart. I'm not one for constant texting; I'd rather be fully present than perform online. Above all, I'm a hands-on mom to two boys, running our home largely on my own — and I do it alongside a demanding STEM master's and a job search, with the door always open for friends and a home-cooked feast.

I've also learned what I'm made of the hard way — a serious health scare, my husband's fight with cancer, and rebuilding my life from scratch after moving from India to the U.S. while raising a newborn and mastering an entirely new field. Those seasons didn't break me; they left me steadier and more grateful. It's why I show up for people in their hardest moments — I know how much even a little care can carry you.

Hobbies & interests

Away from the screen, I'm happiest making something with my hands — tending my flowers and succulents, cooking and experimenting until a dish is just right, and losing myself in watercolor, pencil shading, and henna art. I lean proudly into the girly things, too: my own hairstyling, makeup, and nail art — I even do my own waxing and eyebrows, I'm endlessly curious about skincare, and quietly proud of how much I can do myself. My favorite “hobby” lately, though, is simply giving the task in front of me 100% focus — right now that's my CISA prep, worked through domain by domain. Somewhere along the way I started seeing governance in everything: labeling my pantry, running the household “inventory,” even scheduling when I water the plants.

Family & values

Family is my anchor. I come from humble beginnings, and that's given me a deep gratitude for every opportunity and everything new I get to learn. I try to live by a simple compass — gratitude, integrity, self-respect, and respect for anyone working hard to build a life of their own — and when things get tough, patience, perseverance, determination, and faith keep me grounded and hopeful. My greatest joy is watching my two boys learn something new each day, and seeing the best of my husband and me reflected in them.

01

Governance, Risk & Compliance

GRC, IT Risk & Audit

Risk & Controls

  • End-to-end risk lifecycle & risk-matrix scoping
  • Control design & operating-effectiveness testing
  • IT General Controls (ITGC) & change-management audits
  • First line of defense — gap & escalation reduction

Compliance & Assurance

  • SOX & financial-reporting control evaluation
  • SOC 1 / SOC 2 readiness
  • HIPAA · GDPR · PCI-DSS · HITRUST CSF
  • Management & board-level reporting

Process & Efficiency

  • Six Sigma process re-engineering
  • ~25% efficiency gain by shifting work to self-service
  • KPI definition & assurance reporting
  • Data-quality & process-adherence controls
Frameworks & standards I work with
NIST CSFCOSOCOBITITGCSOXSOC 1SOC 2 ITIL v3CIS Top 18HIPAAGDPRPCI-DSSHITRUST
02

Platform Development

ServiceNow Development

ServiceNow Certified, with a focus on IRM / GRC. Currently an R&D Framework Intern at Inmorphis Inc., building proofs-of-concept and process-optimization research for a ServiceNow IRM & GRC engagement.

Configure & Customize

  • Business rules, client scripts & form design
  • ACLs, SLA / OLA, role & group implementation
  • Custom surveys across modules
  • Custom scoped & global applications

Analytics & Reporting

  • Performance Analytics dashboards & widgets
  • Reports & scheduled reports
  • KPI definition & automated stakeholder reporting
  • Server-side & client-side API / scripting

Platform Engineering

  • Plugins — AWA, Coaching, Task Intelligence & more
  • Data archiving to tune heavy-table performance
  • Version upgrades — skip logs to bug remediation
  • Requirements → technical feasibility → delivery
03

Applied Artificial Intelligence

AI Development & Prompt Engineering

I build with LLMs and evaluate them the way an auditor would — testing not just for output quality, but for bias, cultural fit, and hallucination.

Build & Engineer

  • Custom LLM setup with LLM-Anywhere & parameter tuning
  • Prompt engineering & prompt-pattern design
  • Vector analysis & decision-matrix workflows
  • Multi-model AI workflow building

Evaluate & Govern

  • Bias, cultural-fit & hallucination analysis
  • GenAI inherent-risk & control implementation
  • Organizational AI-readiness assessment
  • Responsible-AI adoption guidance

Research

  • "Human–AI Collaboration in Knowledge Work"
  • "LLMs & ChatGPT — an auditor's perspective"
  • GenAI implementation-preparedness case study

Selected Work

Projects, research & case studies

A focused selection of my strongest, most relevant work across GRC & audit, applied AI, and product & process. Where the work is my own, the full PDF is linked; case studies built on copyrighted scenarios are shown as short summaries in my own words.

Human–AI Collaboration in Knowledge Work
cover-human-ai.png
Research Paper

Human–AI Collaboration in Knowledge Work

A research paper on treating AI as a genuine collaborator — not just a tool — in knowledge work, and what that shift means for trust, oversight, and control. (Co-authored.)

LLMs and ChatGPT — an auditor's perspective
cover-llm-auditor.png
Audit × AI

LLMs & ChatGPT: An Auditor's Perspective

An academic analysis of ChatGPT and generative-AI tools through an IT auditor's lens — evidence, governance, and the controls an organization needs before it relies on AI output.

Enterprise Risk Management — PridePoint Bank
cover-pridepoint.png
IT Risk Lifecycle

Enterprise Risk Management — PridePoint Bank

Ran the full IT-risk lifecycle for a mid-sized bank: mapping a two-zone network, identifying and assessing risks against a risk matrix, recommending controls and mitigation, and defining KRIs/KPIs for ongoing monitoring and board reporting.

Adoption of risk frameworks in technology
cover-risk-frameworks.png
Research

Adoption of Risk Frameworks in Technology

Research into how organizations adopt IT-risk frameworks and ITGCs to manage technology-specific risk — comparing frameworks and the trade-offs behind choosing and operationalizing them.

Northstar Smart Living AI concierge
cover-northstar.png
AI Build

Northstar Smart Living — AI Product Concierge

An AI product concierge built as a Streamlit web app — combining Retrieval-Augmented Generation (RAG), ChromaDB, a local Ollama LLM, and a ReAct agent to help customers compare smart-home products and understand policies.

Applied AI labs: LLMs, RAG and agents
cover-ai-labs.png
AI Engineering

Applied AI Labs: LLMs, RAG & Agents

A hands-on lab series building up the modern AI stack — from running local LLMs (Ollama, Open WebUI) to a Python RAG pipeline, and finally an agentic AI app with a ReAct agent and a web front-end.

TripAssist AI startup business plan
cover-tripassist.png
AI × Business

TripAssist AI — Startup Business Plan

A full startup business plan and pitch for an AI travel-planner that builds personalized, budget-friendly trips in minutes — value proposition, market, model, and go-to-market. (Co-authored.)

Support Squad Six Sigma process improvement
cover-support-squad.png
Process · Six Sigma

Support Squad — Six Sigma Process Improvement

A DMAIC Six Sigma project improving a support process end-to-end — defining scope and stakeholders, measuring and analyzing root causes, then implementing and controlling improvements. (Team final project.)

Get in touch

Let's talk about audit, platform, or AI roles.

Open to full-time opportunities in IT Audit & GRC, ServiceNow / IRM, and applied AI. The fastest way to reach me is email or LinkedIn.