Information Systems Department Advisory Board
Michael Nyman
Membership Information:
Member Since: 2008Employment:
Job Title: Senior Manager, CyberSecurity Governance, Risk, and ComplianceCompany: Avnet
Biography:
I bring 20+ years of IT audit, governance, risk, and compliance leadership to this board, with a career that spans Big 4 public accounting and top-tier professional services before moving into Fortune 500 corporate GRC. My career began at Ernst & Young, where I served up to Senior Manager in the Technology and Security Risk Services practice across the Phoenix and Las Vegas markets. I directed SOX ITGC programs for publicly traded companies, managed 15+ simultaneous IT control programs, and advised CIOs and CFOs on audit strategy and how to reduce control exceptions before external auditors arrived. From EY, I joined CliftonLarsonAllen (CLA), where I spent 17 years leading the Business Risk Services practice in the Phoenix market. As Director with signing authority, I signed 30+ SOC 1 and SOC 2 reports annually, served as an appointed AICPA SOC Peer Reviewer, and led control readiness assessments against SOC, SOX, NIST, and ISO frameworks for clients across industries. I built and mentored teams of audit professionals, developed firmwide SOC methodology, and briefed audit committees and executive leadership regularly. Today I serve as Cybersecurity Senior Manager, GRC at Avnet, a Fortune 500 global technology distributor operating in more than 125 countries. I own the company’s governance, risk, and compliance program, with responsibility for CMMC Level 2 sustainment and ISO 27001 compliance, while building the internal control and continuous monitoring infrastructure that scales with Avnet’s global footprint. I hold five active credentials: CPA (Arizona), CISA, CRISC, CISSP, and CITP. Both of my degrees come from BYU: a Bachelor of Science in Accounting and a Master of Accountancy with an Information Systems emphasis. The IS program gave me the technical grounding my entire career has been built on, from ITGC auditing at EY to SOC reporting at CLA to the GRC program I am building at Avnet today. I serve on this board because students in BYU’s information systems program are well positioned for careers in audit, GRC, and cybersecurity leadership; and most of them do not know it yet. Twenty years of leading compliance programs across industries has taught me what employers are actually looking for and what students need to compete for those roles. Bringing that perspective back to the program that started my career is not optional for me. It is something I owe.