
Role Overview:
Conduct risk-based IT audits covering cybersecurity, information security, IT general controls (ITGCs), applications, infrastructure, cloud environments, and technology governance. Evaluate the effectiveness of controls, identify risks, and recommend improvements to strengthen the organization's control environment.
Role & Responsibilities:
- Plan and execute IT audits covering cybersecurity, information security, IT general controls (ITGC), applications, infrastructure, cloud environments, and technology.
- Review ITGCs including access management, change management, IT operations, backup & recovery, and incident management.
- Assess information security controls, cyber resilience, vulnerability management, and cloud security.
- Evaluate compliance with frameworks such as ISO 27001, NIST, COBIT, and regulatory requirements.
- Review application controls and technology project governance.
- Identify control gaps, document findings, and track remediation.
- Prepare audit reports and track closure of audit observations.
- Coordinate with business, technology, and external/regulatory auditors.
Preferred Candidate Profile:
- CA / MBA / BE / B.Tech / MCA or equivalent.
- Preferred certifications: CISA, CISSP, CISM, CRISC, ISO 27001 Lead Auditor.
- 4 to 8 years of experience in IT Audit, Information Security Audit, Cybersecurity Audit, or Technology Risk within BFSI/NBFC/HFC.
- Strong knowledge of ITGC, cybersecurity, digital lending systems, and regulatory compliance.
- Exposure to COBIT, ISO 27001, cloud/security reviews, and data analytics tools preferred.
Didn’t find the job appropriate? Report this Job