Free cookie consent management tool by TermsFeed IT - IS Auditor | Antal Tech Jobs
Back to Jobs
3 Weeks ago

IT - IS Auditor

decor
Mumbai, Maharashtra, India
Information Technology
Full-Time
WebileApps (India) Pvt. Ltd. (A KFin Technologies company)

Overview

We are looking for a motivated ITGC & ITAC Audit and Compliance Specialist with 1-5 years of hands on experience in planning, executing, and reporting on IT General Controls (ITGC) and IT Application Controls (ITAC) audits assessing control effectiveness, and ensuring compliance with regulatory, statutory, and industry standards like ISO 27001:2022 NIST, OWASP, DPDPA, HIPPA, etc., This role supports business applications, IT infrastructure ( On premises & Cloud), financial systems, support, and SOC-related functions by implementing risk-based Information Security assessments and ability to recommend remediation measures and industry best practices. Prior exposure to fintech or high-sensitivity data (PII) environments will be a strong advantage.

Responsibilities

  • Perform ITGC audits covering Risk Management, access management, change management, backup & recovery, IT operations, logical security, Incident management, Business Continuity, etc.
  • Execute ITAC audits covering financial and operational systems, including transactional, authorisation, interface, and automated controls.
  • Lead walkthroughs with process stakeholders to identify control gaps, risks, and dependencies.
  • Evaluate the design and operating effectiveness of internal controls.
  • Prepare risk and control matrices, test scripts, control effectiveness reports, and closure evidence.
  • Guide engineering teams on secure coding standards, OWASP Top 10 API security, mobile security and architectural best practices.
  • Help define internal data security guidelines and ensure engineering teams adhere to them.
  • Enforce privacy-by-design principles during feature development.
  • Coordinate with external clients and auditors to ensure smooth execution of external audits.
  • Review cloud deployments for security controls (IAM, KMS, Security Groups, WAF, encryption, API Gateway configurations), SOC, BCP/DR, etc., and adherence to ISO 27001:2022 and Regulatory guidelines.
  • Conduct internal Information and Cyber Security trainings and awareness programs.
  • Conduct periodic control reviews for internal teams and third-party service providers, including vendor and supply chain risks.
  • Perform system access reviews, production movement validation, and user access recertification.
  • Assist in preparing compliance submissions to regulatory bodies.
  • Participate in change advisory board meetings for compliance monitoring.
  • Creation and maintenance of internal Information Security SOPs, Policies, Checklists, and guidelines in line with the ISO 27001:2022 Standard and guide respective teams in understanding these documents.
  • Develop audit plans, control documents, and compliance dashboards.
  • Prepare audit reports with observations, risk ratings, and remediation timelines.
  • Follow-up closure for open observations and validate remediation evidence.
  • Regulatory Alignment & Framework Management.

Ensure Compliance With Frameworks Such As

  • ISO 27001/9001/22301/27701/HIPAA
  • System and Organisation Control (SOC) 1 & 2
  • SEBI Cyber Security & Cyber Resilience Framework
  • SEBI/PFRDA system audit & Adoption of cloud framework guidelines
  • Support external statutory, IT, and financial audits.

Requirements

  • Awareness of regulatory expectations in financial/AMC environments (advantage).

Understanding Of ITGC Domains

  • IT INFRA Structure
  • Fare knowledge on Servers & services, Network devices, network topology, communication ports, network architecture, etc.
  • Familiarity with VAPT, threat modelling, and secure coding guidelines.
  • Understanding of authentication frameworks (OAuth2 OIDC, MFA, JWT) and Logical Access Controls
  • Change Management
  • IT Operations Control
  • Incident & Problem Management
  • Logging & Monitoring
  • Understanding of IT Infra & Application Vulnerabilities

Knowledge Of ITAC Related To Financial Systems, Such As

  • Core application controls
  • Familiarity with application workflow, database structures, and logical control flows.

Working Knowledge Of

  • Cloud Security Controls
  • AD/Azure /AWS AD Access Controls
  • Backup & DR Monitoring
  • Evidence gathering and validation

This job was posted by Dileep Teja from WebileApps.

Share job
Similar Jobs
View All
22 Hours ago
Data Engineer
Fintech
  • 3 - 5 Yrs
  • Mumbai
Data Engineer Mumbai | Full-Time  Experience: 3–6 Years Budget: Up to ₹27 LPA Industry: General Insurance (Digital-First Organization) We’re rebuilding insurance from the ground up digital-first, transparent, fast, and fair. No legacy te...
decor
1 Day ago
QA Manager
Fintech
  • 10 - 18 Yrs
  • Pune
Job Description We are seeking an experienced and dynamic QA Manager to lead our quality assurance team in delivering high-quality software products for our organization. The ideal candidate will have a strong background in manual and automation tes...
decor
1 Day ago
Database Administrator (DBA)
Information Technology
  • Bangalore, Karnataka, India
This role is for one of our clients Company Name: cloudtechner Seniority level: Mid-Senior level Min Experience: 5 years Location: Gurgaon, NCR JobType: full-time We are looking for an experienced and detail-oriented Database Administrator (DBA) to ...
decor
1 Day ago
Salesforce Data Engineer
Information Technology
  • Bangalore, Karnataka, India
DescriptionRole Summary :We are seeking a highly skilled Salesforce Data Engineer with deep expertise in the Salesforce platform and a strong focus on building and operating Salesforce Data Cloud (D360) solutions. The ideal candidate will design, int...
decor
1 Day ago
Business Analyst I
Information Technology
  • Bangalore, Karnataka, India
Through our dedicated associates, Conduent delivers mission-critical services and solutions on behalf of Fortune 100 companies and over 500 governments - creating exceptional outcomes for our clients and the millions of people who count on them. You ...
decor
1 Day ago
Associate Software Engineer - Test Automation (Infra)
Information Technology
  • Bangalore, Karnataka, India
Veeva Systems is a mission-driven organization and pioneer in industry cloud, helping life sciences companies bring therapies to patients faster. As one of the fastest-growing SaaS companies in history, we surpassed $2B in revenue in our last fiscal ...
decor
1 Day ago
Interesting Job Opportunity: Data Analyst - SQL/Python
Information Technology
  • Bangalore, Karnataka, India
DescriptionWe are seeking a skilled Data Analyst with strong expertise in Python, SQL, and Excel, coupled with a solid foundation in statistics and a good understanding of retail demand processes.The ideal candidate will be responsible for transformi...
decor
1 Day ago
EY - GDS Consulting - AI and DATA - GCP Data Engineer - Senior
Information Technology
  • Bangalore, Karnataka, India
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even b...
decor

Talk to us

Feel free to call, email, or hit us up on our social media accounts.
Social media