Assistant Manager - Cyber Security - IT-GRC

BDO India

Bengaluru Urban

On-site

INR 1,200,000 - 1,800,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

BDO India invites a techno-functional professional to join its Reg-Tech & Cyber Risk practice in Bengaluru. The role intersects technology, regulation, and compliance advisory, reviewing IT systems and RBI directives while advising clients on compliance posture.

You will work on RBI IT governance, outsourcing, PPI/PA/PG guidelines, and related regulatory frameworks. This growth-track role involves direct client interaction and practice development responsibilities.

Qualifications

  • 3-6 years of IT-GRC experience with RBI guidelines and audit exposure.
  • Engineering or commerce degree with strong technology orientation; MBA/MTech is a plus.
  • Certifications: CISA, CISSP, CISM, CompTIA Security+, CRISC, CCSP.
  • Hands-on experience performing ITGC audits, internal IT audits, and SOC report prep.
  • Independent lead on regulatory audits across Banks, NBFCs, Fintechs, Insurance, and brokers.

Responsibilities

  • Execute IT risk and regulatory compliance audits across diverse financial entities.
  • Review IT controls, evidence, test scripts, and audit documentation for quality.
  • Collaborate with client IT teams and CISO to remediate findings and tailor controls.

Skills

IT-GRC
Regulatory audits
CISA/CISSP/CISM
SOC/ITGC audits
Vendor risk mgmt
CISO liaison

Education

BE/BTech/BSc/IT/CS/ECE
B.Com/BBA

Tools

SAP GRC
ServiceNow GRC
Excel

Job description

BDO is a global network of professional services firms with a presence in over 166 countries, revenue of over USD 14 billion, and experience of over 60 years. It's a leading service provider for the mid-markets with client service at its heart.

BDO India Services Private Limited (or BDO India) is the India member firm of BDO International. BDO India offers strategic, operational, accounting and tax, and regulatory advisory & assistance for both domestic and international organizations across a range of industries. BDO India is led by more than 300+ Partners & Directors with a team of over 10,000 professionals operating across 14 cities and 20 offices. We expect to grow sizably in the coming 3-5 years, adding various dimensions to our business and multiplying and increasing the current team size multi-fold

Job Summary:

We are looking for a techno-functional professional to join our Reg-Tech & Cyber Risk practice. The role sits at the intersection of technology, regulation, and compliance advisory — requiring an individual who is equally at home reviewing IT systems and audit artefacts as they are interpreting RBI Master Directions and advising clients on compliance posture.

The successful candidate will work across regulatory compliance engagements covering the RBI IT Governance, Risk, Controls and Assurance (ITGRCA) framework, IT Outsourcing and TPRM norms, Digital Lending guidelines, Payment and Settlement Systems regulations, and frameworks governing Payment Aggregators / Payment Gateways (PA/PG) and Prepaid Payment Instruments (PPI). This is a growth-track role with direct client interaction and practice development responsibilities.

Experience and Qualifications:
  • 3-6 Years of experience in IT-GRC
  • B.E. / B.Tech / B.Sc. (IT/CS/ECE) or B.Com / BBA with strong technology orientation; MBA / M.Tech is an advantage.
  • Certifications considered - CISA, CISSP, CISM, CompTIA Security+, CRISC, CCSP
  • Shall possess hands‑on technical experience executing a diverse range of engagements, including IT General Controls (ITGC) audits, comprehensive Internal Audits of complex IT environments, and the evaluation/preparation of SOC reports.
  • Shall independently drive and execute regulatory compliance audits spanning diverse financial entities, including Banks, NBFCs, Fintechs, Insurance Brokers, and Stockbrokers ensuring adherence to applicable RBI, SEBI, and IRDAI norms.
  • Ability to critically evaluate technical evidence, identify inconsistencies, and detect control circumvention risks across applications, databases, and infrastructure.
  • Shall independently verify that the organization’s IT strategy, policy frameworks, and Board level oversight (ITSC/ACB) strictly align with regulatory Master Directions and maintain a clear, independent reporting line for the CISO.
  • Shall audit the security posture of the extended ecosystem, including third‑party vendors, outsourced IT services.
  • Capability to seamlessly bridge the gap between technical IT controls and broader regulatory expectations, translating complex cyber risks into clear business impacts.
  • Shall validate the operational effectiveness of security monitoring (SOC), VAPT cycles, and BCP/DR readiness to ensure the institution can detect threats in real‑time and recover from system failures within mandatory RPO/RTO targets.
  • Strong understanding of the control environments surrounding complex payment systems, including Payment Aggregators/Payment Gateways (PA/PG), cross‑border data flows, and third‑party payment integrations.
  • Supervise and review the fieldwork of senior associates/consultants, ensuring that audit working papers, test scripts, and documentation meet rigorous qualitative standards.
  • Collaborating with IT process owners to design practical, risk‑mitigating controls and actively tracking remediation plans to closure.
  • Act as a key liaison during external regulatory inspections and statutory audits, facilitating clear communication between technical IT teams, external auditors, and senior management.
Regulatory Knowledge — Essential
  • RBI IT Governance, Risk, Controls and Assurance (ITGRCA) Master Direction
  • RBI Master Direction on IT Outsourcing / Managing Risks in Outsourcing (NBFC / Banks)
  • RBI Digital Lending Guidelines (2022 and subsequent updates)
  • Payment and Settlement Systems (PSS) Act, 2007 and RBI DPSS frameworks
  • Prepaid Payment Instruments (PPI) Master Direction — wallet issuance, interoperability, KYC norms
  • IT General Controls (ITGC) assessment — access management, change management, operations, BCP/DR
  • Application controls review — input validation, processing controls, output reconciliation
  • Cybersecurity frameworks — familiarity with ISO 27001, NIST CSF, CIS Controls
  • Data protection and privacy — DPDP Act 2023 awareness; data classification and handling controls
  • Cloud risk assessment — awareness of shared responsibility models, cloud‑specific regulatory requirements
Tools & Methodology
  • Proficiency in MS Excel (audit/risk workbooks, control matrices, scoring models)
  • MS PowerPoint — client‑facing deliverable and deck preparation
  • Familiarity with GRC tools (e.g., SAP GRC, ServiceNow GRC, or similar) is an advantage
  • Comfort with data analysis and log review as part of IT audit fieldwork
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead GRC Compliance RBI Audit
Lead GRC Compliance RBI Audit

3i Infotech • Navi Mumbai

On-site
INR 2,500,000 - 4,000,000
IT Risk & Compliance Manager
IT Risk & Compliance Manager

TVS Credit Services Ltd • Chennai District

On-site
INR 1,500,000 - 2,000,000
Security Consultant - GRC
Security Consultant - GRC

IBM • Mumbai

On-site
INR 2,400,000 - 3,600,000
Assistant Manager - Technology Risk Assurance
Assistant Manager - Technology Risk Assurance

BDO India • Bengaluru, Chennai District

On-site
INR 1,200,000 - 2,400,000
Senior Manager - Information Security And Governance
Senior Manager - Information Security And Governance

HDB Financial Services Ltd. • Hyderabad

On-site
INR 1,000,000 - 1,500,000
GRC Manager/ GRC Lead
GRC Manager/ GRC Lead

Riskpro India Ventures • Mumbai

On-site
INR 1,000,000 - 1,500,000
GRC Specialist
GRC Specialist

Aviva India • Gurugram District

On-site
INR 2,500,000 - 4,200,000
GRC Analyst
GRC Analyst

Security Brigade • Delhi, Mumbai

Hybrid
INR 60,000 - 80,000
Competitive salary aligned to experience
Hybrid + remote-friendly
Sponsorship for relevant certifications
+2
IT Risk Analyst
IT Risk Analyst

Sayyam Investments Private Limited • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Infosec Analyst
Infosec Analyst

super.money • Bengaluru

On-site
INR 900,000 - 1,500,000
Competitive compensation
Shape GRC for a top UPI company in I