Assistant Manager - Cyber Security - IT-GRC

BDO India

Chennai District

On-site

INR 1,400,000 - 2,400,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

BDO India Services Private Limited is seeking a techno-functional professional to join its Reg-Tech & Cyber Risk practice. The role sits at the intersection of technology, regulation, and compliance advisory — requiring an individual who is equally at home reviewing IT systems and audit artefacts as they are interpreting RBI Master Directions and advising clients on compliance posture.

The successful candidate will work across regulatory compliance engagements covering the RBI IT Governance,

Qualifications

  • 3-6 years of IT-GRC experience with hands-on audits.
  • Experience in ITGC audits and internal IT audits of complex environments.
  • Ability to drive regulatory compliance audits across Banks, NBFCs, Fintechs, Insurance brokers.
  • Knowledge of RBI, SEBI, IRDAI norms and related governance frameworks.
  • Strong analytical skills to map controls to regulatory expectations.

Responsibilities

  • Lead and supervise IT audit fieldwork and test scripts.
  • Evaluate evidence, identify inconsistencies, and assess control effectiveness.
  • Collaborate with process owners to design risk-mitigating controls.
  • Interface with external regulators and clients, presenting findings clearly.

Skills

IT-GRC
ITGC Audits
Regulatory Audits
CISA
CISSP
CISM
CRISC
CCSP

Education

BE/BTech/BSc IT/CS/ECE
B.Com/BBA with tech orientation
MBA/MTech (advantage)

Tools

MS Excel
MS PowerPoint
SAP GRC
ServiceNow GRC

Job description

BDO is a global network of professional services firms with a presence in over 166 countries, revenue of over USD 14 billion, and experience of over 60 years. It's a leading service provider for the mid-markets with client service at its heart.

BDO India Services Private Limited (or BDO India) is the India member firm of BDO International. BDO India offers strategic, operational, accounting and tax, and regulatory advisory & assistance for both domestic and international organizations across a range of industries. BDO India is led by more than 300+ Partners & Directors with a team of over 10,000 professionals operating across 14 cities and 20 offices. We expect to grow sizably in the coming 3-5 years, adding various dimensions to our business and multiplying and increasing the current team size multi-fold

Job Summary:

We are looking for a techno-functional professional to join our Reg-Tech & Cyber Risk practice. The role sits at the intersection of technology, regulation, and compliance advisory — requiring an individual who is equally at home reviewing IT systems and audit artefacts as they are interpreting RBI Master Directions and advising clients on compliance posture.

The successful candidate will work across regulatory compliance engagements covering the RBI IT Governance, Risk, Controls and Assurance (ITGRCA) framework, IT Outsourcing and TPRM norms, Digital Lending guidelines, Payment and Settlement Systems regulations, and frameworks governing Payment Aggregators / Payment Gateways (PA/PG) and Prepaid Payment Instruments (PPI). This is a growth-track role with direct client interaction and practice development responsibilities.

Experience and Qualifications:
  • 3-6 Years of experience in IT-GRC
  • B.E. / B.Tech / B.Sc. (IT/CS/ECE) or B.Com / BBA with strong technology orientation; MBA / M.Tech is an advantage.
  • Certifications considered - CISA, CISSP, CISM, CompTIA Security+, CRISC, CCSP
  • Shall possess hands-on technical experience executing a diverse range of engagements, including IT General Controls (ITGC) audits, comprehensive Internal Audits of complex IT environments, and the evaluation/preparation of SOC reports.
  • Shall independently drive and execute regulatory compliance audits spanning diverse financial entities, including Banks, NBFCs, Fintechs, Insurance Brokers, and Stockbrokers ensuring adherence to applicable RBI, SEBI, and IRDAI norms.
  • Ability to critically evaluate technical evidence, identify inconsistencies, and detect control circumvention risks across applications, databases, and infrastructure.
  • Shall independently verify that the organization’s IT strategy, policy frameworks, and Board level oversight (ITSC/ACB) strictly align with regulatory Master Directions and maintain a clear, independent reporting line for the CISO.
  • Shall audit the security posture of the extended ecosystem, including third-party vendors, outsourced IT services.
  • Capability to seamlessly bridge the gap between technical IT controls and broader regulatory expectations, translating complex cyber risks into clear business impacts.
  • Shall validate the operational effectiveness of security monitoring (SOC), VAPT cycles, and BCP/DR readiness to ensure the institution can detect threats in real-time and recover from system failures within mandatory RPO/RTO targets.
  • Strong understanding of the control environments surrounding complex payment systems, including Payment Aggregators/Payment Gateways (PA/PG), cross-border data flows, and third-party payment integrations.
  • Supervise and review the fieldwork of senior associates/consultants, ensuring that audit working papers, test scripts, and documentation meet rigorous qualitative standards.
  • Collaborating with IT process owners to design practical, risk-mitigating controls and actively tracking remediation plans to closure.
  • Act as a key liaison during external regulatory inspections and statutory audits, facilitating clear communication between technical IT teams, external auditors, and senior management.
Regulatory Knowledge — Essential
  • RBI IT Governance, Risk, Controls and Assurance (ITGRCA) Master Direction
  • RBI Master Direction on IT Outsourcing / Managing Risks in Outsourcing (NBFC / Banks)
  • RBI Digital Lending Guidelines (2022 and subsequent updates)
  • Payment and Settlement Systems (PSS) Act, 2007 and RBI DPSS frameworks
  • Prepaid Payment Instruments (PPI) Master Direction — wallet issuance, interoperability, KYC norms
  • IT General Controls (ITGC) assessment — access management, change management, operations, BCP/DR
  • Application controls review — input validation, processing controls, output reconciliationCybersecurity frameworks — familiarity with ISO 27001, NIST CSF, CIS Controls
  • Data protection and privacy — DPDP Act 2023 awareness; data classification and handling controls
  • Cloud risk assessment — awareness of shared responsibility models, cloud-specific regulatory requirements
Tools & Methodology
  • Proficiency in MS Excel (audit/risk workbooks, control matrices, scoring models)
  • MS PowerPoint — client-facing deliverable and deck preparation
  • Familiarity with GRC tools (e.g., SAP GRC, ServiceNow GRC, or similar) is an advantage
  • Comfort with data analysis and log review as part of IT audit fieldwork
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Assistant Manager - Cyber Security - IT-GRC
Assistant Manager - Cyber Security - IT-GRC

BDO India • Bengaluru Urban

On-site
INR 1,200,000 - 1,800,000
Manager - Cyber Security - IT-GRC
Manager - Cyber Security - IT-GRC

BDO India • Kolkata District

On-site
INR 1,800,000 - 2,400,000
Risk Control and governance- Finance SME
Risk Control and governance- Finance SME

NEC Corporation • Navi Mumbai

On-site
INR 1,900,000 - 3,200,000
IT Risk Control Manager
IT Risk Control Manager

Futops • Mumbai

On-site
INR 1,200,000 - 1,800,000
Business Continuity Manager @ Mumbai
Business Continuity Manager @ Mumbai

Quess IT Solutions • Mumbai

On-site
INR 1,400,000 - 2,000,000
GRC Manager/ GRC Lead
GRC Manager/ GRC Lead

Riskpro India Ventures • Mumbai

On-site
INR 1,000,000 - 1,500,000
GRC - Security Analyst
GRC - Security Analyst

Jobgether • India

Remote
INR 1,200,000 - 1,800,000
Fully remote in India
Full-time employment
Exposure to multiple security framesk—
+2
Assistant Manager - Information Security/ IT GRC
Assistant Manager - Information Security/ IT GRC

KVAT & Co • Mumbai

On-site
INR 1,500,000 - 2,700,000
Assistant Manager - Information Security/ IT GRC
Assistant Manager - Information Security/ IT GRC

KVAT & Co • Thane

On-site
INR 1,200,000 - 1,800,000
IT Risk Analyst
IT Risk Analyst

Sayyam Investments Private Limited • Bengaluru

On-site
INR 1,200,000 - 2,000,000