Internal Auditor

Davies Group

Pune District

On-site

INR 600,000 - 1,200,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Hybrid work after probation

Job summary

Davies Group is seeking an experienced Internal Auditor to audit our ISMS and technology controls in Pune. You will conduct technology, information security, and compliance audits, report findings, and collaborate with stakeholders to improve control effectiveness.

Reporting to the Group Security Audit & Assurance Manager, you will lead remediation discussions, prepare audit plans and KPI reporting, and support external ISO 27001 audits while maintaining strong documentation.

Qualifications

  • ISO/IEC 27001:2022 Lead Auditor certification is required.
  • Experience conducting technology, information security, and compliance audits.
  • Strong documentation and stakeholder communication skills.

Responsibilities

  • Conduct technology, information security, cybersecurity, and compliance audits.
  • Lead remediation discussions with stakeholders and guide timely resolutions.
  • Develop audit plans with defined scope and objectives.
  • Collaborate with internal stakeholders to ensure successful audit engagements.
  • Perform remote audits including assessments of physical security controls.
  • Escalate and provide expert guidance on audit findings.
  • Produce high-quality audit documentation and evidence.
  • Prepare and deliver monthly KPI/KRI reporting.
  • Support coordination and delivery of global ISO 27001 external audits.
  • Share best practices and promote continual security improvement.

Skills

ISO 27001
Auditing
Information security
ISMS
Stakeholder management
Documentation
Communication
Risk assessment

Job description

Internal Auditor

Department: Risk and Compliance

Employment Type: Permanent - Full Time

Location: Pune

Reporting To: Alex Murphy

Description

We are seeking an experienced Internal Auditor to support the business in achieving its objectives by conducting audits of our Global Information Security Management System (ISMS). Reporting to the Group Security Audit & Assurance Manager, this role is responsible for performing technology, information security, cybersecurity, and compliance audits to assess the effectiveness of our ISO 27001 controls. To be successful in this role, candidates must demonstrate excellent communication skills, hold ISO 27001 Lead Auditor certification, and possess strong documentation capabilities. The ability to clearly articulate technical concepts to both technical and non-technical stakeholders across the organisation is essential. Familiarity with additional industry standards - such as Cyber Essentials, Cyber Essentials Plus, PCI-DSS, NYDFS 23 NYCRR 500, ISO 42001, CSA, and SOC 2 is highly advantageous. We are looking for individuals with strong interpersonal skills who can build effective working relationships at all levels. The ideal candidate is a collaborative team player - flexible, approachable, and capable of managing multiple workstreams while meeting deadlines and maintaining excellent stakeholder engagement. This is a full‑time, office-based position located in Pune. Hybrid working arrangements may be considered following successful completion of the probation period.

Key Responsibilities
  • Conduct technology, information security, cybersecurity, and compliance audits to assess the design, efficiency, and effectiveness of internal security controls.
  • Lead remediation discussions with stakeholders, ensuring clear guidance and timely resolution of audit findings.
  • Develop audit plans, including scope and objectives, and ensure audit assignments are completed accurately and within agreed timelines.
  • Engage and collaborate with key internal stakeholders, maintaining professionalism to ensure successful delivery of audit engagements.
  • Perform remote auditing activities, including assessments of physical security controls.
  • Serve as an escalation point for internal audit queries, providing clarity and expert guidance.
  • Produce high-quality audit documentation, reports, and supporting evidence.
  • Prepare and deliver monthly KPI/KRI reporting.
  • Support the coordination and delivery of global ISO 27001 external audits.
  • Share best practices and contribute to the promotion of innovation across the security function.
  • Foster a culture of continual improvement across all aspects of security. Demonstrate the company’s core values: We are Dynamic, We are Innovative, We are Connected, and We Succeed Together.
  • Perform additional duties as required to support the wider Information Assurance team.
Skills, Knowledge and Expertise
Skills
  • Exceptional attention to detail, with strong analytical, reporting, and communication capabilities.
  • Clear and confident communicator, able to translate complex security concepts into language suitable for both technical and non-technical audiences.
  • Strong stakeholder management skills with a focus on delivering an excellent customer experience.
  • Proactive, self-motivated problem solver with the ability to work independently and take initiative.
  • Flexible, approachable, and effective in collaborative, fast-paced environments.
  • Results-driven and commercially aware, with the ability to align security activities to business objectives.
Knowledge
  • Strong understanding and practical experience with ISO/IEC 27001:2022, including both audit and implementation activities (implementation is advantageous).
  • Solid knowledge of ISO 31000: Risk Management – Guidelines.
  • Working knowledge of key cybersecurity frameworks such as the NIST Cybersecurity Framework (CSF) and CIS Controls.
  • Familiarity with security governance and compliance practices, including the development and interpretation of policies, standards, and procedures.
  • Good understanding of IT infrastructure, cloud services, business applications, and third-party supplier risk management.
  • Proficient in risk assessment methodologies, including risk identification, analysis, evaluation, and mitigation strategies.
  • Strong understanding of security incident response processes, including escalation, investigation, and reporting.
  • Awareness of relevant regulatory and legal requirements, including:
  • GDPR
  • UK Data Protection Act
  • EU AI Act
  • India Digital Personal Data Protection Act (DPDPA)
Ability
  • Ability to perform information security internal audits and produce clear, accurate, and well-structured audit findings.
  • Collaborative team player, comfortable working alongside cross-functional teams including departments such as IT, Legal, HR, Risk, and Operations.
  • Capable of leading small-scale initiatives and contributing to continual improvement across security and risk audit activities.
  • Quick learner with a strong growth mindset, adaptable, and able to adjust effectively to changing priorities.
  • Strong understanding and practical experience with key information security and cyber risk frameworks, including ISO 27001, ISO 31000, NIST RMF/CSF, and CIS Controls.
  • Proven experience in conducting audits focused on information security and risk management.
  • Excellent English communication skills, both written and verbal, with the ability to convey complex information clearly and effectively.
  • Relevant professional certification, including:
  • ISO/IEC 27001:2022 Lead Auditor
  • A confident, collaborative team player who enjoys audit work and thrives in an environment that focuses on solutions rather than problems.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

InfoSec Executive
InfoSec Executive

Qualitykiosk Technologies • Thane, Mumbai

On-site
INR 1,500,000 - 2,500,000
Sr. Information Security Analyst – ISMS and SOC2 Implementor (Immediate Joiner - Thane Hybrid)
Sr. Information Security Analyst – ISMS and SOC2 Implementor (Immediate Joiner - Thane Hybrid)

Gleren • Thane

On-site
INR 1,200,000 - 1,700,000
Information Security Analyst
Information Security Analyst

ACL Digital • Chennai District, Bengaluru

On-site
INR 600,000 - 900,000
Information Security Analyst
Information Security Analyst

ASSA ABLOY Global Solutions • Chennai District

On-site
INR 900,000 - 1,500,000
CISO - Internal Audit
CISO - Internal Audit

Essar Group • Mumbai

On-site
INR 1,800,000 - 3,200,000
(none)
CISO - Internal Audit
CISO - Internal Audit

Essar Career Site • Mumbai

On-site
INR 2,500,000 - 5,000,000
Cyber Security GRC Consultant @ Mumbai
Cyber Security GRC Consultant @ Mumbai

Quess IT Solutions • Mumbai

On-site
INR 1,600,000 - 2,800,000
Information Security Auditor & Standards Lead
Information Security Auditor & Standards Lead

Bridgesoftsol • India

On-site
INR 1,000,000 - 1,500,000
Manager - Information Security
Manager - Information Security

Ashok Maheshwary & Associates • Gurugram District

Hybrid
INR 2,000,000 - 3,800,000
Manager- ISO 27001 and SOC 2 Audits (FEMALE)
Manager- ISO 27001 and SOC 2 Audits (FEMALE)

HCLTech • Bengaluru

On-site
INR 1,500,000 - 2,000,000