ISMS-IT Audit Director

EY

India

On-site

INR 3,500,000 - 6,500,000

Full time

9 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

EY is seeking a Director ITGC & ISMS in Delhi NCR. The role leads ITGC and ISMS programs, aligning controls with regulatory standards and business goals. You will partner with senior leaders to strengthen governance, manage cyber risks, and drive continuous compliance improvements.

The ideal candidate has 12–18+ years in IT audit, security, risk, and compliance, with 5+ years in leadership, and strong experience in SOX, ISO 27001, and CobIT frameworks.

Qualifications

  • 12-18+ years of experience in IT Audit, ISMS, Governance, Risk, and Compliance.
  • 5+ years in leadership roles managing large ITGC and ISMS programs.
  • Experience with SOX, ISO 27001, and risk-based audit approaches.

Responsibilities

  • Lead enterprise ITGC frameworks, control programs, and testing.
  • Own ISMS governance, ISO 27001 certification, and cert audits.
  • Drive IT risk management and regulatory compliance initiatives.
  • Coordinate with auditors, risk stakeholders, and leaders.
  • Provide strategic direction for information security governance programs.
  • Lead and mentor governance, risk, and compliance teams.
  • Present updates to CIO, CISO, Risk, Legal, and exec committees.

Skills

ITGC
SOX Compliance
ISO 27001 ISMS
InfoSec Governance
IT Risk Mgmt
Cybersecurity Frameworks
COBIT
NIST
Internal Controls Testing
Data Privacy
SAP Security
Cloud Security Governance

Education

Bachelor's in IT/CS/Cybersecurity
Master's preferred

Tools

SAP Security & GRC

Job description

Director ITGC & ISMS (Information Technology General Controls & Information Security Management System)
Job Title

Director – ITGC & ISMS

Location-

Delhi NCR

Experience

12-18+ years in IT Audit, Information Security, Risk Management, Compliance, and Governance with at least 5+ years in leadership roles.

Role Overview

The Director – ITGC & ISMS will lead the organization's Information Technology General Controls (ITGC), Information Security Management System (ISMS), cybersecurity governance, and compliance programs. The role is responsible for establishing and maintaining a robust controls environment that aligns with regulatory requirements, industry standards, and business objectives.

The individual will partner closely with senior business leaders, technology teams, external auditors, and risk stakeholders to strengthen governance, manage cyber risks, and drive continuous compliance improvements across the enterprise.

Key Responsibilities
ITGC Leadership
  • Develop and manage enterprise-wide ITGC frameworks and control programs.
  • Oversee design, implementation, and testing of IT General Controls across key systems and applications.
  • Lead ITGC assessments supporting SOX, internal audits, and external audit requirements.
  • Ensure effective management of:
    • User Access Management
    • Privileged Access Controls
    • Change Management
    • IT Operations Controls
    • Backup & Recovery Controls
    • Interface Monitoring Controls
ISMS Governance
  • Own and maintain the organization's ISMS framework aligned with ISO 27001 standards.
  • Lead ISO 27001 certification, surveillance audits, and recertification activities.
  • Ensure continual improvement of security policies, standards, procedures, and control frameworks.
  • Monitor compliance with security governance requirements across business functions.
Risk Management & Compliance
  • Drive enterprise IT risk management initiatives.
  • Conduct risk assessments and control gap analyses.
  • Ensure compliance with:
    • ISO 27001
    • SOX
    • COBIT
    • NIST
    • GDPR/Data Privacy requirements
    • Industry-specific regulatory frameworks
  • Present key risk indicators and compliance metrics to executive leadership.
Audit & Assurance
  • Serve as the primary point of contact for internal and external auditors.
  • Lead audit planning, execution support, remediation tracking, and closure.
  • Ensure timely resolution of audit findings and control deficiencies.
  • Establish sustainable controls to reduce recurring audit observations.
Security Governance & Strategy
  • Provide strategic direction for information security governance programs.
  • Review and approve security standards and policies.
  • Drive security awareness and compliance initiatives across the organization.
  • Support business transformation projects by embedding security and compliance requirements.
Team Leadership
  • Lead and mentor managers, consultants, and auditors.
  • Build high-performing governance, risk, and compliance teams.
  • Develop talent pipeline and succession planning strategies.
  • Foster a culture of accountability, continuous improvement, and risk awareness.
Stakeholder Management
  • Collaborate with CIO, CISO, Risk, Legal, Compliance, and Business Leaders.
  • Present security, audit, and compliance updates to executive leadership and governance committees.
  • Influence enterprise-wide decisions related to risk management and security investments.
Required Qualifications
  • Bachelor’s degree in information technology, Computer Science, Cybersecurity, or related discipline.
  • Master's degree preferred.
  • 12-18+ years of relevant experience in IT Audit, ISMS, Governance, Risk, and Compliance.
  • Demonstrated experience leading large-scale ITGC and ISMS programs.
Preferred Certifications

One or more of the following:

  • CISA (Certified Information Systems Auditor)
  • CISSP (Certified Information Systems Security Professional)
  • CISM (Certified Information Security Manager)
  • ISO 27001 Lead Implementer
  • ISO 27001 Lead Auditor
  • CRISC (Certified in Risk and Information Systems Control)
  • CGEIT
  • COBIT Certification
Required Skills
Technical Skills
  • IT General Controls (ITGC)
  • SOX Compliance
  • ISO 27001 ISMS
  • Information Security Governance
  • IT Risk Management
  • Cybersecurity Frameworks
  • COBIT
  • NIST
  • Internal Controls Testing
  • Data Privacy & Regulatory Compliance
  • SAP Security & GRC (preferred)
  • Cloud Security Governance (Azure, AWS, GCP)
Leadership Skills
  • Strategic Planning
  • Executive Stakeholder Management
  • Team Leadership
  • Program Management
  • Audit & Compliance Management
  • Risk-Based Decision Making
Key Performance Indicators (KPIs)
  • ITGC testing effectiveness and compliance scores
  • Reduction in audit observations
  • ISO 27001 certification success and audit outcomes
  • Risk remediation closure timelines
  • Compliance maturity improvements
  • Policy adherence and governance metrics
  • Stakeholder satisfaction and regulatory readiness
  • Looking for a Risk Consulting professional, not a core technical or cyber security specialist.
  • Strong experience in Risk & Compliance, Internal Audit, ITGC, ITAC, and SOX engagements is essential.
  • Cyber security exposure is good to have, but not mandatory. Avoid profiles that are heavily focused on cyber security.
  • Candidates should have experience managing General IT Controls (ITGC), IT Application Controls (ITAC), and ERP Pre- and Post-Implementation Reviews.
  • Familiarity with ISO 27001 and ISO 42001 frameworks is preferred.
  • Seeking a Team Manager / People Manager who can act as the right-hand support .
  • Strong client-facing experience is critical, particularly with local/domestic clients across Internal Audit and External Audit engagements.
  • Candidates from Global Capability Centers (GCCs) are not preferred.
  • Profiles focused primarily on Financial Services (FS) or GCC environments should be avoided.
  • Industry candidates with limited consulting or client management exposure may not be ideal.
  • The ideal candidate should have a strong background in:
    • Risk Consulting
    • Governance, Risk & Compliance (GRC)
    • Internal Audit
    • SOX Compliance
    • IT General Controls (ITGC)
    • IT Application Controls (ITAC)
    • ERP Pre & Post Implementation Reviews
    • ISO 27001 / ISO 42001
    • Client Relationship Management
    • Team Leadership and People Management
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Associate Director
Associate Director

Virtuoso Staffing Solutions • Mumbai

On-site
INR 3,150,000 - 3,850,000
Associate Manager Internal Audit - IT
Associate Manager Internal Audit - IT

Shashwath Solution • Pune District

On-site
INR 2,000,000 - 3,500,000
Manager
Manager

Virtuoso Staffing Solutions • Mumbai

On-site
INR 1,500,000 - 2,500,000
Associate Manager Internal Audit - IT
Associate Manager Internal Audit - IT

Shashwath Solution • Dadri

On-site
INR 1,200,000 - 2,400,000
Audit & Compliance Executive
Audit & Compliance Executive

Vouchagram India • New Delhi

On-site
INR 700,000 - 1,100,000
Technical Manager
Technical Manager

Incedo Inc. • Gurugram District

On-site
INR 2,500,000 - 5,000,000
IT Security Compliance and Assurance Manager
IT Security Compliance and Assurance Manager

wk • India

On-site
INR 2,000,000 - 3,600,000
Sr. Analyst I Audit & Compliance
Sr. Analyst I Audit & Compliance

Shashwath Solution • Dadri

On-site
INR 2,400,000 - 3,600,000
Sr. Analyst I Audit & Compliance
Sr. Analyst I Audit & Compliance

Shashwath Solution • Pune District

On-site
INR 1,200,000 - 2,000,000
Hiring For ITGC, TPRM, 2+ years
Hiring For ITGC, TPRM, 2+ years

WNS Holdings • Gurugram District

On-site
INR 2,800,000 - 4,000,000