IT Auditor

Incred

Navi Mumbai, Mumbai

On-site

INR 900,000 - 1,500,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Incred in Navi Mumbai is seeking an experienced IT Audit professional to lead risk-based audit planning and execution across cybersecurity, ITGCs and application controls. You will design engagement letters, scope, and timelines to ensure clear expectations and regulatory alignment.

The role involves identifying security gaps from VAPT reports, assessing control design and operation, and coordinating RBI, PCI DSS and other framework compliance.

Qualifications

  • Experience in IT audits and cybersecurity assessments.
  • Knowledge of RBI, PCI DSS and other regulatory frameworks.
  • Ability to assess design and operating effectiveness of controls.
  • Strong documentation and communication skills.

Responsibilities

  • Prepare risk-based audit plans aligned with objectives and regulatory expectations.
  • Conduct audits covering cybersecurity, ITGCs, application controls, and technology risks.
  • Identify security gaps from VAPT reports and recommend mitigations.
  • Assess control design and operation through detailed review and analysis.
  • Perform analytical procedures to evaluate risk exposure.
  • Ensure RBI Cybersecurity Guidelines, PCI DSS compliance, and other frameworks.
  • Develop audit documentation and final reports for management.
  • Coordinate with IT, InfoSec and business teams to implement controls.
  • Lead knowledge sharing and security awareness initiatives.

Skills

IT audits
Cybersecurity
ITGCs
Application controls
Analytical skills
Documentation
Communication skills
Stakeholder management

Education

Inter CA/Bachelors degree in IT/CS/Cybersecurity
CISA, CISM, ISO 27001 LA/LI, CEH (advantage)

Job description

Role & responsibilities
Audit Planning & Execution
  • Prepare risk-based audit plans aligned with audit objectives and regulatory expectations.
  • Construct audit-specific engagement letters based on defined audit scopes and timelines.
  • Conduct audits covering cybersecurity, IT general controls, application controls, and technology risks.
Risk Assessment & Control Evaluation
  • Identify security gaps and vulnerabilities Assessment and Penetration Testing (VAPT) reports for critical applications. assess impact and recommend mitigation measures.
  • Assess the design and operating effectiveness of controls through detailed review and analysis
  • Perform analytical procedures to evaluate control effectiveness and risk exposure.
Regulatory & Compliance Oversight
  • Ensure RBI Cybersecurity Guidelines, PCI DSS, and other applicable frameworks.
  • Perform and coordinate KRI submissions to RBI across various risk parameters.
  • Evaluate IT policies, risk management frameworks, and BCP/DRP for adequacy and compliance.
  • Conduct third-party and cloud security assessments, including review of cloud security configurations, encryption, and access controls.
Documentation & Reporting
  • Develop comprehensive documentation for audit procedures and ensure accuracy through cross-referencing of work papers.
  • Create preliminary and final audit reports for circulation to auditees and senior management.
  • Prepare clear, concise audit observations highlighting risks, root causes, and actionable recommendations.
  • Track closure and remediation of audit findings.
Stakeholder Management & Collaboration
  • Facilitate discussions with management and process owners regarding audit observations and corrective actions.
  • Collaborate closely with IT, Information Security, and business teams to implement controls.
  • Facilitate knowledge sharing and mentoring among team members to enhance audit quality.
  • Conduct security awareness programs to strengthen employee understanding of cybersecurity risks and controls.
Key Skills & Competencies
  • Strong understanding of IT audits, cybersecurity, ITGCs, and application controls.
  • Hands‑on experience with audit planning, walkthroughs, IDR management, and documentation.
  • Knowledge of regulatory and industry standards (ISO 27001, RBI, PCI DSS).
  • Strong analytical, documentation, and communication skills.
  • Ability to manage multiple audits and stakeholder expectation
Educational Qualifications
  • Inter CA/Bachelors degree in information technology, Computer Science, Cybersecurity, or related field.
  • Certifications such as CISA, CISM, ISO 27001 LA/LI, CEH will be an added advantage.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Risk Control and governance- Finance SME
Risk Control and governance- Finance SME

NEC Corporation • Navi Mumbai

On-site
INR 1,900,000 - 3,200,000
CISO - Internal Audit
CISO - Internal Audit

Essar Group • Mumbai

On-site
INR 1,800,000 - 3,200,000
(none)
IT Risk Control Manager
IT Risk Control Manager

Futops • Mumbai

On-site
INR 1,200,000 - 1,800,000
Associate Auditor-Cybersecurity-Immediate joiner
Associate Auditor-Cybersecurity-Immediate joiner

Reserve Bank Information Technology • Navi Mumbai

On-site
INR 800,000 - 1,400,000
IT Audit,
IT Audit,

Link Management Solutions Pvt. Ltd • Mumbai Suburban

On-site
INR 800,000 - 1,200,000
Internal Auditor-Information Security/System Audits:Audit & Process_AFL
Internal Auditor-Information Security/System Audits:Audit & Process_AFL

Axis Finance Limited • Navi Mumbai

On-site
INR 600,000 - 900,000
IT Audit Manager
IT Audit Manager

Brain Pool Consultant • Gurugram District

On-site
INR 800,000 - 1,200,000
IT Risk Analyst
IT Risk Analyst

Sayyam Investments Private Limited • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Assistant Manager - Cyber Security - IT-GRC
Assistant Manager - Cyber Security - IT-GRC

BDO India • Bengaluru Urban

On-site
INR 1,200,000 - 1,800,000
IT Audit | Hyderabad | Immediate Joiners
IT Audit | Hyderabad | Immediate Joiners

Deloitte Shared Services India • Hyderabad

Hybrid
INR 900,000 - 1,600,000