Role & responsibilities
Audit Planning & Execution
- Prepare risk-based audit plans aligned with audit objectives and regulatory expectations.
- Construct audit-specific engagement letters based on defined audit scopes and timelines.
- Conduct audits covering cybersecurity, IT general controls, application controls, and technology risks.
Risk Assessment & Control Evaluation
- Identify security gaps and vulnerabilities Assessment and Penetration Testing (VAPT) reports for critical applications. assess impact and recommend mitigation measures.
- Assess the design and operating effectiveness of controls through detailed review and analysis
- Perform analytical procedures to evaluate control effectiveness and risk exposure.
Regulatory & Compliance Oversight
- Ensure RBI Cybersecurity Guidelines, PCI DSS, and other applicable frameworks.
- Perform and coordinate KRI submissions to RBI across various risk parameters.
- Evaluate IT policies, risk management frameworks, and BCP/DRP for adequacy and compliance.
- Conduct third-party and cloud security assessments, including review of cloud security configurations, encryption, and access controls.
Documentation & Reporting
- Develop comprehensive documentation for audit procedures and ensure accuracy through cross-referencing of work papers.
- Create preliminary and final audit reports for circulation to auditees and senior management.
- Prepare clear, concise audit observations highlighting risks, root causes, and actionable recommendations.
- Track closure and remediation of audit findings.
Stakeholder Management & Collaboration
- Facilitate discussions with management and process owners regarding audit observations and corrective actions.
- Collaborate closely with IT, Information Security, and business teams to implement controls.
- Facilitate knowledge sharing and mentoring among team members to enhance audit quality.
- Conduct security awareness programs to strengthen employee understanding of cybersecurity risks and controls.
Key Skills & Competencies
- Strong understanding of IT audits, cybersecurity, ITGCs, and application controls.
- Hands‑on experience with audit planning, walkthroughs, IDR management, and documentation.
- Knowledge of regulatory and industry standards (ISO 27001, RBI, PCI DSS).
- Strong analytical, documentation, and communication skills.
- Ability to manage multiple audits and stakeholder expectation
Educational Qualifications
- Inter CA/Bachelors degree in information technology, Computer Science, Cybersecurity, or related field.
- Certifications such as CISA, CISM, ISO 27001 LA/LI, CEH will be an added advantage.