A leading financial services firm in Mumbai seeks candidates for IT Control Assessments, focusing on identifying risks and evaluating compliance with internal policies and regulatory standards. The role involves audit planning and ensuring the effectiveness of cybersecurity measures within the organization. A strong background in Information Technology General Controls (ITGC), along with relevant education such as BE/B.Tech or MBA, is essential for success in this position. Candidates should be familiar with ISO and SOX frameworks, IT compliance, and risk management.
Qualifications
Experience in IT controls and risk management.
In-depth knowledge of IT compliance frameworks.
Ability to understand regulatory standards.
Responsibilities
Conduct periodic controls assessments to identify areas of risk.
Prepare reports on the adequacy and effectiveness of controls.
Lead audit planning and reporting for ISO and SOX controls.
Skills
Knowledge of SDLC
Knowledge of ISO, SOX frameworks
Strong understanding of cybersecurity
IT compliance knowledge
Education
BE / B.Tech Computer Science / MBA – Systems
Tools
ISO standards
SOX compliance tools
Job description
Coordinate with business and IT process owners to initiate, scope, plan, and conduct periodic controls assessments to identify areas of risk by evaluating the design and operating effectiveness of Information Technology General Controls (ITGC) over applications, operating systems, and databases as well as the network infrastructure including cybersecurity controls
Planning, testing, documentation and reporting
Communicate issues to process owners, ensuring their understanding of associated risks and the actions needed to remediate those risks
Prepare reports based on the adequacy and effectiveness of controls evaluated/tested
Track and monitor open issues and conduct follow-up to evaluate the adequacy of remediation efforts
Lead ISO, SOX and ICoFR audit planning, fieldwork (testing and documentation), and reporting
Interact with the IT application during the SOX control testing processes, including attending walkthrough meetings and performing testing on their behalf
Aware of IT Controls and related compliances
Evaluate compliance with Company policies and procedures and regulatory standards
Build collaborative working relationships with internal stakeholders (appropriate levels>
Education
BE / B.Tech Computer Science / MBA – Systems
Competencies (Knowledge & Skills)
Knowledge of SDLC (Software Development Life Cycle)
Certification of CA, CPA or CIA (or actively working towards) or other similar certifications would be an added advantage.
Demonstrated in-depth knowledge of concepts, best practices and controls in a breadth of Information Security areas/domains. These include governance & risk management, access control, cybersecurity, physical security, security architecture and design, business continuity/disaster recovery, network security, application & operations security and compliance/incident management.
Demonstrated ability to understand complex technologies, business processes, regulations and emerging risks.
Strong understanding of ISO, SOX and IT frameworks including COSO and COBIT.