A leading insurance company in Mumbai is looking for a professional to coordinate IT controls assessments and lead SOX audit processes. The role demands strong understanding of IT governance, risk management, and compliance standards. Candidates with a BE/B.Tech in Computer Science or an MBA, along with knowledge in SDLC and IT frameworks will be preferred. This position offers an opportunity to engage with both internal stakeholders and external auditors to effectively manage IT risks.
Qualifications
Knowledge of IT Controls and related compliance standards.
Demonstrated in-depth knowledge in Information Security areas.
Certification of CA, CPA or CIA is an advantage.
Ability to understand complex technologies, processes, and regulatory requirements.
Strong understanding of ISO, SOX, COSO and COBIT frameworks.
Responsibilities
Coordinate risk assessments and evaluate ITGC effectiveness.
Lead audit planning, fieldwork, and reporting.
Communicate and remediate risks with process owners.
Prepare reports on adequacy and effectiveness of controls evaluated/tested.
Track and monitor open issues and follow up on remediation progress.
Interface with external auditors and support IT audit initiatives from an audit perspective.
Lead ISO, SOX and ICoFR audit planning, fieldwork, documentation and reporting.
Interact with IT application owners during SOX testing, including walkthroughs and testing on their behalf.
Demonstrate awareness of IT controls and related compliances.
Evaluate compliance with company policies, procedures and regulatory standards.
Build collaborative relationships with internal stakeholders at appropriate management levels.
Skills
Knowledge of SDLC (Software Development Life Cycle)
Understanding of ISO, SOX and IT frameworks
Ability to understand complex technologies
ISO
SOX compliance
Cybersecurity
Regulatory compliance
Risk management
Education
BE / B.Tech Computer Science / MBA – Systems
MBA – Systems
CIA / CA / CPA Certification
Tools
ISO frameworks
SOX compliance
IT Security Tools
Job description
Coordinate with business and IT process owners to initiate, scope, plan, and conduct periodic controls assessments to identify areas of risk by evaluating the design and operating effectiveness of Information Technology General Controls (ITGC) over applications, operating systems, and databases as well as the network infrastructure including cybersecurity controls
Planning, testing, documentation and reporting
Communicate issues to process owners, ensuring their understanding of associated risks and the actions needed to remediate those risks
Prepare reports based on the adequacy and effectiveness of controls evaluated/tested
Track and Monitor open issues and conduct follow-up to evaluate the adequacy of remediation efforts
Communicate with external auditors and support their initiatives effectively from an IT audit standpoint.
Lead ISO, SOX and ICoFR audit planning, fieldwork (testing and documentation), and reporting
Interact with the IT application owner and provide assistance as needed during the SOX control testing processes, including attending walkthrough meetings and performing testing on their behalf
Aware about IT Controls and related compliances
Evaluate compliance with Company policies and procedures and regulatory standards
Build collaborative working relationships with internal stakeholders (appropriate levels of management)
Education
BE / B.Tech Computer Science / MBA – Systems
Competencies (Knowledge & Skills)
Knowledge of SDLC (Software Development Life Cycle)
Certification of CA, CPA or CIA (or actively working towards) or other similar certifications would be an added advantage.
Demonstrated in-depth knowledge of concepts, best practices and controls in a breadth of Information Security areas/domains. These include governance & risk management, access control, cybersecurity, physical security, security architecture and design, business continuity/disaster recovery, network security, application & operations security and compliance/incident management.
Demonstrated ability to understand complex technologies, business processes, regulations and emerging risks.
Strong understanding of ISO, SOX and IT frameworks including COSO and COBIT.