A financial services company in Mumbai seeks an experienced IT Auditor responsible for coordinating controls assessments and leading ISO, SOX, and ICoFR audits. Ideal candidates will hold a BE/B.Tech in Computer Science or an MBA in Systems, along with expertise in IT controls, cybersecurity, and regulatory standards. You will prepare detailed reports, communicate findings with stakeholders, and ensure compliance with internal policies. Strong understanding of complex technologies is essential.
Qualifications
Strong understanding of IT controls and related compliances.
Demonstrated ability to understand complex technologies and business processes.
Knowledge of governance & risk management, access control, and cybersecurity.
Responsibilities
Coordinate with business and IT process owners for controls assessments.
Lead ISO, SOX and ICoFR audit planning and reporting.
Prepare reports based on controls evaluated/tested.
Skills
Knowledge of SDLC (Software Development Life Cycle)
ISO, SOX and IT frameworks including COSO and COBIT
Demonstrated in-depth knowledge of Information Security areas
Education
BE / B.Tech Computer Science / MBA – Systems
Tools
Certification of CA, CPA or CIA
Job description
Coordinate withbusiness and IT process owners to initiate, scope, plan, and conduct periodiccontrols assessments to identify areas of risk by evaluating the design andoperating effectiveness of Information Technology General Controls (ITGC) overapplications, operating systems, and databases as well as the networkinfrastructure including cybersecurity controls
Planning,testing, documentation and reporting
Communicateissues to process owners, ensuring their understanding of associated risks andthe actions needed to remediate those risks
Prepare reportsbased on the adequacy and effectiveness of controls evaluated/tested
Track andMonitors open issues and conductsfollow-up to evaluate the adequacy of remediation efforts
Communicate withexternal auditors and support their initiatives effectively from an IT auditstandpoint.
Lead ISO, SOX and ICoFR audit planning, fieldwork(testing and documentation), and reporting
Interact withthe IT application owner and provide assistance as needed during the SOXcontrol testing processes, including attending walkthrough meetings andperforming testing on their behalf
Aware about ITControls and related compliances
Evaluatecompliance with Company policies and procedures and regulatory standards
Buildcollaborative working relationships with internal stakeholders (appropriatelevels of management
Education
BE / B.Tech Computer Science / MBA – Systems
Competencies (Knowledge & Skills)
Knowledge ofSDLC (Software Development Life Cycle)
Certification ofCA, CPA or CIA (or actively working towards) or other similar certificationswould be an added advantage.
Demonstratedin-depth knowledge of concepts, best practices and controls in a breadth ofInformation Security areas/domains. These include governance & riskmanagement, access control, cybersecurity, physical security, securityarchitecture and design, business continuity/disaster recovery, networksecurity, application & operations security and compliance/incidentmanagement.
Demonstratedability to understand complex technologies, business processes, regulations andemerging risks.
Strongunderstanding of ISO, SOX and IT frameworks including COSO and COBIT.