Walk-in | Lead Auditor-System Audit

Reserve Bank Information Technology

Navi Mumbai

On-site

INR 2,400,000 - 3,600,000

Full time

8 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Reserve Bank Information Technology is seeking an experienced IT Audit professional with 9–12 years in PMO reviews, information security operations, and IS audits across banking tech domains. You will lead hybrid-cloud audits, assess API security, containerization, DevSecOps, and data-driven risk dashboards, while ensuring regulatory alignment and high-quality deliverables.

The role involves travel within Mumbai and across the country to perform audits and ensure IT controls meet RBI standards

Qualifications

  • 9–12 years of total experience in PMO reviews/audits and information security operations in banking tech domains.
  • Exposure to Banking/Finance/Payments industry domains preferred.
  • Experience in writing policies, procedures, and processes.
  • Conducting risk assessments covering Cyber Security domains.

Responsibilities

  • Lead deep-dive audits of AWS IAM, S3, VPC, and GuardDuty; review Microsoft Hybrid environments.
  • Audit Java-based application security, API security, and containerization (Docker/Kubernetes) with DevSecOps pipelines.
  • Perform performance audits of high-value IT projects ensuring PMP/Agile milestones meet security standards.
  • Develop data-driven continuous auditing dashboards using Python or SQL to monitor risk in real time.
  • Oversee database security with Oracle and MS SQL; monitor using Database Activity Monitoring tools.
  • Ensure compliance with RBI Cyber Security Framework and Global Internal Audit Standards (2024).
  • Review IT General Controls including IAM, network, server, application, change management, backup/DR; align with ISO standards.
  • Prepare quality deliverables: audit reports, presentations; communicate findings to stakeholders.
  • Travel within Mumbai and across India as required to conduct audits.

Skills

Project Management
Audits
Information Security
Cloud Security
Cyber Security
Python
SQL
DevSecOps
API Security
Docker
Kubernetes
ISO Standards
BCP/DR
Regulatory Compliance
PCI-DSS

Tools

Oracle
MS SQL
Database Activity Monitoring
WAF
Active Directory
GuardDuty
IAM
S3
VPC
Docker
Kubernetes

Job description

  • 9 to 12 years of total experience (upto 12 yrs.) in the field of Project Management review/audits, information security operations, Information System Audits encompassing experience into any of the Banking Technologies Domains Cloud Security, Database management and administration, Network security and SOC in addition to IT General controls (ITGC).
  • Exposure to the Banking / Finance / Payment industry domains would be preferrable.
  • Hands 1-on experience in the following areas:
  • Writing policies, procedures, and processes
  • Conducting risk assessment covering Cyber Security domains as noted below:
Hybrid Cloud Mastry:
  • Lead deep-dive audits of AWS (IAM, S3, VPC, GuardDuty) and Microsoft Hybrid environments.
Code & Architecture Review:
  • Audit Java-based application security, focusing on API security, containerization (Docker/K8s), and DevSecOps pipelines.
Project Governance:
  • Conduct performance audits of high-value IT projects, ensuring they meet PMP/Agile milestones without compromising on security.
Data-Driven Assurance:
  • Use Python or SQL to build automated "Continuous Auditing" dashboards that track risk in real-time.
Database Security:
  • Database administration and management - Oracle, MS SQL etc., Database Activity Monitoring tools, data security and localization.
Regulatory Alignment:
  • Ensure all IT operations comply with the latest RBI Cyber Security Framework and Global Internal Audit Standards (2024)
IT General Controls:
  • Familiarity with Technical Security controls of Identity & Access Management, Network, Server, Application, Change management, Backup and Restoration etc. and process controls reviews.
  • Understand BCP and DR processes and architecture.
  • Experience in conducting reviews based on ISO standards and regulatory guidelines in banking sector for a medium to large sized organization would be preferred.
  • Experience in conducting Information System Audits/Review
  • Must have experience in preparing quality deliverables such as audit reports, presentations, etc.
  • Excellent written, oral communication and presentation skills
  • Excellent organizational and interpersonal skills
  • Ability to work independently or as part of a team

Information technology / Banking and Financial services / Auditing / Cyber Security consulting

  • To evaluate the systemic impact of risks across Project Management (PMO) and ITIL service delivery.
  • Heavy-hitter who can dissect complex AWS/Azure/Hybrid-Cloud architectures and scrutinize the Java-based microservices.
  • Candidates may have to travel within Mumbai and across the country (if required) to perform audits, as per RBI requirements.
  • Conducting audit of Information security policies, procedures, and processes to identify process/design gaps.
  • Conduct audits of information security systems and infrastructure to verify systems are secure and support the related applications/business processes.
  • Conducts audits in different banking technology domains such as Active Directory, WAF, Network access security, End-point security, Application VA/PT/AppSec, SDLC, Database management and security, PCI-DSS, and IT General Controls etc.
  • Additional weightage will be given to candidates with experience in domains such as Cloud Security, API security, CI-CD pipeline, project management Audits, etc.
  • Developing project plans, work programs, evaluating system controls, identify risks and audit gaps, documenting results in proper audit report format, making recommendations, and communicating information to stakeholders.
  • Support in maintaining audit checklist and documents, trend analysis, preparing presentations etc.
  • Should be a self-learner and must keep updated with the latest security guidelines issued by regulators, international standards for information security, threats and vulnerabilities researched/discovered.
  • Research public domain to keep up to date knowledge on latest banking applications / technologies and emerging technologies Cloud, Virtualisation, AI-ML, IOT, CI-CD, API security, etc. and ensure continuous learning in identified security competencies and new/emerging technologies.
  • All positions are on fixed term contract on a full-time basis exclusively for ReBIT, initially for a period of five years, extendable by mutual consent

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Auditor-Immediate Joiner
Senior Auditor-Immediate Joiner

Reserve Bank Information Technology • Navi Mumbai

On-site
INR 1,500,000 - 2,000,000
Assistant Manager - Cyber Security - IT-GRC
Assistant Manager - Cyber Security - IT-GRC

BDO India • Bengaluru Urban

On-site
INR 1,200,000 - 1,800,000
Assistant Manager - Cyber Security - IT-GRC
Assistant Manager - Cyber Security - IT-GRC

BDO India • Chennai District

On-site
INR 1,400,000 - 2,400,000
IT Auditor
IT Auditor

Incred • Navi Mumbai, Mumbai

On-site
INR 900,000 - 1,500,000
IT & Cyber Security Auditor
IT & Cyber Security Auditor

ANB Global • Mumbai

On-site
INR 1,200,000 - 1,800,000
Technical Security Manager
Technical Security Manager

Pay10 India • New Delhi

On-site
INR 1,300,000 - 2,100,000
Lead Cyber Security- VAPT
Lead Cyber Security- VAPT

Darwinbox Digital Solutions Pvt. Ltd. • Navi Mumbai

On-site
INR 2,500,000 - 4,000,000
IT Audit Lead
IT Audit Lead

Paytm Payment Gateway • Dadri

On-site
INR 1,200,000 - 1,800,000
Security Risk and Regulatory Tech Compliance
Security Risk and Regulatory Tech Compliance

KreditBee • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Risk Control and governance- Finance SME
Risk Control and governance- Finance SME

NEC Corporation • Navi Mumbai

On-site
INR 1,900,000 - 3,200,000