31 Jul
|
BDO EDGE INDIA PRIVATE
|
Gurugram
31 Jul
BDO EDGE INDIA PRIVATE
Gurugram
Job Title: Assistant Manager
Job Designation: Assistant Manager
Location: Gurugram
Department: Advisory-ITGC
Job Type: Full-Time
Experience Level: 5-8 Years
About BDO EDGE:-
BDO EDGE India Private Limited is an entity, based in India created through a strategic partnership among BDO member firms: in India, the United States, the United Kingdom, and Germany. It operates independently within the BDO network of accounting and advisory firms, enhancing their combined capabilities and resources.
BDO EDGE (Exceptional Delivery for Global Enterprises) delivers tax, assurance, accounting, outsourcing, advisory, and technology-driven services through highly skilled professionals in India to BDO network firms, their alliance programmes and any other certified public accounting firms (CPA firms).
Position Overview:
We are looking for an Assistant Manager to support the IT General Control (ITGC) assessments and audits for clients across various industries. This role will involve designing and implementing IT control frameworks, leading internal and external audits, and ensuring compliance with standards such as SOX, SOC, and ISO 27001. You will collaborate with senior team members to identify risks and recommend control improvements to clients.
Job Description:
• Design & implement ITGC frameworks: Assist in testing the design and implementation of ITGC frameworks to ensure that they are aligned with company security and compliance strategies.
• Risk identification & mitigation: Assess ITGC processes and controls, identify risks, and recommend necessary improvements to clients.
• Client interaction: Develop strong client relationships, provide insights into ITGC practices,
and recommend solutions based on client needs.
• Documentation & reporting: Prepare and review ITGC audit reports, ensuring clarity and transparency in findings and recommendations.
• Mentoring: Guide and assist junior staff members in understanding ITGC frameworks and the auditing process.
• Client collaboration: Work with clients and engagement teams to follow up on assignments and ensure the timely completion of tasks.
Requirements
Qualifications & Experience
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Security, Engineering, Commerce, or a related discipline.
- Minimum 5+ years of experience in Information Security, Cybersecurity, IT Audit, Risk Advisory, or Compliance, As a Qualified Security Assessor (QSA) conducting PCI DSS assessments and advisory engagements.
- Proven experience performing PCI DSS Gap Assessments, Readiness Assessments, Reports on Compliance (ROC), Attestations of Compliance (AOC), and Cardholder Data Environment (CDE) scoping.
- Experience working with merchants, service providers, financial institutions, payment processors, or organizations handling payment card data.
- Experience leading client engagements and managing multiple assessment projects simultaneously.
- Prior consulting or professional services experience is preferred.
Required Skills
- Strong expertise in PCI DSS v4.0 requirements and PCI Security Standards Council (PCI SSC) guidance.
- In-depth understanding of payment card ecosystems, Cardholder Data Environments (CDE), and PCI DSS scoping methodologies.
- Strong knowledge of:
- Information Security Principles
- Enterprise IT Infrastructure
- Network Security
- Firewalls
- IDS/IPS
- Web Application Firewalls (WAF)
- Cloud Security (AWS, Azure, GCP)
- Identity & Access Management (IAM)
- Multi-Factor Authentication (MFA)
- Cryptography and Key Management
- Security Logging and SIEM
- Endpoint Detection & Response (EDR)
- Vulnerability Assessment and Penetration Testing (VA/PT)
- Secure Configuration Standards
- Incident Response
- Security Operations
Experience reviewing PCI DSS evidence, validating compensating controls, and assessing third-party service providers.
Certifications
Mandatory
- Current or former PCI Qualified Security Assessor (QSA) certification (within the past six (6) years).
Preferred
- PCI Internal Security Assessor (ISA)
- CISA (Certified Information Systems Auditor)
- CISM (Certified Information Security Manager)
- CRISC (Certified in Risk and Information Systems Control)
- ISO/IEC 27001 Lead Auditor
- ISO/IEC 27001 Lead Implementer
BenefitsWhy Join Us?
• Opportunity to work on high-impact advisory projects across various industries.
• Leadership and career advancement opportunities.
• Exposure to diverse client engagements and strategic consulting work.
• Cooperative and learning-driven work environment.
📌 Assistant Manager - ITGC (Gurugram)
🏢 BDO EDGE INDIA PRIVATE
📍 Gurugram