06 Aug
|
Volkswagen Group Digital Solutions [India]
|
Pune
06 Aug
Volkswagen Group Digital Solutions [India]
Pune
Join to Grow,
Excellent work will eventually happen!
hashtag#ShapingFutureTechnologists is our POV.
If technology is your passion and innovation is your fuel, then this is your workplace. More than a Great Place to Work, we are a Great Place to Grow. And a growing list of new opportunities every single day.
IT AUDITOR will be part of the IT & DI AUDIT HUB INDIA and will be responsible to perform Internal Audits in the domain of Information Technology (IT). The Audits are performed as part of audit services offered to Group Audit (K-GR), Brand Audit and Regional Audit teams of the Volkswagen Group. IT AUDITOR is responsible to participate in planning and performing the audit assignment starting from audit announcement, audit planning, field work, audit quality reviews, pre-closing / closing meetings with the respective Head of the Departments including writing of the audit report and its finalization as well as follow up of the audit actions.
The IT Auditor expected to posses’ knowledge in the areas of IT Audits, IT Infrastructure, Information Security / Cybersecurity Audits, Vulnerability Assessment and Penetration testing.
Years of Experience: Working experience of 4-8 years, preferably within a Software company for at least 3 years in a multinational company or Big 4, or in the Information Security / Cyber security department or IT audit department or equivalent work experience
Job Title: IT Auditor (IT General Controls & Security Penetration Testing)
Key Tasks and Responsibilities
1. IT General Controls (ITGC):
• Perform IT audits to evaluate the design, implementation and effectiveness of IT general controls (ITGCs) in alignment with industry best practices, standards (e.g., COBIT, NIST, ISO 27001) and regulatory requirements (e.g., SOX, GDPR).
- Assess and review access control, change management,
IT operations and data management procedures to ensure compliance with organizational policies and applicable regulations.
- Evaluate the effectiveness of IT infrastructure management controls, including cloud services, network architecture and application security.
- Conduct risk assessments to identify control gaps, areas of improvement and potential vulnerabilities in the IT environment.
- Review and assess backup, disaster recovery and business continuity plans to ensure that the organization's IT operations are adequately protected against disruptions.
1. Penetration Testing & Vulnerability Assessments:
• Plan, execute and lead penetration testing engagements to identify vulnerabilities in cloud environments, network systems and applications.
- Use tools and techniques to perform comprehensive vulnerability scans, network and web application penetration tests and cloud security assessments.
- Identify vulnerabilities in cloud platforms (e.g., AWS/Azure) including misconfigurations,
insecure protocols and other exploitable weaknesses.
- Perform ethical hacking and simulate real-world attacks to assess the security posture of internal and external systems.
- Provide detailed reports on findings, including actionable recommendations to mitigate identified security risks and enhance system hardening.
1. Reporting & Documentation:
• Prepare detailed audit reports that document findings, risk assessments and recommendations for improvement in both technical and non-technical language.
- Provide executive-level presentations to senior leadership regarding audit results, security vulnerabilities and proposed remediation steps.
- Track and verify the implementation of corrective actions to ensure that risks are mitigated and controls are strengthened.
1. Collaboration & Continuous Improvement:
• Collaborate with IT and security teams to improve the organization’s overall security posture and audit processes.
📌 Information Technology Auditor (Pune)
🏢 Volkswagen Group Digital Solutions [India]
📍 Pune