06 Aug
|
S&P Global Market Intelligence
|
Hyderabad
06 Aug
S&P Global Market Intelligence
Hyderabad
About the Role:
Grade Level (for internal use):11
The Team: The SP Global Internal Audit function reports to the Audit Committee and the President and CEO. Join our energetic Internal Audit Team as a Senior IT Audit Manager, focusing on IT audits and cyber security. You'll lead technology audits across the Chief Technology and Transformation Office (divisional IT infrastructure, applications, cloud systems, cyber security, identity and access management) and provide independent assessments for the company. In this critical role, you will be responsible for the execution of technology audits, managing key stakeholder relationships, and driving high-impact strategic transformation initiatives across the organization.
The Impact: The Senior IT Audit Manager role will lead and oversee technology-focused audits across the Chief Technology and Transformation Office (CTTO), ensuring compliance with internal policies and regulations. Your expertise will enhance the Internal Audit value proposition by harnessing technologies and tools to improve audit quality on audit coverage for cutting edge technologies like Identity and Access Management (IAM) tools, Generative AI, Large Language Models, and strategic transformation initiatives. To be successful in this role requires solid experience implementing identity and access management tools and processes across various environments.
The role reports directly to the Senior Director, Enterprise Technology Audit and will be responsible for audit planning and execution.
Description
- Partner with technology stakeholders to identify and assess identity-related vulnerabilities and control gaps through grey box testing.
- IAM architecture experience,
including MFA and tools such as SailPoint and CyberArk.
- Act as a subject matter expert in IAM security testing, providing deep insights into exploitation techniques across IAM solutions.
- Assess the effectiveness of Identity Governance Administration controls (provisioning, RBAC, access certifications) through control testing, abuse-case simulation, and privilege escalation scenarios.
- Conduct risk-based vulnerability assessments focused on identity attack vectors, including credential compromise, privilege misuse, and lateral movement.
- Drive and assess adoption of Secure-by-Design principles, validating implementation through security testing across the SDLC and pre-production environments.
- Lead testing and validation of advanced IAM capabilities such as MFA bypass scenarios, SSO misconfigurations, and Privileged Access Management (PAM) weaknesses.
- Continuously monitor and emulate emerging IAM threat techniques, attack vectors, and adversary tactics, integrating them into test scenarios and audit coverage.
- Collaborate with other technology auditors to develop and execute audit programs to support coverage for established, emerging, frontier technologies and related applications/workflows (IAM, Cybersecurity, and AI/GenAI).
Requirements
- 8+ years of experience in IAM and cybersecurity,
with strong hands-on expertise in vulnerability assessment and security testing of identity platforms and access control mechanisms. Broader information security experience is a plus.
- Strong experience in testing identity governance and access management controls, including provisioning, RBAC models, privilege escalation, and access certification bypass scenarios.
- Experience performing security testing of IAM solutions in cloud environments (AWS, Azure, GCP), including validation of authentication, authorization, and federation controls.
- Understanding of cryptographic controls, PKI, and their exploitation risks, with the ability to assess weaknesses in identity and authentication mechanisms.
- Knowledge of Zero Trust architectures, DevSecOps pipelines, and modern application environments with a focus on identifying identity-driven attack paths.
- Knowledge of security frameworks and regulatory standards (ISO 27001/27002, NIST, GDPR, PCI-DSS etc.)
- Experience in cloud IAM architectures (hybrid, multi-cloud, cloud-native), with the ability to identify misconfigurations and vulnerabilities.
- Strong stakeholder management skills with the ability to translate technical findings into risk-focused audit insights.
- Ability to analyze, synthesize, and communicate complex security testing results to both technical and non-technical stakeholders.
- Excellent written and verbal communication skills
- Willingness to travel as needed
Preferred Qualifications
- Certified Information Systems Auditor (CISA), or Certified Information Systems Security Professional CISSP, CEH, Red Team, or Equivalent.
Location - Hyderabad,Gurugram,Bengaluru,Mumbai,Maharastra
📌 Senior IT Audit Manager, Cybersecurity & Technology (Hyderabad)
🏢 S&P Global Market Intelligence
📍 Hyderabad