Job DescriptionRole Snapshot
nRole Title
nAudit Manager - Systems Audit & Access Governance
nDepartment
nSystem and Process Audit
nLocation
nTirupur, Tamil Nadu (in office; travel within group companies as required)
nTeam
nBuild and lead a team of 2–4 audit analysts
nExperience
n8–14 years in IT / Systems Audit or ERP Access Governance
nQualifications
nCA Intermediate / MBA (Finance or IT) / CPA / ACCA
nCertifications
nCISA preferred — CISSP / CIA / CRISC advantageous
nIndustry
nManufacturing / Textiles / Retail — Multi-ERP, multi-application environment
nRole Purpose
nSingle owner of user access governance, controls assurance, process audit, and continuous systems improvement across the entire application landscape. Hands-on and board-facing — equally comfortable extracting raw ERP data and presenting risk findings. We want someone dynamic and raring to make a measurable difference, not a passive reviewer.
nKey Responsibilities
n01 User Access Review
nReconcile all ERP/app accounts against live HR records; disable leavers and dormant users; establish JML process; maintain User Access Register with quarterly owner-certification cycles.
n02 Segregation of Duties
nBuild role-to-function matrices; apply SoD rule library to identify conflicts (e.g. create-vendor/approve-payment); prioritise by risk; track remediation in a living Risk Register.
n03 Least Privilege
nCompare assigned permissions vs actual usage; produce Entitlement Heat Map; drive rationalisation programmes; establish bi-annual re-certification for all privileged accounts.
n04 Access Control Vulnerabilities
nAssess authentication, MFA coverage, PAM controls, API/middleware gaps, and logging adequacy; produce prioritised Vulnerability Register with risk ratings and mitigations.
n05 Management Reporting & Follow-Up
nPrepare risk-rated audit reports; maintain CAP tracker; conduct monthly follow-up reviews; escalate overdue critical actions; produce Quarterly Governance Dashboard for