16 Aug
|
BDO India
|
Karnataka
16 Aug
BDO India
Karnataka
About Company
BDO is a global network of professional services firms with a presence in over 166 countries, revenue of over USD 14 billion, and experience of over 60 years. It's a leading service provider for the mid-markets with client service at its heart.
BDO India Services Private Limited (or BDO India) is the India member firm of BDO International. BDO India offers strategic, operational, accounting and tax, and regulatory advisory & assistance for both domestic and international organizations across a range of industries. BDO India is led by more than 300+ Partners & Directors with a team of over 10,000 professionals operating across 14 cities and 20 offices.
We expect to grow sizably in the coming 3-5 years, adding various dimensions to our business and multiplying and increasing the current team size multi-fold
Job Summary:
We are looking for a techno-functional professional to join our Reg-Tech & Cyber Risk practice. The role sits at the intersection of technology, regulation, and compliance advisory — requiring an individual who is equally at home reviewing IT systems and audit artefacts as they are interpreting RBI Master Directions and advising clients on compliance posture.
The successful candidate will work across regulatory compliance engagements covering the RBI IT Governance, Risk, Controls and Assurance (ITGRCA) framework, IT Outsourcing and TPRM norms, Digital Lending guidelines, Payment and Settlement Systems regulations, and frameworks governing Payment Aggregators / Payment Gateways (PA/PG) and Prepaid Payment Instruments (PPI). This is a growth-track role with direct client interaction and practice development responsibilities.
Experience and Qualifications:
- 3-6 Years of experience in IT-GRC
- B.E. / B.Tech / B.Sc. (IT/CS/ECE) or B.Com / BBA with strong technology orientation; MBA / M.Tech is an advantage.
- Certifications considered - CISA, CISSP, CISM, CompTIA Security+, CRISC, CCSP
Roles & Responsibilities:
- Shall possess hands-on technical experience executing a diverse range of engagements,
including IT General Controls (ITGC) audits, comprehensive Internal Audits of complex IT environments, and the evaluation/preparation of SOC reports.
- Shall independently drive and execute regulatory compliance audits spanning diverse financial entities, including Banks, NBFCs, Fintechs, Insurance Brokers, and Stockbrokers ensuring adherence to applicable RBI, SEBI, and IRDAI norms.
- Ability to critically evaluate technical evidence, identify inconsistencies, and detect control circumvention risks across applications, databases, and infrastructure.
- Shall independently verify that the organization’s IT strategy, policy frameworks, and Board level oversight (ITSC/ACB) strictly align with regulatory Master Directions and maintain a clear, independent reporting line for the CISO.
- Shall audit the security posture of the extended ecosystem, including third-party vendors, outsourced IT services.
- Capability to seamlessly bridge the gap between technical IT controls and broader regulatory expectations, translating complex cyber risks into clear business impacts.
- Shall validate the operational effectiveness of security monitoring (SOC), VAPT cycles, and BCP/DR readiness to ensure the institution can detect threats in real-time and recover from system failures within mandatory RPO/RTO targets.
- Strong understanding of the control environments surrounding complex payment systems, including Payment Aggregators/Payment Gateways (PA/PG), cross-border data flows, and third-party payment integrations.
- Supervise and review the fieldwork of senior associates/consultants, ensuring that audit working papers, test scripts,
and documentation meet rigorous qualitative standards.
- Collaborating with IT process owners to design practical, risk-mitigating controls and actively tracking remediation plans to closure.
- Act as a key liaison during external regulatory inspections and statutory audits, facilitating explicit communication between technical IT teams, external auditors, and senior management.
Skills & Competencies:
Regulatory Knowledge — Essential
- RBI IT Governance, Risk, Controls and Assurance (ITGRCA) Master Direction
- RBI Master Direction on IT Outsourcing / Managing Risks in Outsourcing (NBFC / Banks)
- RBI Digital Lending Guidelines (2022 and subsequent updates)
- Payment and Settlement Systems (PSS) Act, 2007 and RBI DPSS frameworks
- Payment Aggregator / Payment Gateway (PA/PG) guidelines — Merchant onboarding, escrow, baseline security
- Prepaid Payment Instruments (PPI) Master Direction — wallet issuance, interoperability, KYC norms
- UPI ecosystem — NPCI operating guidelines, dispute resolution, fraud risk frameworks
Technology & Control Domains
- IT General Controls (ITGC) assessment — access management, change management, operations, BCP/DR
- Application controls review — input validation, processing controls, output reconciliation
- Cybersecurity frameworks — familiarity with ISO 27001, NIST CSF, CIS Controls
- Data protection and privacy — DPDP Act 2023 awareness; data classification and handling controls
- Third-party risk management (TPRM) — vendor assessment, contract review, SLA monitoring
- Cloud risk assessment — awareness of shared responsibility models, cloud-specific regulatory requirements
Tools & Methodology
- Proficiency in MS Excel (audit/risk workbooks, control matrices, scoring models)
- MS PowerPoint — client-facing deliverable and deck preparation
- Familiarity with GRC tools (e.g., SAP GRC, ServiceNow GRC, or similar) is an advantage
- Comfort with data analysis and log review as part of IT audit fieldwork
📌 Assistant Manager - Cyber Security - IT-GRC (Karnataka)
🏢 BDO India
📍 Karnataka