20 Aug
|
WNS Holdings
|
Gurugram
20 Aug
WNS Holdings
Gurugram
As part of the IT Cyber & Assurance team, you will help maintain and enhance the IT control environment that underpins financial and operational reporting. You will evaluate the design and operating effectiveness of Controls (ITGCs), produce audit ready documentation, and partner with stakeholders to remediate control gaps.
The role has a strong focus on Identity & Access Management (IAM), supporting the clients transition of access certifications and user access governance to SailPoint, with close interaction with Active Directory / Entra ID data.
Role & responsibilities
Control Testing & Evaluation
- Plan and execute walkthroughs and testing (ToD/ToE) over core ITGC domains: Logical access (provisioning, SOD, privileged access, periodic recerts), change management (SDLC, emergency changes), IT operations (backups/restore, batch jobs, monitoring, incident/problem management), and disaster recovery.
- Maintain test scripts, sampling, evidence, and conclusions in line with internal methodology and external expectations.
- Identify control deficiencies, classify severity, and work with owners to define root cause, remediation actions, and target dates.
Governance, Stakeholder & Audit Engagement
- Work with control owners, process leads, Internal audit, External audit and Risk to align scope, gather evidence, and resolve findings.
- Support definition and periodic refresh of the material controls set, mapping to principal risks and financial statement assertions.
- Track and validate remediation; escalate slippage and emerging risks with data backed insights.
Reporting & Documentation
- Produce concise testing reports, issue logs, and management dashboards (e.g., control health, overdue actions).
- Keep the control library, RACMs, narratives and process flow current; ensure evidence is audit ready and retained per policy.
- Log and monitor third party SOC1/SOC2 reports and associated user control considerations impacting ICFR
Identity & Access Management (IAM) - SailPoint
- Support transition from manual access recertification processes to an automated SailPoint based identity governance model, while ensuring ongoing compliance with annual audit.
- Assist with the current manual access review process, which involves:
- Obtaining user access lists (ACLs) directly from applications and directories (e.g., Active Directory / Entra ID),
- Reconciling those populations against SailPoint to validate completeness and accuracy,
- Supporting and executing SailPoint access certification campaigns used as audit evidence.
- Work with IAM, application owners, infrastructure, and security teams to:
- Onboard applications into SailPoint that are not yet integrated,
- Define authoritative access sources, entitlement structures, and certification scope,
- Support the design and testing of automated recertification processes.
- Perform and document reconciliation of SailPoint certification results to application, Active Directory, and Entra ID populations.
- Ensure access recertifications continue to operate effectively during the transition period, including manual or hybrid approaches where automation is not yet available.
- Identify opportunities to reduce manual effort, improve data quality, and strengthen control effectiveness through automation and standardization within SailPoint.
Continuous Improvement
- Contribute to enhancements in control methodology, scoping, and continuous control monitoring.
- Support thematic reviews/deep dives (e.g., joiners/leavers/transfer, emergency changes, backup restorations).
- Champion data driven testing from full population extracts (e.g., Entra ID/AD, SAP, Oracle, Dynamics) to targeted samples.
Preferred candidate profile
- 3 - 5 years hands-on experience in ITGC/ITAC testing within internal audit, external audit, risk assurance, or GRC.
- Strong working knowledge of SOX/ICFR concepts and how they translate into UK Governance Code Provision 29 evidence expectations (material controls, effectiveness at balance-sheet date).
- Familiarity with control frameworks such as SOX, COBIT and ISO 27001; understanding of COSO principles and their mapping to IT controls.
- Experience supporting Identity & Access Management (IAM) initiatives, including SailPoint access certifications, reconciliation of certification populations to Active Directory / Entra ID and application access, and assisting with application onboarding and automation of access reviews in an audit-controlled environment.
- Excellent documentation, analytical and problem-solving skills; able to articulate clear, defensible conclusions.
- Proven stakeholder management; comfortable with challenging conversations and influencing outcomes.
- Proficiency with Excel and PowerPoint; experience with control monitoring/GRC tools (e.g., MetricStream, Archer, AuditBoard, ServiceNow GRC).
- Ability to work independently, handle multiple priorities, and meet deadlines in a fast-moving setting.
Education & Qualifications:
- Bachelors degree in information systems, Computer Science, Engineering or a related discipline.
- CISA (or actively pursuing) or equivalent professional qualification.
Good to have, not mandatory:
- Certifications such as COBIT Foundation, ISO/IEC 27001 LA/LI, ITIL, CCSK.
- Additional audit/risk credentials (e.g., CIA, CRISC).
Tools you may use
- GRC/ICFR: MetricStream (or equivalent), SharePoint/Confluence, Jira/ServiceNow.
- Data & Evidence: Excel/Power BI, SQL, ERP audit logs (SAP GRC, Oracle, Dynamics), Entra ID/AD.
📌 experience in ITGC, Client facing role (Gurugram)
🏢 WNS Holdings
📍 Gurugram