21 Aug
|
INTERCERT
|
Noida
Senior IT Regulatory Auditor
Location: Noida
Work Mode: On-site
Employment Type: Full-Time
Experience: 3–4 Years
About Us
We are a CREST Member Company and an Accredited Certification Body providing cybersecurity, regulatory compliance, assurance, and certification services across India and international markets.
Our expertise includes Information Security Audits, Regulatory Compliance Assessments, Cybersecurity Audits, Data Privacy, Governance, Risk & Compliance (GRC), Certification Audits, and Security Assurance Services.
We work with Banks, NBFCs, FinTechs, Insurance Companies, Payment Aggregators, Government Organisations, Critical Infrastructure, Telecom, Healthcare, and Enterprises to help them meet regulatory, cybersecurity, and compliance requirements.
Position Summary
We are looking for an experienced Senior IT Regulatory Auditor to join our Audit & Compliance practice. The candidate will be responsible for planning, leading, and executing IT, cybersecurity, regulatory, and information security audits for regulated entities across the BFSI sector and other critical industries.
The ideal candidate should have strong knowledge of Indian regulatory requirements, cybersecurity frameworks, IT governance, risk management, information security controls, third-party risk, cloud security, and data privacy.
The role involves regular interaction with CXOs, CISOs, Compliance Officers, Regulators, Internal Audit Teams, Technology Teams, and Business Leaders throughout the audit lifecycle.
Key ResponsibilitiesRegulatory & IT Audits
- Lead and execute IT, cybersecurity, information security, and regulatory compliance audits.
- Conduct gap assessments, compliance reviews, and regulatory readiness assessments.
- Review IT governance, security controls, risk management, and compliance processes.
- Prepare detailed audit reports, executive summaries, and remediation recommendations.
- Validate closure of audit findings and assist clients during regulatory inspections.
- Manage multiple audit engagements while ensuring quality and timely delivery.
Regulatory Compliance Expertise Hands-on experience with one or more of the following regulatory frameworks is preferred:
- RBI: Digital Lending Regulations, IT Governance, Outsourcing of IT Services, IT Vendor Risk Management, Cyber Security Framework, Information Security Guidelines, and IT Examination & Compliance Audits.
- SEBI: Cyber Security & Cyber Resilience Framework, Information Security Compliance, and regulatory audits for regulated market entities.
- IRDAI: Information Security Guidelines,
Cyber Security Framework, Information Systems Audits, and Regulatory Compliance Assessments.
- NPCI: Information Security Compliance, UPI Security Audits, Payment Switch Security, and NPCI Audit Requirements.
- CERT-In: CERT-In Directions, Information Security Audits, VAPT Report Reviews, Incident Response Readiness, Log Retention, and Security Monitoring.
- Data Privacy: DPDP Act, 2023, Privacy Impact Assessments (PIA), Data Protection Assessments, Data Governance, Data Classification, and Privacy Compliance Reviews.
Other Audit & Compliance Engagements
- Internal IT Audits
- Information Security & Cybersecurity Audits
- IT General Controls (ITGC)
- Vendor & Third-Party Risk Assessments
- Cloud Security Reviews
- Business Continuity Management (BCM) & Disaster Recovery (DR) Audits
- Technology & Operational Risk Assessments
- Regulatory Readiness Assessments
- OC-87 and Section 8 Compliance Audits
Certification & Assurance
- Support certification readiness assessments and information security certification audits.
- Conduct technical and risk reviews.
- Perform control effectiveness and compliance maturity assessments.
- Support governance reviews and client readiness programmes.
- Review internal quality and audit documentation.
- Ensure audit evidence, working papers, and documentation meet required quality standards.
Technical Skills
Strong understanding of
- Information Security & IT Governance
- Cybersecurity & Risk Management
- IT General Controls (ITGC)
- Identity & Access Management (IAM)
- Cloud, Network & Endpoint Security
- Security Operations, SIEM & Security Monitoring
- Vulnerability & Patch Management
- Secure Configuration Reviews
- Encryption & Key Management
- Data Loss Prevention (DLP)
- Vendor & Third-Party Risk Management
- Business Continuity & Disaster Recovery
- Security Architecture
- IT Audit & Assessment Methodologies
Frameworks & Standards Hands-on experience with one or more of the following:
- ISO/IEC 27001
- NIST Cybersecurity Framework (CSF)
- COBIT
- CIS Controls
- SWIFT Customer Security Controls Framework (CSCF)
Qualifications
- Bachelor's or Master's degree in Computer Science, Information Technology,
Cybersecurity, Information Systems, Electronics, or a related discipline.
- 3–4 years of relevant experience in Information Security Audits, IT Audits, Cybersecurity Audits, Regulatory Compliance, GRC, Risk Advisory, or related areas.
Preferred Certifications One or more of the following certifications will be an advantage:
- CISA
- CEH
- ISO/IEC 27001 Lead Auditor
- Certified Data Privacy Professional (CDPP) or equivalent privacy certification
- CERT-In Recognised Information Security Auditor Qualification
Preferred Industry Experience Candidates with experience in any of the following will be preferred:
- CERT-In Empanelled Audit Organisations
- CREST Member Organisations
- Cybersecurity Consulting Firms
- NBFCs & FinTech Companies
- Insurance Companies
- Government Organisations
- Critical Information Infrastructure
- BFSI and other regulated industries
Key Competencies
- Strong analytical and problem-solving skills
- Excellent report writing and documentation skills
- Ability to interpret and apply regulatory requirements
- Excellent verbal and written communication skills
- Client-facing and stakeholder management experience
- Solid project planning and audit management skills
- Leadership and mentoring capabilities
- High level of integrity and professional ethics
- Ability to manage multiple audit engagements simultaneously
- Strong attention to detail and quality orientation
Why Join Us? Join one of India's leading cybersecurity, regulatory compliance, assurance, and certification service providers.
As a CREST Member Company and Accredited Certification Body, we offer exposure to high-impact cybersecurity and regulatory engagements across the BFSI ecosystem and other regulated industries.
You will have the opportunity to:
- Work on critical cybersecurity and regulatory audit assignments.
- Interact with CXOs, CISOs, regulators, and senior technology stakeholders.
- Work alongside experienced cybersecurity and compliance professionals.
- Contribute to certification, assurance, and regulatory compliance engagements.
- Help organisations strengthen governance, cyber resilience, regulatory compliance, and operational security.
- Build strong expertise across cybersecurity, risk, audit, and regulatory frameworks.
- Grow professionally in a challenging and fast-paced consulting environment.
Interested can apply on: 92205 06287 Pay: Up to ₹100,000.00 per year
Benefits
- Health insurance
- Provident Fund
Work Location: In person
📌 IT Regulatory Auditor – BFSI, Cybersecurity & Compliance (Noida)
🏢 INTERCERT
📍 Noida