21 Aug
|
Long Shot Assignment
|
Andheri
21 Aug
Long Shot Assignment
Andheri
– IT General Controls, Application Controls & Vendor Risk Assessment
Position: IT Audit / IT Risk & Controls Consultant
Department: Information Technology Audit / Risk & Compliance
Industry: Financial Services/Banking
Employment Type: Project / Contract Assignment
Assignment Duration: 3–4 Months
Location: Andheri, Mumbai, Maharashtra
Reporting To: IT Audit Manager / Risk & Compliance Head
Job Summary
We are looking for an experienced IT Audit / IT Risk & Controls professional for a 3–4 month project assignment. The role will be responsible for evaluating IT General Controls (ITGC), application controls, information security controls, business continuity processes, and third-party/vendor risks.
The candidate will identify control gaps, assess associated risks, document audit findings, and provide practical remediation recommendations.
Key Responsibilities
1. IT General Controls (ITGC)
- Conduct ITGC audits across IT processes, systems, and infrastructure.
- Review and assess key IT controls related to:
User Access Management o Change Management o Incident Management
- Evaluate control design and operating effectiveness.
- Identify control gaps, exceptions, and potential risks.
1. Business Continuity & Disaster Recovery
- Assess Business Continuity Management (BCM) processes.
- Review Disaster Recovery (DR) plans, procedures, and controls.
- Evaluate backup processes, backup frequency, retention, and recovery procedures.
- Review evidence of DR/backup testing and identify gaps where applicable.
1. Application Controls
- Evaluate application-level controls to ensure data accuracy, completeness, and integrity.
- Review Input and Output controls.
- Assess Interface controls between applications and systems.
- Review Batch Job controls, scheduling, monitoring, and exception handling.
- Evaluate Encryption controls for data protection.
- Review application access controls and segregation of duties where applicable.
1. Vendor Risk Assessment
- Conduct Third-Party / Vendor Risk Assessments.
- Review vendor security and compliance documentation.
- Assess MSAs (Master Service Agreements) and SLAs/KPIs.
- Evaluate third-party controls related to information security, data protection, access, and service availability.
- Identify vendor-related risks and control gaps.
- Review third-party compliance with applicable organizational requirements.
1. Regulatory & Security Compliance
- Assess compliance with applicable regulatory requirements, data-handling standards, and information security policies.
- Review access management and security controls.
- Evaluate incident response processes and related controls.
- Identify deviations from defined security policies and procedures.
- Support risk-based assessment of identified control weaknesses.
1. Audit Reporting & Remediation
- Prepare detailed IT audit reports documenting observations and control gaps.
- Assess and assign appropriate risk ratings to audit findings.
- Develop practical remediation recommendations.
- Discuss findings with relevant IT, security, business, and vendor stakeholders.
- Track corrective actions and remediation status.
- Follow up on identified findings and support closure of audit observations.
Required Skills
- IT General Controls (ITGC)
- IT Audit
- Application Controls
- User Access Management
- Change Management
- Incident Management
- Business Continuity Management (BCM)
- Disaster Recovery (DR)
- Backup & Recovery Controls
- Application Security Controls
- Input/Output Controls
- Interface Controls
- Batch Job Controls
- Encryption Controls
- Vendor Risk Assessment
- Third-Party Risk Management
- MSA / SLA / KPI Review
- Information Security
- Data Protection & Compliance
- Risk Assessment
- Audit Reporting
- Remediation Tracking
Preferred Candidate Profile
- Bachelor's/Master's degree in Information Technology, Computer Science, Cybersecurity, Risk Management, or a related field.
- Relevant experience in IT Audit, IT Risk, ITGC, Information Security Audit, Application Controls, or Vendor Risk Management.
- Strong understanding of IT control frameworks and audit methodologies.
- Experience in preparing audit observations, risk ratings, and remediation plans.
- Solid analytical, documentation, and communication skills.
- Ability to work independently and complete project deliverables within defined timelines.
Pay: ₹50,000.00 - ₹55,000.00 per month
Work Location: In person
📌 IT General Controls, Application Controls & Vendor Risk Assessment (Andheri)
🏢 Long Shot Assignment
📍 Andheri