IT General Controls, Application Controls & Vendor Risk Assessment (Andheri)

IT General Controls, Application Controls & Vendor Risk Assessment (Andheri)

21 Aug
|
Long Shot Assignment
|
Andheri

21 Aug

Long Shot Assignment

Andheri

– IT General Controls, Application Controls & Vendor Risk Assessment

Position: IT Audit / IT Risk & Controls Consultant

Department: Information Technology Audit / Risk & Compliance

Industry: Financial Services/Banking

Employment Type: Project / Contract Assignment

Assignment Duration: 3–4 Months

Location: Andheri, Mumbai, Maharashtra

Reporting To: IT Audit Manager / Risk & Compliance Head

Job Summary

We are looking for an experienced IT Audit / IT Risk & Controls professional for a 3–4 month project assignment. The role will be responsible for evaluating IT General Controls (ITGC), application controls, information security controls, business continuity processes, and third-party/vendor risks.

The candidate will identify control gaps, assess associated risks, document audit findings, and provide practical remediation recommendations.

Key Responsibilities

1. IT General Controls (ITGC)

- Conduct ITGC audits across IT processes, systems, and infrastructure.
- Review and assess key IT controls related to:

User Access Management o Change Management o Incident Management
- Evaluate control design and operating effectiveness.
- Identify control gaps, exceptions, and potential risks.

1. Business Continuity & Disaster Recovery

- Assess Business Continuity Management (BCM) processes.
- Review Disaster Recovery (DR) plans, procedures, and controls.
- Evaluate backup processes, backup frequency, retention, and recovery procedures.
- Review evidence of DR/backup testing and identify gaps where applicable.

1. Application Controls

- Evaluate application-level controls to ensure data accuracy, completeness, and integrity.




- Review Input and Output controls.
- Assess Interface controls between applications and systems.
- Review Batch Job controls, scheduling, monitoring, and exception handling.
- Evaluate Encryption controls for data protection.
- Review application access controls and segregation of duties where applicable.

1. Vendor Risk Assessment

- Conduct Third-Party / Vendor Risk Assessments.
- Review vendor security and compliance documentation.
- Assess MSAs (Master Service Agreements) and SLAs/KPIs.
- Evaluate third-party controls related to information security, data protection, access, and service availability.
- Identify vendor-related risks and control gaps.
- Review third-party compliance with applicable organizational requirements.

1. Regulatory & Security Compliance

- Assess compliance with applicable regulatory requirements, data-handling standards, and information security policies.
- Review access management and security controls.
- Evaluate incident response processes and related controls.
- Identify deviations from defined security policies and procedures.
- Support risk-based assessment of identified control weaknesses.

1. Audit Reporting & Remediation

- Prepare detailed IT audit reports documenting observations and control gaps.




- Assess and assign appropriate risk ratings to audit findings.
- Develop practical remediation recommendations.
- Discuss findings with relevant IT, security, business, and vendor stakeholders.
- Track corrective actions and remediation status.
- Follow up on identified findings and support closure of audit observations.

Required Skills
- IT General Controls (ITGC)
- IT Audit
- Application Controls
- User Access Management
- Change Management
- Incident Management
- Business Continuity Management (BCM)
- Disaster Recovery (DR)
- Backup & Recovery Controls
- Application Security Controls
- Input/Output Controls
- Interface Controls
- Batch Job Controls
- Encryption Controls
- Vendor Risk Assessment
- Third-Party Risk Management
- MSA / SLA / KPI Review
- Information Security
- Data Protection & Compliance
- Risk Assessment
- Audit Reporting
- Remediation Tracking

Preferred Candidate Profile
- Bachelor's/Master's degree in Information Technology, Computer Science, Cybersecurity, Risk Management, or a related field.
- Relevant experience in IT Audit, IT Risk, ITGC, Information Security Audit, Application Controls, or Vendor Risk Management.
- Strong understanding of IT control frameworks and audit methodologies.
- Experience in preparing audit observations, risk ratings, and remediation plans.
- Solid analytical, documentation, and communication skills.
- Ability to work independently and complete project deliverables within defined timelines.

Pay: ₹50,000.00 - ₹55,000.00 per month

Work Location: In person

📌 IT General Controls, Application Controls & Vendor Risk Assessment (Andheri)
🏢 Long Shot Assignment
📍 Andheri

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: it general controls, application controls & vendor risk assessment (andheri) / andheri

Subscribe to this job alert:

Get the latest job offers by email for: it general controls, application controls & vendor risk assessment (andheri) / andheri