Job Description
Role Snapshot
n
n
Role Title
n
Audit Manager - Systems Audit & Access Governance
n
Department
n
System and Process Audit
n
Location
n
Tirupur, Tamil Nadu (on-site; travel within group companies as required)
n
Team
n
Build and lead a team of 2–4 audit analysts
n
Experience
n
8–14 years in IT / Systems Audit or ERP Access Governance
n
Qualifications
n
CA Intermediate / MBA (Finance or IT) / CPA / ACCA
n
Certifications
n
CISA preferred — CISSP / CIA / CRISC advantageous
n
Industry
n
Manufacturing / Textiles / Retail — Multi-ERP, multi-application environment
n
n
Role Purpose
n
Single owner of user access governance, controls assurance, process audit, and continuous systems improvement across the entire application landscape. Hands-on and board-facing — equally comfortable extracting raw ERP data and presenting risk findings. We want someone dynamic and raring to make a measurable difference, not a passive reviewer.
n
n
Key Responsibilities
n
n
01 User Access Review
n
Reconcile all ERP/app accounts against live HR records; disable leavers and dormant users; establish JML process; maintain User Access Register with quarterly owner-certification cycles.
n
02 Segregation of Duties
n
Build role-to-function matrices; apply SoD rule library to identify conflicts (e.g. create-vendor/approve-payment); prioritise by risk; track remediation in a living Risk Register.
n
03 Least Privilege
n
Compare assigned permissions vs actual usage; produce Entitlement Heat Map; drive rationalisation programmes; establish bi-annual re-certification for all privileged accounts.
n
04 Access Control Vulnerabilities
n
Assess authentication, MFA coverage,
PAM controls, API/middleware gaps, and logging adequacy; produce prioritised Vulnerability Register with risk ratings and mitigations.
n
05 Management Reporting & Follow-Up
n
Prepare risk-rated audit reports; maintain CAP tracker; conduct monthly follow-up reviews; escalate overdue critical actions; produce Quarterly Governance Dashboard for the board.
n
06 Process Controls Review
n
Walkthrough P2P, O2C, R2R, H2R and Inventory cycles; identify control gaps and single points of failure; recommend preventive/detective controls; re-audit remediated areas.
n
07 Redundancy & Productivity
n
Identify duplicate functions, unused modules, and manual re-keying steps; quantify effort cost; prepare rationalisation business cases with productivity impact projections.
n
08 AI & Advanced Analytics
n
Deploy AI anomaly detection; run SQL/Python/ACL population-level tests; automate reconciliations via RPA; design Continuous Monitoring Framework with real-time risk dashboards.
n
09 Analytical Reporting & Abnormality Detection
n
Prepare data-driven reports with Benford's Law, duplicate-payment, and three-way match tests; profile user behaviour anomalies; produce consolidated Master Exception Reports.
n
10 Master Data Governance
n
Review Vendor, Customer, Item,
CoA and Employee masters for duplicates and orphaned records; detect unauthorised changes; implement governance framework with data stewards and cleanse cycles.
n
n
Education & Certifications
n
n
- CA Intermediate / MBA (Finance or IT) / CPA / ACCA
n
- CISA strongly preferred
n
- CIA / CISSP / CRISC / SAP GRC advantageous
n
- A Degree/Diploma in CS or any IT field is a plus
n
n
n
Experience
n
n
- 8–14 years in IT/Systems Audit or ERP Access Governance
n
- Hands-on with ≥ 2 years of: SAP, Oracle, MS Dynamics or equivalent
n
- SoD analysis, access reviews, and least privilege in multi-system environments
n
- Board-level audit reporting and CAP closure track record
n
- Manufacturing / Textiles / FMCG background preferred
n
n
Technical Skills
n
n
- ERP user admin, role config, authorisation, and log extraction
n
- SQL / Python / ACL / IDEA for population-level data testing
n
- Power BI / Tableau for management dashboards
n
- AI anomaly detection and LLM-assisted audit tools
n
- RPA / scripting for audit automation
n
- ISO 27001, COBIT, ITIL, SOX awareness
n
n
n
Behavioural
n
n
- Energetic, action-oriented — finds problems and drives resolution
n
- Translates technical findings into plain board-level language
n
- Owns findings through to closure, not just the report
n
- Resilient — comfortable raising uncomfortable truths
n
- Hunger to learn and adopt new tools and techniques
n
n
n
Work Schedule: 6 Days Working (Monday – Saturday)
n
Timings: 9:00 AM to 6:00 PM
n
Mode: Work From Office (WFO )
n
n
Interested candidates kindly share your updated resume to
[email protected]
n
📌 Audit Manager - Systems Audit & Access Governance (Tiruppur)
🏢 Ramraj Cotton
📍 Tiruppur