29 Aug
|
NEC
|
Navi Mumbai
Role & responsibilities: :-
Looking a person who can support the organizations IT Governance, Risk, and Compliance (GRC) program by executing risk assessments, compliance tracking (RBI/Head Office), control testing, and audit coordination activities. The role is primarily an individual contributor who works under the guidance of the IT GRC Lead/Manager.
Preferred candidate profile :-
1. IT Governance (Execution Support)
- Support maintenance of IT governance frameworks aligned to RBI Master Directions.
- Help compile and publish periodic IT security governance reports (metrics, KRIs/KPIs, compliance status).
- Support process alignment activities by mapping IT controls to internal standards and business requirements.
1. IT Risk Management (Hands-on Assessments)
- Conduct IT/cyber risk assessments for applications, infrastructure, networks, and end-user computing environments.
- Support data risk classification and maintain information asset inventory (classification, ownership, inherent risk).
- Review security evidence from a control perspective, including:
- SIEM alerts/reports (triage support, trend reporting, control gaps)
- Firewall rule reviews (basic hygiene checks, documentation, approvals)
- Network/security device configuration evidence (as provided by Infra/SecOps)
- Track risk treatment plans and follow up closure items with IT and business owners.
- Participate in security awareness activities (campaign support, reporting completion metrics).
1. Compliance & Regulatory Reporting (Tracking + Evidence)
- Track RBI circulars/advisories applicable to IT and cyber security; support impact assessment documentation.
- Prepare compliance checklists and evidence packs for RBI and Head Office reporting.
- Monitor reporting calendars and due dates (e.g., CSITE or internal mandated submissions) and escalate risks of delay to the GRC Lead.
- Support implementation tracking for mandated controls and document compliance status.
1. IT Audit Management (Coordination + Closure Tracking)
- Support audit activities as part of the audit management team:
- Evidence collection, control walkthrough scheduling, documentation support
- Maintain audit trackers for internal/external audits, including observation status and closure evidence.
- Support closure of audit findings by coordinating with control owners and validating remediation evidence.
- Contribute to continuous control improvement actions identified through audits and risk assessments.
Role Requirements Education & Experience
- Any Graduate
- 10 years experience in IT GRC / IT Risk / Compliance / IT Audit (preferably in Banking/Financial Services)
Knowledge & Skills (Expected at 10 Years)
- Working knowledge of RBI IT/cyber security expectations and banking audit practices.
- Strong execution capability in:
- IT risk assessment documentation and risk registers
- Control evidence review and compliance tracking
- Audit coordination and observation closure documentation
- Familiarity with SIEM reporting concepts, VA/PT governance tracking, and baseline security controls.
- Positive communication and stakeholder coordination skills across IT, InfoSec, and audit teams.
Preferred Certifications
- CISA / ISO 27001 Internal Auditor or LA (preferred)
📌 Risk Control and governance- Finance SME (Navi Mumbai)
🏢 NEC
📍 Navi Mumbai