ISMS-IT Audit Director (Delhi)

ISMS-IT Audit Director (Delhi)

03 Sep
|
EY
|
Delhi

03 Sep

EY

Delhi

Director ITGC & ISMS (Information Technology General Controls & Information Security Management System)

Job Title

Director – ITGC & ISMS

Location- Delhi NCR

Experience

12-18+ years in IT Audit, Information Security, Risk Management, Compliance, and Governance with at least 5+ years in leadership roles.

Role Overview The Director – ITGC & ISMS will lead the organization's Information Technology General Controls (ITGC), Information Security Management System (ISMS), cybersecurity governance, and compliance programs. The role is responsible for establishing and maintaining a robust controls environment that aligns with regulatory requirements, industry standards, and business objectives.

The individual will partner closely with senior business leaders, technology teams, external auditors, and risk stakeholders to strengthen governance, manage cyber risks, and drive continuous compliance improvements across the enterprise.

Key Responsibilities

ITGC Leadership

- Develop and manage enterprise-wide ITGC frameworks and control programs.
- Oversee design, implementation, and testing of IT General Controls across key systems and applications.
- Lead ITGC assessments supporting SOX, internal audits, and external audit requirements.

- Ensure effective management of

- User Access Management

- Privileged Access Controls

- Change Management

- IT Operations Controls
- Backup & Recovery Controls

- Interface Monitoring Controls

ISMS Governance

- Own and maintain the organization's ISMS framework aligned with ISO 27001 standards.
- Lead ISO 27001 certification, surveillance audits, and recertification activities.
- Ensure continual improvement of security policies, standards, procedures, and control frameworks.
- Monitor compliance with security governance requirements across business functions.

Risk Management & Compliance

- Drive enterprise IT risk management initiatives.
- Conduct risk assessments and control gap analyses.

- Ensure compliance with

- ISO 27001

- SOX

- COBIT

- NIST

- GDPR/Data Privacy requirements
- Industry-specific regulatory frameworks
- Present key risk indicators and compliance metrics to executive leadership.

Audit & Assurance

- Serve as the primary point of contact for internal and external auditors.




- Lead audit planning, execution support, remediation tracking, and closure.
- Ensure timely resolution of audit findings and control deficiencies.
- Establish sustainable controls to reduce recurring audit observations.

Security Governance & Strategy

- Provide strategic direction for information security governance programs.
- Review and approve security standards and policies.
- Drive security awareness and compliance initiatives across the organization.
- Support business transformation projects by embedding security and compliance requirements.

Team Leadership

- Lead and mentor managers, consultants, and auditors.
- Build high-performing governance, risk, and compliance teams.
- Develop talent pipeline and succession planning strategies.
- Foster a culture of accountability, continuous improvement, and risk awareness.

Stakeholder Management

- Collaborate with CIO, CISO, Risk, Legal, Compliance, and Business Leaders.
- Present security, audit, and compliance updates to executive leadership and governance committees.
- Influence enterprise-wide decisions related to risk management and security investments.

Required Qualifications

- Bachelor’s degree in information technology, Computer Science, Cybersecurity, or related discipline.
- Master's degree preferred.
- 12-18+ years of relevant experience in IT Audit, ISMS, Governance, Risk, and Compliance.
- Demonstrated experience leading large-scale ITGC and ISMS programs.

Preferred Certifications One or more of the following:

- CISA (Certified Information Systems Auditor)
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- ISO 27001 Lead Implementer
- ISO 27001 Lead Auditor
- CRISC (Certified in Risk and Information Systems Control)
- CGEIT
- COBIT Certification

Required Skills

Technical Skills

- IT General Controls (ITGC)




- SOX Compliance
- ISO 27001 ISMS
- Information Security Governance
- IT Risk Management
- Cybersecurity Frameworks
- COBIT
- NIST
- Internal Controls Testing
- Data Privacy & Regulatory Compliance
- SAP Security & GRC (preferred)
- Cloud Security Governance (Azure, AWS, GCP)

Leadership Skills

- Strategic Planning
- Executive Stakeholder Management
- Team Leadership
- Program Management
- Audit & Compliance Management
- Risk-Based Decision Making

Key Performance Indicators (KPIs)

- ITGC testing effectiveness and compliance scores

- Reduction in audit observations
- ISO 27001 certification success and audit outcomes

- Risk remediation closure timelines

- Compliance maturity improvements
- Policy adherence and governance metrics
- Stakeholder satisfaction and regulatory readiness
- Looking for a Risk Consulting professional, not a core technical or cyber security specialist.
- Strong experience in Risk & Compliance, Internal Audit, ITGC, ITAC, and SOX engagements is essential.
- Cyber security exposure is positive to have, but not mandatory. Avoid profiles that are heavily focused on cyber security.
- Candidates should have experience managing General IT Controls (ITGC), IT Application Controls (ITAC), and ERP Pre- and Post-Implementation Reviews.
- Familiarity with ISO 27001 and ISO 42001 frameworks is preferred.
- Seeking a Team Manager / People Manager who can act as the right-hand support .
- Strong client-facing experience is critical, particularly with local/domestic clients across Internal Audit and External Audit engagements.
- Candidates from Global Capability Centers (GCCs) are not preferred.
- Profiles focused primarily on Financial Services (FS) or GCC environments should be avoided.
- Industry candidates with limited consulting or client management exposure may not be ideal.
- The ideal candidate should have a strong background in:

- Risk Consulting
- Governance, Risk & Compliance (GRC)

- Internal Audit

- SOX Compliance

- IT General Controls (ITGC)

- IT Application Controls (ITAC)
- ERP Pre & Post Implementation Reviews
- ISO 27001 / ISO 42001

- Client Relationship Management
- Team Leadership and People Management

📌 ISMS-IT Audit Director (Delhi)
🏢 EY
📍 Delhi

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: isms-it audit director (delhi) / delhi

Subscribe to this job alert:

Get the latest job offers by email for: isms-it audit director (delhi) / delhi