18 Sep
|
Hipotz
|
Bengaluru
Role: VP IT Internal Audit | Technology Issue Management
Location: Bengaluru
Experience: 812 years
Function: Internal Audit / Technology Risk / IT Controls
We are looking for an experienced technology auditor or technology-risk professional to join MUFGs Internal Audit team in Bengaluru. The role will own the validation, reporting and ongoing monitoring of technology issues arising from audit activity.
This is a senior individual-contributor and team-lead role. It requires sound independent judgement, solid written communication and the ability to challenge remediation evidence constructively while maintaining an objective third-line audit perspective.
Key responsibilities
- Own a portfolio of technology-related audit issues from assignment through validation and closure recommendation.
- Understand the original audit finding, risk rating, root cause, management action plan and expected remediation outcome.
- Develop or review test steps to assess whether remediation addresses the underlying risk and control deficiency.
- Evaluate control design, operating effectiveness, evidence quality and sustainability of remedial actions.
- Challenge incomplete, one-off or insufficient remediation evidence and recommend further action where required.
- Monitor issue ageing, milestones, dependencies, risk status and management commitments.
- Prepare clear issue-validation updates, reporting and escalation material for senior management and Audit Directors.
- Identify changes in residual risk and escalate overdue, ineffective or potentially recurring issues.
- Assign, guide and review the work of junior auditors or consultants on issue-validation activities.
- Support consistent application of audit methodology, documentation standards and quality expectations.
- Work with Technology, Information Security, Risk, Compliance, business stakeholders and global audit teams.
- Provide pragmatic, risk-based recommendations in a complex and evolving regulatory environment.
Mandatory requirements
- Bachelor’s degree in Computer Science, Information Systems, Accounting, Finance, Business Administration or a related discipline.
- 7–10 years of experience in IT audit, technology internal audit, technology risk, IT controls or a closely related risk-and-control function.
- Recent experience auditing or assessing information systems and technology controls.
- Demonstrable experience validating audit findings, remediation actions, management action plans or control improvements.
- Banking, financial-services, capital-markets, payments, insurance or another regulated BFSI environment.
- Supervisory, work-review or team-lead experience, preferably within the last three years.
- Strong understanding of audit methodology, risk assessment, evidence evaluation and issue reporting.
- One relevant professional certification, such as CISA, CIA, CISM, CISSP or CPA; certification status will be verified during the process.
- Excellent written and verbal communication, stakeholder-management and escalation skills.
- Ability to manage multiple issues and engagements independently and handle confidential information appropriately.
Preferred experience Experience in one or more of the following is desirable:
- IT general controls, application controls or SOX controls.
- Identity and access management, privileged access and Active Directory.
- Network infrastructure, firewalls, IDS/IPS, routers and switches.
- Databases including SQL Server, Oracle or DB2.
- Cloud computing and cloud-control assessment across AWS, Azure or GCP.
- Vulnerability, patch, incident, change, logging, backup, disaster-recovery or business-continuity controls.
- DLP, BYOD or mobile-security controls.
- COBIT, COSO, NIST, FFIEC, ITIL or ISO 27001/27000-series practices.
- Audit analytics, data analysis and evidence-driven reporting.
What this role offers
- Ownership of a visible technology-issue portfolio within a global banking group.
- Exposure to senior stakeholders and global Internal Audit colleagues.
- Opportunity to influence the quality, sustainability and risk clarity of technology remediation.
- A team-lead role combining independent judgement, audit execution and coaching.
- Exposure to a broad technology and control environment rather than a narrow recurring-testing remit.
Important clarification This is not a software-development, infrastructure-administration, SOC-monitoring or pure project-tracking role. The successful candidate must be able to independently assess whether technology remediation has genuinely reduced the underlying risk and communicate that judgement to senior stakeholders.
📌 VP - IT Internal Audit - Technology Issue Management (Bengaluru)
🏢 Hipotz
📍 Bengaluru