20 Sep
|
INTERCERT
|
Noida
IT Regulatory Auditor – BFSI, Cybersecurity & Compliance
Location: Noida
Work Mode: On-site
Employment Type: Full time
Experience: 3–4 Years
About INTERCERT
INTERCERT is a CREST Member Company and an Accredited Certification Body providing cybersecurity, regulatory compliance, assurance, and certification services across India and international markets.
Our expertise covers Information Security Audits, Regulatory Compliance Assessments, Cybersecurity Audits, Data Privacy, GRC, Certification Audits, and Security Assurance Services. We work with organisations across BFSI, government, critical infrastructure, telecom, healthcare, and other industries.
About the Role
We are looking for an experienced IT Regulatory Auditor with strong knowledge of cybersecurity, regulatory compliance, IT audits, information security, governance, risk management, and BFSI regulations.
The candidate will be responsible for planning, leading, and executing regulatory, cybersecurity, compliance, and information security audits for regulated entities across the BFSI sector and other critical industries.
The role involves working closely with CXOs, CISOs, Compliance Officers, Regulators, Internal Audit Teams, Technology Teams, and Business Leaders throughout the audit lifecycle.
Key ResponsibilitiesRegulatory & IT Audits
- Lead and execute IT, cybersecurity, and regulatory compliance audits.
- Conduct gap assessments, compliance reviews, and regulatory readiness assessments.
- Prepare detailed audit reports, executive summaries, and remediation recommendations.
- Validate closure of audit findings and support clients during regulatory inspections.
Regulatory Compliance
Hands-on experience with one or more of the following regulatory frameworks is preferred:
- RBI: Digital Lending Regulations, IT Governance, Outsourcing of IT Services, IT Vendor Risk Management, Cyber Security Framework, Information Security Guidelines, and IT Examination & Compliance Audits.
- SEBI: Cyber Security & Cyber Resilience Framework, Information Security Compliance, and Regulatory Audits.
- IRDAI: Information Security Guidelines,
Cyber Security Framework, Information Systems Audits, and Regulatory Compliance Assessments.
- NPCI: Information Security Compliance, UPI Security Audits, Payment Switch Security, and NPCI Audit Requirements.
- CERT-In: CERT-In Directions, Information Security Audits, VAPT Report Reviews, Incident Response Readiness, Log Retention, and Security Monitoring.
- Data Privacy: DPDP Act, 2023, Privacy Impact Assessments, Data Protection Assessments, Data Governance, Data Classification, and Privacy Compliance Reviews.
Other Audit & Compliance Engagements
Experience in one or more of the following areas:
- Internal IT Audits
- Information Security & Cybersecurity Audits
- IT General Controls (ITGC)
- Vendor & Third-Party Risk Assessments
- Cloud Security Reviews
- Business Continuity & Disaster Recovery Audits
- Technology & Operational Risk Assessments
- Regulatory Readiness Assessments
- OC-87 and Section 8 Compliance Audits
Certification & Assurance
- Support certification readiness and assurance engagements.
- Conduct information security certification audits.
- Perform technical and risk reviews.
- Assess control effectiveness and compliance maturity.
- Conduct governance reviews and client readiness programmes.
- Support internal quality and audit documentation reviews.
Technical Skills
Strong understanding of:
- Information Security & IT Governance
- Cybersecurity & Risk Management
- IT General Controls (ITGC)
- Identity & Access Management (IAM)
- Cloud, Network & Endpoint Security
- Security Operations, SIEM & Security Monitoring
- Vulnerability & Patch Management
- Secure Configuration Reviews
- Encryption & Key Management
- Data Loss Prevention (DLP)
- Vendor & Third-Party Risk Management
- Business Continuity & Disaster Recovery
- Security Architecture and Audit Methodologies
Frameworks & Standards
Hands-on experience with one or more of:
- ISO/IEC 27001
- NIST Cybersecurity Framework (CSF)
- COBIT
- CIS Controls
- SWIFT Customer Security Controls Framework (CSCF)
Qualifications
- Bachelor's or Master's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, Electronics, or a related discipline.
- 3–4 years of experience in Information Security Audits, IT Audits, Cybersecurity Audits, Regulatory Compliance, GRC, or Risk Advisory.
Preferred Certifications
One or more of the following will be an advantage:
- CISA
- CEH
- ISO/IEC 27001 Lead Auditor
- Certified Data Privacy Professional (CDPP) or equivalent
- CERT-In Recognised Information Security Auditor Qualification
Preferred Industry Experience
Candidates with experience in the following are preferred:
- CERT-In Empanelled Audit Organisations
- CREST Member Organisations
- Cybersecurity Consulting Firms
- NBFCs & FinTech Companies
- Insurance Companies
- Government Organisations
- Critical Information Infrastructure
Key Competencies
- Strong analytical and problem-solving skills
- Excellent report writing and documentation skills
- Ability to interpret and apply regulatory requirements
- Excellent verbal and written communication
- Client-facing and stakeholder management skills
- Project planning and audit management
- Leadership and mentoring capabilities
- High level of integrity and professional ethics
- Ability to manage multiple audit engagements simultaneously
Key Skills
IT Audit | Regulatory Audit | Cybersecurity Audit | BFSI Compliance | RBI | SEBI | IRDAI | NPCI | CERT-In | ITGC | GRC | ISO 27001 | NIST | COBIT | Cybersecurity | Risk Assessment | Information Security | Data Privacy | Vendor Risk | Cloud Security | Audit & Compliance
Pay: ₹394,026.83 - ₹1,671,678.74 per year
Benefits:
- Health insurance
- Leave encashment
- Life insurance
- Paid sick time
Work Location: In person
📌 IT Regulatory Auditor – BFSI, Cybersecurity & Compliance (Noida)
🏢 INTERCERT
📍 Noida