27 Sep
|
Kalkine Solutions
|
Noida
27 Sep
Kalkine Solutions
Noida
Role & responsibilities
- Conduct IT, Information Security, Compliance and Operational Audits as per the Internal Audit Plan.
- Assess controls and compliance against ISO/IEC 27001:2022 (ISMS), PCI DSS v4.x and SOC 2 Type II requirements.
- Conduct operational and process audits across Engineering & Digital, IT, Information Security and selected Sales/business functions.
- Manage the end-to-end audit lifecycle, including planning, risk assessment, walkthroughs, control testing, evidence collection, reporting and follow-up.
- Review policies, SOPs, system configurations and processes against applicable control and compliance requirements.
- Evaluate the design and operating effectiveness of internal controls and identify control gaps, non-compliances and operational risks. Recommend practical corrective actions/CAPAs and agree action plans and closure timelines with process owners.
- Prepare clear and concise audit reports, covering observations, risks/impact, root causes and recommendations.
- Track audit findings and perform follow-up and closure validation of agreed corrective actions.
- Conduct/support Management Review Meetings (MRM) and coordinate with internal stakeholders and external auditors/assessors.
- Maintain appropriate audit working papers, evidence, checklists, risk control matrices and documentation.
- Demonstrate strong analytical, stakeholder management, communication and report-writing skills, with proficiency in Microsoft Office.
PREFERRED TECHNICAL KNOWLEDGE Working knowledge/basic understanding of:
- Network Security, Firewalls and Security Configurations
- Active Directory, IAM and Privileged Access Management Windows/Linux and Cloud environments (AWS/Azure)
- Endpoint Security, Antivirus and EDR
- Vulnerability Assessment, Patch and Change Management
- Backup, Disaster Recovery and Business Continuity
- Log Monitoring, SIEM and Incident Management
- Secure SDLC and application security controls
- Data Protection and Third-Party/Vendor Risk Management
QUALIFICATIONS & KEY COMPETENCIES
- Bachelors degree in computer science, IT, Cyber Security, Engineering or related field.
- Relevant experience in IT/Internal Audit, Information Security, Compliance or Risk Management.
- Experience in IT and operational/process audits, preferably covering Engineering, Digital and IT functions.
- Working knowledge of ISO/IEC 27001:2022, PCI DSS and SOC 2 Type II.
- Certifications such as ISO 27001 Internal/Lead Auditor, CISA, CISM or CRISC are preferred but not mandatory.
- Valuable understanding of risk-based auditing, internal controls and control testing.
- Strong analytical, communication, stakeholder management and report writing skills.
- Ability to work independently, manage multiple audits and meet timelines.
- High level of integrity, objectivity and confidentiality.
- Willingness to stay updated on emerging technologies, risks and compliance requirements.
📌 Techinal AND Process Auditor (Noida)
🏢 Kalkine Solutions
📍 Noida