Assistant Manager - Internal Audit
- Location not stated
- Manager or above
- 2 days ago
- Regulatory Compliance
- ISO 27001
- NIST
- COBIT
- Active Directory
- Change Management
- SIEM
- Vulnerability Management
- Incident Response
- DLP
- Risk Management
- Network Security
- IAM
- Azure
- AWS
- GCP
- DevSecOps
- Disaster Recovery
- AI
- Machine Learning
- CIS Controls
- Excel
- PowerPoint
- Power BI
- CISA
- CISSP
|
Position Title |
Assistant Manager/Manager |
|
Department |
Internal Audit |
|
Level/ Band |
301 |
Role Summary:
Experienced IT Internal Auditor responsible for leading and executing risk-based audits across IT infrastructure, applications, cybersecurity, cloud, data management, and third-party risk domains. Conducts end-to-end audit engagements, evaluates ITGCs, ITACs, cybersecurity, and regulatory compliance controls, and assesses technology risks impacting business operations. Identifies control gaps, recommends risk mitigation measures, and ensures adherence to IRDAI, ISO 27001, NIST, COBIT, and other applicable frameworks. Collaborates with business and technology stakeholders to deliver audit insights, strengthen governance, improve control effectiveness, and support organizational resilience.
A.Organizational Relationships
|
Reports To |
AVP / Sr. Manager Internal Audit |
|
Supervises |
Individual contributor |
Job Dimensions
|
Geographic Area Covered |
Pan - India. All Departments |
|
Internal Stakeholders |
Head of Audit Senior Management / All Departments - management categories |
|
External Stakeholders |
NA |
B.Key Result Areas
|
·Perform risk-based IT audits across Infrastructure, Applications, Information Security, Cyber Security, Cloud, Data Management, Third-Party Risk, and Emerging Technology domains as per the approved audit plan. ·Lead end-to-end audit engagements, including audit planning, scope discussions, kick-off meetings, walkthroughs, risk assessments, fieldwork, control testing, stakeholder interactions, reporting, and audit closure. ·Review previous audit reports and validate closure of outstanding audit observations and management action plans. ·Prepare Risk Assessment Matrices (RAM), identify key risks and controls, and develop audit programs aligned with business, technology, and regulatory risks. ·Assess and audit IT General Controls (ITGCs) across applications, operating systems, databases, network infrastructure, Active Directory, middleware, and virtualized environments, covering Access Management, Change Management, IT Operations, and IT Service Management controls. ·Perform IT Application Controls (ITAC) reviews, including automated controls, interface controls, workflow controls, configuration controls, report controls, and system-generated reports. ·Assess Cyber Security governance and operational controls, including SOC operations, SIEM monitoring, vulnerability management, incident response, threat monitoring, endpoint security, and cyber resilience programs. ·Perform audits of Data Security controls, including data classification, encryption, data loss prevention (DLP), data retention, backup security, and protection of sensitive customer information. ·Evaluate Third-Party and Outsourcing Risk Management controls in line with organizational policies, Information Security standards, and IRDAI requirements. ·Assess compliance with IRDAI Information & Cyber Security Guidelines, Technology Governance requirements, Operational Resilience expectations, and other applicable regulatory obligations. ·Perform compliance, substantive, and control effectiveness testing to assess the adequacy, design, and operating effectiveness of key controls and identify areas of improvement. ·Prepare and maintain audit workpapers, testing documentation, observations, conclusions, and supporting evidence in TeamMate (TM) in accordance with audit methodology and quality standards. ·Identify control gaps, process weaknesses, compliance deviations, and emerging risks; recommend practical remediation actions and process improvements. ·Discuss audit observations with business and technology stakeholders, validate factual accuracy, obtain management responses, and draft audit reports as per Internal Audit methodology. ·Present audit findings to audit management, support quality assurance reviews, monitor remediation progress, track closure of audit observations, and participate in special reviews, fraud investigations, business continuity, contingency planning, and risk mitigation initiatives. ·Participate in risk mitigation plans, contingency planning, business continuity programs by executing and reporting within defined timelines. Highlight and recommend process gaps, flaws and process changes. |
C.Skills Required
|
Technical |
|
A.Incumbent Characteristics
|
|
Essential |
Essential |
|
Qualification |
MBA IT/BE/B.Sc IT/M.Tech |
Certification in CISA / CISSP / CIA / ISO 27001 / ISO 22301 |
|
Experience |
5 - 8 years in IT Audit |
Preferably in life insurance / financial / BFSI services sector/ BIG 4. |
Assistant Manager - Internal Audit · Tata AIA Life Insurance