IT Audit Risk Assessment

1 week ago


Bengaluru, India Talent Worx Full time

IT Advisory Risk Consulting—IT Audit & Assurance  Our client’s IT Advisory – Risk Consulting team is looking for Associate Consultants/ Consultants/ Assistant Managers to join their IT Audit & Assurance team in Bengaluru. Team provides Independent assurance on controls in place across client’s IT environment and ways to mitigate Technology risks.  Following are some of our key solution offerings Risk Based IT Internal Audit IT SOX 404 Controls Testing, Quality Assurance Internal Financial Controls related to IT General Controls  IT General Controls as part of Financial Statements Audits IT Risk & Control Self-Assessment  Business Systems Controls / IT Application Controls  Auditing Emerging Technologies such as Cloud Security, Intelligent Automation, RPA, IoT etc. IT Attestation (SOC1/SOC2/ISAE 3402, ISAE 3000 etc.) Third Party/Vendor Risk Assessments  Position: Associate Consultants/ Consultants/ Assistant Managers Location: Bengaluru   Requirements Industry Experience: Plan, budget and execute the day-to-day activities of infrastructure audit engagements for clients Assess client's security landscape, assess, evaluate and recommend most suitable security solution, tools & techniques to create a threat resilient landscape using our client's differentiated approach and methodologies. Provide security concept, framework & standards for development & support client teams for the solution design, customization build and roll out to end users.  Perform a holistic security risk assessment of the client’s IT landscape taking various assets, threats, vulnerabilities, business impact & legal aspects into consideration. Designing and implementing controls to mitigate identified risks by lucid communication to client stakeholders. Effective persuasive/convincing abilities while communicating gaps detected during audits, risk assessments, attestation engagements.           Collaborate with other practice groups to review the effects of new threats and vulnerabilities in the security space to assess, remediate, test and protect client application artefacts, data and enterprise ecosystems from threat vectors as they emerge.  Work with other technology groups to provide cohesive solutions in Risk assessments, Financial statement audits, Attestation engagements encompassing network architecture, application, database, , standards and implementation related mandates for development, deployment and maintenance.  Manage teams delivering co-working discovery workshops & support delivery teams to provide assessment, remediation, testing and standards refresh for the application security practice.  Present and distill complex Security solutions into simple, easy to understand concepts for both technical and non-technical audiences especially in the context of opportunity pursuit.  Drive Innovation through Offerings: — Drive profitable growth through the execution of the strategy and the strengthening of the audit and assurance practice  Building innovative & collaborative solutions to bring combined offerings such as security related combinations with J2C, API, Data security as advisory & execution footprint to capture opportunities & illustrate convergence  Bring the audit and assurance practice to life to achieve sales and commercial opportunities in a collaborative ecosystem and follow through with support for cost effective high quality execution.  Additional Responsibilities for Assistant Managers: Supervise associates and interns on engagements Serve as a liaison between financial services clients and upper management Establish and sustain long-term profitable client relationships that drive value creation, delivery excellence and a positive client work environment Works with the client to minimize delivery disruptions and effectively manages client urgencies.Qualifications Engineering / MBAs with atleast 6+ years of experience  3+ years of experience with hands on exposure to Infrastructure / Mobile/ Web application security spanning across various technologies.  Working level familiarity of advanced security assessment concepts, including but not limited to –, Malware analysis, OT/ICS security, Cloud security, security in IoT, Blockchain, RPA and emerging technologies, etc.  Working level familiarity with Static and Dynamic Analysis tools (SAST, DAST, IAST). Ability to manage deployment & use of OWASP tools and methodologies.  Ability to elucidate vulnerabilities and weaknesses in the OWASP Top10,WASCTCv2, SANS Top-25 and CWE25 to client IT/ISO audiences and discuss effective defensive techniques.  Comprehensive understanding and previous oversight of IT hardware, software, networking, databases, API services, J2C storage, licensing and related hosting needs. Infrastructural configuration reviews to identify the security related gaps within the IT environment Preference would be given to significant experience in relevant technical knowledge: (a) financial statement – IT  Audits; (b) IT internal or IT operations audits; (c) IT SOX engagements (d) Emerging Technology Risks (e) Data Privacy and PCI-DSS risks Good to have, add on skills - Working level familiarity with relevant vulnerability scanning tools (e.g., Qualys, Nessus, Nexpose, Saint or any other open source tools). Working level familiarity with web application vulnerability scanning tools (e.g. IBM AppScan, HP Fortify, Accunetix, NTO Spider, Burpsuite Pro or any other open source tools), SIEM tools (SolarWinds, Splunk, LogRhythm, IBM QRadar)  Ability to understand/identify best practices for infrastructure process and controls. CISA, CISM, CISSP, CRISC, TOGAF certifications would be an added advantage Prior experience in client facing / account management roles Possess strong domain knowledge, understanding of IT processes supporting business and possible risks in operations of at least two industry sectors Demonstrate integrity, values, principles, and work ethic and lead by example Benefits Work with one of the Big 4's in India Healthy work Environment Work Life Balance


  • IT Risk Assessment

    2 weeks ago


    Bengaluru, India NetConnect Global Full time

    Job description **Location**: Bangalore **Mode of Work**: Hybrid **Experience required**: 4-11 years **Mandatory Skills**: Information Security, Risk Assessment, ITGC, Vlunberality Assessment, ISO27001, Third-Party Security **Secondary Skills**: Control Testing, Penetration Testing, Gap Analysis, IT Infrastructure, Incident Management, SOX, NIST,...

  • Risk Assessment

    2 weeks ago


    Bengaluru, Karnataka, India KPMG Assurance and Consulting Services LLP Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    ROLE & RESPONSIBILTY:Conduct thorough and detailed cyber risk assessments for our clients, analyzing their digital infrastructure, systems, and security controls.Collaborate with cross-functional teams to gather essential information and data required for comprehensive risk assessments.Evaluate and interpret assessment results to identify potential...

  • Risk Assessment

    3 days ago


    Bengaluru, Karnataka, India KPMG Assurance and Consulting Services LLP Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    ROLE & RESPONSIBILTY:Conduct thorough and detailed cyber risk assessments for our clients, analyzing their digital infrastructure, systems, and security controls.Collaborate with cross-functional teams to gather essential information and data required for comprehensive risk assessments.Evaluate and interpret assessment results to identify potential...

  • Risk Assessment

    6 days ago


    Bengaluru, India Talent Worx Full time

    Talworx is hiring! Our client in India, a professional services firm, is the Indian member firm affiliated. Our professionals leverage the global network of firms, providing detailed knowledge of local laws, regulations, markets, and competition. Our client has offices across India in Ahmedabad, Bengaluru, Chandigarh, Chennai, Gurugram, Hyderabad, Jaipur,...

  • Risk Assessment

    2 weeks ago


    Bengaluru, Karnataka, India Talent Worx Full time ₹ 12,00,000 - ₹ 24,00,000 per year

    Talworx is hiringOur client in India, a professional services firm, is the Indian member firm affiliated. Our professionals leverage the global network of firms, providing detailed knowledge of local laws, regulations, markets, and competition. Our client has offices across India in Ahmedabad, Bengaluru, Chandigarh, Chennai, Gurugram, Hyderabad, Jaipur,...


  • Bengaluru, India Virtusa Full time

    Job Description Location: Hybrid (Pan-India as per operating locations) Department: Strategy Reports to: Chief Risk Officer (CRO) Job Summary We are seeking an experienced and highly motivated Global Risk Assessment Manager to lead and support our global risk assessment program. As part of the Enterprise Risk Management function, this role will be...


  • Bengaluru, India NAZZTEC Full time

    We are seeking a skilled Cybersecurity Risk Assessment Specialist with 5+ years of relevant experience to join our Information Security team. The ideal candidate will be responsible for conducting enterprise-wide risk assessments, identifying security gaps, ensuring compliance with international frameworks, and strengthening the organization’s overall...

  • IT Risk Assessment

    2 weeks ago


    Bengaluru, India Promaynov Advisory Full time

    Hi all, Promaynov is currently hiring for BIG 4 Role -IT Risk Assessment Location -Bangalore Experience - 4-9 years **Responsibilities**: 1. Good communication skills 2. Knowledge on Application Infrastructure Architecture 3. IT Risk assessment (ITRA) experience 5. Knowledge on Database and Middleware communication 6. Knowledge on API security 7....


  • Bengaluru, Karnataka, India Virtusa Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Location: Hybrid (Pan-India as per operating locations)Department: StrategyReports to: Chief Risk Officer (CRO)Job Summary:We are seeking an experienced and highly motivated Global Risk Assessment Manager to lead and support our global risk assessment program. As part of the Enterprise Risk Management function, this role will be responsible for managing all...


  • Bengaluru, India JPMorgan Chase & Co. Full time

    Are you passionate about risk management and quality assurance in a dynamic, global environment? Join our Supplier Assurance Services (SAS) Process Assurance team as an Associate, where you’ll play a pivotal role in safeguarding our firm’s operations by ensuring the highest standards in third-party assessments Job Summary As an Associate, within the...