Information security auditor

2 days ago


Bangalore, India Muthoot Fincorp Ltd. Full time

ROLE SUMMARY (PURPOSE) The Information Security Auditor at Muthoot Fincorp Limited (MFL), assesses and evaluates our information systems, data protection protocols, and cybersecurity measures to ensure compliance with regulatory requirements, internal policies, and industry best practices. This role involves identifying vulnerabilities, providing recommendations for security improvements, and helping to safeguard company data and systems from potential security breaches. KEY RESPONSIBILITIES Perform regular internal and external audits to assess compliance with security policies, standards, and controls. Review IT infrastructure, applications, networks, and data protection practices. Identify vulnerabilities and assess risks associated with information systems and recommend corrective actions to reduce risk and improve security. Prepare detailed audit reports, outlining findings, non-compliance issues, and risk assessments, and present findings to senior management and provide actionable recommendations. Develop and execute comprehensive internal audit plans to assess the effectiveness of risk management, control, and governance processes within the organization Evaluate the adequacy of cloud security controls which includes but not limited to access management, data encryption, and incident response procedures. Conduct audits based on cloud security controls, specifically AWS and OCI. Provide recommendations, suggestions to improve security posture of the cloud hosted infrastructure. Ensure ongoing compliance with relevant industry standards (e.g., ISO 27001, DPDPA). Additionally collaborate with teams to maintain compliance with regulatory requirements (e.g., GDPR, HIPAA). Offer insights and guidance on security policies, access controls, data protection, and risk management strategies. KEY INTERACTIONS Internal Stakeholders External Stakeholders IT and Cybersecurity Teams: Work closely on implementing recommendations and ensuring secure IT operations. Compliance Officers: Collaborate to maintain adherence to internal policies and external regulations. Senior Management: Provide audit findings and suggest improvements to executive leadership. HR and Legal Departments: Engage for policy alignment and regulatory compliance. Third-Party Vendors: Conduct security assessments of vendors and ensure they comply with data protection requirements. Regulatory Authorities: Maintain compliance with relevant industry and government standards. External Auditors: Coordinate joint assessments or external audits as necessary. KEY ROLE DIMENSIONS This is a Pan India Individual Contribution role, which requires continuous communication, mostly with senior leaders, compliance and technology team KEY SKILLS & BEHAVIOURAL ATTRIBUTES Proficiency in cybersecurity frameworks, network security, vulnerability management, and information systems auditing. Strong understanding of risk assessment methodologies and the ability to identify and prioritize vulnerabilities. Broad knowledge of cloud computing platforms like AWS, Azure and GCP, and various cloud security controls. Strong understanding of cloud security frameworks and standards, such as CIS Controls, NIST Cybersecurity Framework, and ISO 27001. Precision in auditing, documentation, and compliance monitoring. Behavioral Attributes- Driven and in alignment with our Purpose “Transforming the life of the common man by improving their financial well-being” and anchored by our core value of integrity, collaboration, and excellence. EDUCATION / EXPERIENCE Minimum Qualification: Bachelor’s degree in information technology, Engineering, Computer Science, Cybersecurity, or a related field. However, a Master’s degree in Cybersecurity, Information Assurance, or a similar discipline is desirable for this role. Nature of Experience: Minimum of 6 years of experience in internal auditing, with a strong focus on IT audit, security and third-party audits. Additional Certifications - Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP) is mandatory Certified Information Security Manager (CISM), ISO 27001 Lead Auditor, Certified Ethical Hacker (CEH) are also preferred.



  • bangalore, India Muthoot Fincorp Ltd. Full time

    ROLE SUMMARY (PURPOSE) The Information Security Auditor at Muthoot Fincorp Limited (MFL), assesses and evaluates our information systems, data protection protocols, and cybersecurity measures to ensure compliance with regulatory requirements, internal policies, and industry best practices. This role involves identifying vulnerabilities, providing...


  • bangalore, India Muthoot Fincorp Ltd. Full time

    ROLE SUMMARY (PURPOSE)The Information Security Auditor at Muthoot Fincorp Limited (MFL), assesses and evaluates our information systems, data protection protocols, and cybersecurity measures to ensure compliance with regulatory requirements, internal policies, and industry best practices. This role involves identifying vulnerabilities, providing...


  • bangalore, India Muthoot Fincorp Ltd. Full time

    ROLE SUMMARY (PURPOSE) The Information Security Auditor at Muthoot Fincorp Limited (MFL), assesses and evaluates our information systems, data protection protocols, and cybersecurity measures to ensure compliance with regulatory requirements, internal policies, and industry best practices. This role involves identifying vulnerabilities, providing...


  • bangalore, India Muthoot Fincorp Ltd. Full time

    ROLE SUMMARY (PURPOSE)The Information Security Auditor at Muthoot Fincorp Limited (MFL), assesses and evaluates our information systems, data protection protocols, and cybersecurity measures to ensure compliance with regulatory requirements, internal policies, and industry best practices. This role involves identifying vulnerabilities, providing...


  • bangalore, India Happiest Minds Technologies Full time

    Happiest Minds is hiring for Information Security professionals:Experience: 2 - 8 yrsLocation: BangaloreReview and make update updates to security policy, process, procedure & guideline documentsPerform formal Information Security and Privacy risk analysis and assessments programDrive compliance with customer contractual obligations through identification...


  • bangalore, India Happiest Minds Technologies Full time

    Happiest Minds is hiring for Information Security professionals: Experience: 2 - 8 yrs Location: Bangalore Review and make update updates to security policy, process, procedure & guideline documents Perform formal Information Security and Privacy risk analysis and assessments program Drive compliance with customer contractual obligations through...


  • Bangalore, India Happiest Minds Technologies Full time

    Happiest Minds is hiring for Information Security professionals: Experience: 2 - 8 yrs Location: Bangalore Review and make update updates to security policy, process, procedure & guideline documents Perform formal Information Security and Privacy risk analysis and assessments program Drive compliance with customer contractual obligations through...


  • bangalore, India ACL Digital Full time

    Location : Bangalore (Work from Office)Experience : 6 - 12 yrsLooking for : Immediate Joiners or Serving notice period or Max 30 days notice period.Job Description:The Information Security Specialist or Manager should have hands-on experience implementing the ISO 27001 framework to validate and monitor the effectiveness of IT controls. Key responsibilities...


  • Bangalore, India ACL Digital Full time

    Location : Bangalore (Work from Office) Experience : 6 - 12 yrs Looking for : Immediate Joiners or Serving notice period or Max 30 days notice period. Job Description: The Information Security Specialist or Manager should have hands-on experience implementing the ISO 27001 framework to validate and monitor the effectiveness of IT controls. Key...


  • Bangalore, India Murf AI Full time

    At , we're simplifying multimedia creation by harnessing the power of artificial intelligence. Our platform empowers users to craft high-quality voiceovers effortlessly, without the need for recording equipment. Some interesting facts about Murf AI: Customers in 100+ countries 8 Mn+ registered users 6 X growth in revenue in the last 12 months ...


  • Bangalore, India HuntingCube Recruitment Solutions Full time

    Job Description ● Develop and finalize policies, procedures, and guidelines related to IT and Infosec domains in alignment with industry best practices (ISO 27001 , GDPR and SOC 2)● Align internal IT and Infosec processes as per ISO 27001 and SOC 2 standards and security guidelines ● Assist in defining and reviewing the key metrics for management...


  • Bangalore, India Talent one Consulting Full time

    Job Title: Information Security EngineerAbout the Role:We are seeking an experienced Information Security Engineer to join our team at Talent One Consulting. As a key member of our IT and Infosec team, you will be responsible for developing and implementing policies, procedures, and guidelines related to IT and Infosec domains in alignment with industry best...


  • bangalore, India HuntingCube Recruitment Solutions Full time

    Job Description● Develop and finalize policies, procedures, and guidelines related to IT and Infosecdomains in alignment with industry best practices (ISO 27001 , GDPR and SOC 2)● Align internal IT and Infosec processes as per ISO 27001 and SOC 2 standards andsecurity guidelines● Assist in defining and reviewing the key metrics for management...


  • bangalore, India ACL Digital Full time

    Location : Bangalore (Work from Office) Experience : 6 - 12 yrs Looking for : Immediate Joiners or Serving notice period or Max 30 days notice period. Job Description: The Information Security Specialist or Manager should have hands-on experience implementing the ISO 27001 framework to validate and monitor the effectiveness of IT controls. Key...


  • bangalore, India ACL Digital Full time

    Location : Bangalore (Work from Office)Experience : 6 - 12 yrsLooking for : Immediate Joiners or Serving notice period or Max 30 days notice period.Job Description:The Information Security Specialist or Manager should have hands-on experience implementing the ISO 27001 framework to validate and monitor the effectiveness of IT controls. Key responsibilities...


  • Bangalore, India ACL Digital Full time

    Location : Bangalore (Work from Office) Experience : 6 - 12 yrs Looking for : Immediate Joiners or Serving notice period or Max 30 days notice period. Job Description: The Information Security Specialist or Manager should have hands-on experience implementing the ISO 27001 framework to validate and monitor the effectiveness of IT controls....


  • Bangalore, India IT Service Company Full time

    Job Title: Information Security ConsultantWe are seeking an experienced Information Security Consultant to join our team at Procain Consulting and Services Private Limited. As an Information Security Consultant, you will be responsible for providing expert advice on information security and risk management to our clients.Key Responsibilities:Develop and...


  • Bangalore, India INTERROPAC PRIVATE LIMITED Full time

    Job DescriptionPosition Summary:The Information Security Officer is responsible for establishing and maintaining the enterprise vision, strategy, and program to ensure information assets and technologies are adequately protected.Key Responsibilities:Strategic Leadership:Develop and implement a strategic, long-term information security strategy and roadmap to...


  • bangalore, India HuntingCube Recruitment Solutions Full time

    Job Description● Develop and finalize policies, procedures, and guidelines related to IT and Infosecdomains in alignment with industry best practices (ISO 27001 , GDPR and SOC 2)● Align internal IT and Infosec processes as per ISO 27001 and SOC 2 standards andsecurity guidelines● Assist in defining and reviewing the key metrics for management...


  • bangalore, India HuntingCube Recruitment Solutions Full time

    Job Description ● Develop and finalize policies, procedures, and guidelines related to IT and Infosec domains in alignment with industry best practices (ISO 27001 , GDPR and SOC 2) ● Align internal IT and Infosec processes as per ISO 27001 and SOC 2 standards and security guidelines ● Assist in defining and reviewing the key metrics for management...