Source description
About the role
Role Overview: The Information Security Auditor at Muthoot Fincorp Limited (MFL) assesses and evaluates information systems, data protection protocols, and cybersecurity measures to ensure compliance with regulatory requirements, internal policies, and industry best practices. Your role involves identifying vulnerabilities, providing recommendations for security improvements, and helping to safeguard company data and systems from potential security breaches. Key Responsibilities: - Perform regular internal and external audits to assess compliance with security policies, standards, and controls. - Review IT infrastructure, applications, networks, and data protection practices. - Identify vulnerabilities, assess risks associated with information systems, and recommend corrective actions to reduce risk and improve security. - Prepare detailed audit reports outlining findings, non-compliance issues, and risk assessments, and present findings to senior management with actionable recommendations. - Develop and execute comprehensive internal audit plans to assess the effectiveness of risk management, control, and governance processes within the organization. - Evaluate the adequacy of cloud security controls, including access management, data encryption, and incident response procedures. - Provide recommendations and suggestions to improve the security posture of the cloud-hosted infrastructure. - Ensure ongoing compliance with relevant industry standards such as ISO 27001, DPDPA, and collaborate with teams to maintain compliance with regulatory requirements like GDPR and HIPAA. - Offer insights and guidance on security policies, access controls, data protection, and risk management strategies. Qualification Required: - Bachelors degree in information technology, Engineering, Computer Science, Cybersecurity, or a related field. A Masters degree in Cybersecurity, Information Assurance, or a similar discipline is desirable. - Minimum of 6 years of experience in internal auditing, with a strong focus on IT audit, security, and third-party audits. - Additional Certifications: Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP) is mandatory. Certified Information Security Manager (CISM), ISO 27001 Lead Auditor, Certified Ethical Hacker (CEH) are preferred. Company Details: Muthoot Fincorp Limited is the organization where you will be contributing as an Information Security Auditor. The company focuses on transforming the life of the common man by improving their financial well-being, anchored by core values of integrity, collaboration, and excellence. Role Overview: The Information Security Auditor at Muthoot Fincorp Limited (MFL) assesses and evaluates information systems, data protection protocols, and cybersecurity measures to ensure compliance with regulatory requirements, internal policies, and industry best practices. Your role involves identifying vulnerabilities, providing recommendations for security improvements, and helping to safeguard company data and systems from potential security breaches. Key Responsibilities: - Perform regular internal and external audits to assess compliance with security policies, standards, and controls. - Review IT infrastructure, applications, networks, and data protection practices. - Identify vulnerabilities, assess risks associated with information systems, and recommend corrective actions to reduce risk and improve security. - Prepare detailed audit reports outlining findings, non-compliance issues, and risk assessments, and present findings to senior management with actionable recommendations. - Develop and execute comprehensive internal audit plans to assess the effectiveness of risk management, control, and governance processes within the organization. - Evaluate the adequacy of cloud security controls, including access management, data encryption, and incident response procedures. - Provide recommendations and suggestions to improve the security posture of the cloud-hosted infrastructure. - Ensure ongoing compliance with relevant industry standards such as ISO 27001, DPDPA, and collaborate with teams to maintain compliance with regulatory requirements like GDPR and HIPAA. - Offer insights and guidance on security policies, access controls, data protection, and risk management strategies. Qualification Required: - Bachelors degree in information technology, Engineering, Computer Science, Cybersecurity, or a related field. A Masters degree in Cybersecurity, Information Assurance, or a similar discipline is desirable. - Minimum of 6 years of experience in internal auditing, with a strong focus on IT audit, security, and third-party audits. - Additional Certifications: Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP) is mandatory. Certified Information Security Manager (CISM), ISO 27001 Lead Auditor, Certified Ethical Hacker (CEH) are preferred. Company D
More at Muthoot Fincorp Ltd.