Source description
About the role
Reporting Structure:
Reports to Sr. Manager Systems Audit
Education:
Graduate in Computer Science/IT or B.E / B. Tech or BCA / MCA
Certifications:
Mandatory:
PMP/ CAPM/ PRINCE2/ CSM
Good to have:
CCSP/ AAIA / AAISM / CISA / CISM / CISSP / CEH / CRISC
Additionally, domain-specific certifications below may be preferred.
Application & API Security:
MCSD
Certification in Mobile application security testing
Java certifications
Certifications in API security
Database Security:
MCDBA
Oracle database
Certification in big data / analytics
Network Security:
CCNA.
Certified Firewall administrator
Cloud Security:
CCSK/CCSP
Experience (years):
6 - 8 years of total experience (upto 8 yrs.) in the field of Project Management review/audits, information security operations, Information System Audits encompassing experience into any of the Banking Technologies Domains – Cloud Security, Database management and administration, Network security and SOC in addition to IT General controls (ITGC).
Exposure to the Banking / Finance / Payment industry domains would be preferrable.
Hands 1-on experience in the following areas:
Writing policies, procedures, and processes
Conducting risk assessment covering Cyber Security domains as noted below:
Hybrid Cloud Mastry:
Lead deep-dive audits of AWS (IAM, S3, VPC, GuardDuty) and Microsoft Hybrid environments.
Code & Architecture Review:
Audit Java-based application security, focusing on API security, containerization (Docker/K8s), and DevSecOps pipelines.
Project Governance:
Conduct performance audits of high-value IT projects, ensuring they meet PMP/Agile milestones without compromising on security.
Data-Driven Assurance:
Use Python or SQL to build automated "Continuous Auditing" dashboards that track risk in real-time.
Database Security:
Database administration and management - Oracle, MS SQL etc., Database Activity Monitoring tools, data security and localization.
Regulatory Alignment:
Ensure all IT operations comply with the latest RBI Cyber Security Framework and Global Internal Audit Standards (2024)
IT General Controls:
Familiarity with Technical Security controls of Identity & Access Management, Network, Server, Application, Change management, Backup and Restoration etc. and process controls reviews.
Understand BCP and DR processes and architecture.
Experience in conducting reviews based on ISO standards and regulatory guidelines in banking sector for a medium to large sized organization would be preferred.
Experience in conducting Information System Audits/Review
Must have experience in preparing quality deliverables such as audit reports, presentations, etc.
Excellent written, oral communication and presentation skills
Excellent organizational and interpersonal skills
Ability to work independently or as part of a team
Industry:
Information technology / Banking and Financial services / Auditing / Cyber Security consulting
Responsibilities
-
To evaluate the systemic impact of risks across Project Management (PMO) and ITIL service delivery.
-
Heavy-hitter who can dissect complex AWS/Azure/Hybrid-Cloud architectures and scrutinize the Java-based microservices.
-
Candidates may have to travel within Mumbai and across the c ountry (if required) to perform audits, as per RBI requirements.
-
Conducting audit of Information security policies, procedures, and processes to identify process/design gaps.
-
Conduct audits of information security systems and infrastructure to verify systems are secure and support the related applications/business processes.
-
Conducts audits in different banking technology domains such as Active Directory, WAF, Network access security, End-point security, Application VA/PT/AppSec, SDLC, Database management and security, PCI-DSS, and IT General Controls etc.
-
Additional weightage will be given to candidates with experience in domains such as Cloud Security, API security, CI-CD pipeline, project management Audits, etc.
-
Developing project plans, work programs, evaluating system controls, identify risks and audit gaps, documenting results in proper audit report format, making recommendations, and communicating information to stakeholders.
-
Support in maintaining audit checklist and documents, trend analysis, preparing presentations etc.
-
Should be a self-learner and must keep updated with the latest security guidelines issued by regulators, international standards for information security, threats and vulnerabilities researched/discovered.
-
Research public domain to keep up to date knowledge on latest banking applications / technologies and emerging technologies – Cloud, Virtualisation, AI-ML, IOT, CI-CD, API security, etc. and ensure continuous learning in identified security competencies and new/emerging technologies.
-
Employment Type
-
All positions are on fixed term contract on a full-time basis exclusively for ReBIT, initially for a period of five years, extendable by mutual consent
More at Reserve Bank Information Technology Pvt Ltd