Assistant Manager – Application Security, IT Audit & GRC (02 positions)
Must Have Skills
Preferred Skills
Assistant Manager – IT Audit, Technology Risk & Information Security
Location: Kochi, Kerala Work Mode: On-site Employment Type: Full-Time Experience: 4–7 Years Maximum CTC: ₹14 LPA
About the Opportunity
We are calling applicants on behalf of a global retail group for an experienced IT Audit, Technology Risk & Information Security professional to join a growing organization in Kochi. This role offers comprehensive exposure to IT General Controls (ITGC), IT Application Controls (ITAC), ERP/application audits, user access reviews, information security assessments, risk management, vulnerability assessment, and regulatory compliance. The ideal candidate will possess a strong foundation in audit principles combined with practical knowledge of information security, applications, databases, and technology risk.
About the Role
The Assistant Manager will be responsible for planning and executing technology and information security audits, evaluating IT controls, reviewing enterprise applications and ERP environments, identifying risks, and collaborating with stakeholders on remediation efforts. Experience with SAP, Oracle, ERP applications, ITGC, ITAC, user access reviews, SOX, ISO 27001, vulnerability assessment, or GRC is highly desirable.
Key Responsibilities
1. IT Audit & Technology Risk
- Plan and execute IT audit assignments according to defined audit plans.
- Perform technology risk assessments and identify control gaps.
- Evaluate IT processes, systems, applications, and infrastructure.
- Prepare audit scopes, testing procedures, working papers, and audit reports.
- Communicate findings and track remediation activities to closure.
- Support internal and external audit engagements.
2. IT General Controls – ITGC
- Review and test controls related to:
- User access management
- Joiner/Mover/Leaver processes
- Privileged access
- Change management
- IT operations
- Backup and recovery
- Incident management
- Access reviews
- Identify control deficiencies and recommend remediation strategies.
3. IT Application Controls – ITAC
- Review application-level controls across critical business processes.
- Assess application workflows and automated controls.
- Review controls related to transaction processing and authorization.
- Evaluate Segregation of Duties (SoD) risks.
- Perform control testing and document operating effectiveness.
- Support application control reviews for ERP and business applications.
4. ERP & Application Audit
- Conduct IT control reviews of enterprise applications and ERP platforms.
- Review environments such as SAP, Oracle, or other ERP/business applications.
- Understand application workflows and identify technology-related financial and operational risks.
- Review application configurations and relevant control points.
- Perform SQL/query-based validation as required.
5. User Access & Security Reviews
- Conduct periodic user access reviews.
- Review privileged and administrative access.
- Identify inappropriate or excessive access.
- Support access remediation and SoD conflict resolution.
- Evaluate access governance across applications, databases, and infrastructure.
6. Information Security & GRC
- Support information security audits and compliance assessments.
- Perform asset-based and scenario-based risk assessments.
- Maintain IT asset risk registers and risk treatment plans.
- Conduct third-party risk assessments.
- Support security policy and procedure reviews.
- Assist with ISO 27001 and other information security framework assessments.
7. Vulnerability & Security Assessment
- Support vulnerability assessment and security testing activities.
- Review vulnerabilities and assess business/technical impact.
- Collaborate with technology teams on remediation tracking.
- Exposure to tools such as Nessus, Burp Suite, Nmap, OWASP ZAP, or equivalents is an advantage.
- Understanding of application/API security is beneficial.
8. Compliance & Regulatory Audits
- Support audits against applicable regulatory and compliance requirements.
- Work with internal and external auditors.
- Prepare audit evidence and walkthrough documentation.
- Track observations, corrective actions, and closure status.
- Support compliance reporting to management.
9. Audit Data & Technical Analysis
- Perform SQL/query analysis for audit validation as required.
- Analyze system-generated reports and application output.
- Validate the completeness and accuracy of audit evidence.
- Perform basic code/configuration analysis where relevant.
10. Reporting & Stakeholder Management
- Prepare clear audit reports and management summaries.
- Present observations and recommendations to stakeholders.
- Coordinate with IT, cybersecurity, application, infrastructure, finance, and business teams.
- Track remediation and ensure timely closure of findings.
Must-Have Skills
- IT Audit / Technology Risk experience with hands-on exposure to ITGC and/or IT Application Controls.
- Strong experience in User Access Management, Change Management, and application/ERP controls.
- Experience performing IT risk assessments, audit testing, documentation, and reporting.
- Good understanding of enterprise applications and databases.
- Strong analytical, documentation, and stakeholder-management skills.
Good-to-Have Skills
- SAP / SAP S4 HANA
- Oracle EBS / Oracle Fusion
- SOX 404
- ISO 27001
- Information Security / GRC
- Vulnerability Assessment / VAPT
- Nessus / Burp Suite / Nmap / OWASP ZAP
- SQL query analysis
- SOC 1 / SOC 2
- ITIL / COBIT
- Third-party risk assessment
- Audit trail and backup testing
- API security
Preferred Candidate Profile
- Bachelor's degree in IT, Computer Science, Engineering, Commerce, Finance, or a related discipline.
- 4–7 years of relevant experience in IT Audit, Technology Risk, IT GRC, Information Security Audit, or related areas.
- Candidates from Big 4, consulting, NBFC, BFSI, IT services, or enterprise environments will be considered.
- Experience handling multiple audit engagements is preferred.
- A combination of IT Audit and Information Security/GRC experience will be advantageous.
Certifications – Added Advantage
- CISA
- ISO 27001 Lead Auditor / Internal Auditor
- CEH
- CISSP
- CRISC
- ACCA
- Other relevant IT audit, cybersecurity, or GRC certifications
Why This Role?
- Gain cross-functional experience across IT Audit, Information Security, and Technology Risk.
- Exposure to diverse enterprise applications and ERP environments.
- Opportunity to work on ITGC, ITAC, user access, risk, compliance, and security assessments.
- Engage in cross-functional interactions with technology and business stakeholders.
- Clear career progression pathways towards IT Audit Manager, Technology Risk Manager, GRC Manager, or Information Security Manager roles.
Apply to this job
Required — upload a file or paste the text
