Assistant Manager – Application Security, IT Audit & GRC (02 positions)
Must Have Skills
Preferred Skills
Assistant Manager – Application Security, IT Audit & GRC
Location: Kochi, Kerala
Employment Type: Full-Time
Work Mode: On-site
Experience: 5–6 Years
Compensation: Salary is not a constraint for the right candidate
About the Hiring Organization
We are hiring on behalf of one of India's most recognized retail enterprises with a strong global presence and decades of excellence. As part of its ongoing digital transformation journey, the organization is strengthening its Information Security, IT Audit, and Governance, Risk & Compliance (GRC) functions to support enterprise applications, ERP platforms, cloud infrastructure, and business-critical systems.
This is an excellent opportunity for Information Security professionals looking to work on enterprise-scale application security, IT audits, vulnerability management, and regulatory compliance in a collaborative and technology-driven environment.
About the Role
We are looking for an Assistant Manager – Application Security, IT Audit & GRC with 5–6 years of relevant experience in Information Security, Application Security, IT Audits, or Governance, Risk & Compliance.
The ideal candidate should have practical experience supporting internal and external IT audits, application security assessments, Vulnerability Assessment & Penetration Testing (VAPT), ERP/application security reviews, and user access governance. You will work closely with internal technology teams, auditors, infrastructure teams, and business stakeholders to strengthen the organization's security posture and compliance.
Key Responsibilities
Application Security
- Support application security reviews for web applications, APIs, and enterprise applications.
- Assist in Vulnerability Assessment & Penetration Testing (VAPT) activities.
- Track identified vulnerabilities and coordinate remediation with application teams.
- Support Secure SDLC initiatives and basic application security testing.
IT Audit & ERP Security
- Support Internal, External, and Regulatory IT Security Audits.
- Participate in ERP and enterprise application security reviews.
- Perform User Access Reviews (UAR), role validation, and privileged access verification.
- Assist in IT General Controls (ITGC) reviews and audit evidence collection.
- Track audit observations until closure.
Governance, Risk & Compliance
- Support implementation of Information Security policies and standards.
- Assist in technology risk assessments and compliance reviews.
- Support compliance activities aligned with ISO 27001, NIST, RBI, or similar frameworks.
- Maintain audit documentation, risk registers, and compliance reports.
Security Operations Support
- Assist in security incident investigations and remediation tracking.
- Review authentication logs, access controls, and endpoint compliance.
- Coordinate with Infrastructure, ERP, Application, and Audit teams on security initiatives.
Documentation & Reporting
- Prepare audit reports, risk assessments, compliance documentation, and executive summaries.
- Maintain security evidence, SOPs, audit trackers, and remediation status reports.
Must-Have Skills
- Information Security Audits
- Internal & External IT Audit Support
- Application Security & Secure SDLC Fundamentals
- Vulnerability Assessment & Penetration Testing (VAPT)
- ERP/Application Security Reviews
- User Access Reviews (UAR) & Access Governance
- IT General Controls (ITGC)
- Governance, Risk & Compliance (GRC)
- ISO 27001, NIST, RBI Guidelines, or similar frameworks
- Security Assessment Tools (Burp Suite, Nessus, OWASP ZAP, Nmap, or equivalent)
Good-to-Have Skills
- Active Directory & Identity Access Management
- SIEM Platforms
- Azure, AWS, or GCP Security Fundamentals
- Endpoint Security & EDR Solutions
- API Security Testing
- ERP Platforms (Dynamics 365, SAP, Oracle ERP, etc.)
- CEH, CISA, ISO 27001 LA/LI, Security+, or similar certifications
Preferred Candidate Profile
- 5–6+ years of experience in Information Security, IT Audit, Application Security, or GRC.
- Hands-on experience supporting IT security audits and compliance initiatives.
- Experience with VAPT coordination and application security assessments.
- Familiarity with ERP security reviews and user access governance.
- Good understanding of IT risk management and audit documentation.
- Strong analytical, communication, and stakeholder coordination skills.
- Candidates willing to build a long-term career in Kochi are preferred.
- Malayalam speaking and understanding will be an added advantage.
Please fill the preapplication answers
Apply to this job
Required — upload a file or paste the text
