…

Assistant Manager Technology Audit Bengaluru Internal audit

Deloitte India (South Asia) · Consulting & Professional Services

  • Bengaluru, India
  • On-site
  • Posted today
  • Apply by 11 Oct
  • Finance & Accounting

About the job

Assistant Manager | Technology Audit | Bengaluru | Internal audit

Job requisition ID : 114703
Location : Bengaluru
Entity : Deloitte Touche Tohmatsu India LLP

Your Role

We are seeking a highly motivated Technology Auditor / Technology Risk Consultant to support and lead Technology Audit, IT Risk Assurance, SOX, Internal Audit, and Controls Assurance engagements across diverse industries, with a strong preference for Banking & Financial Services experience.

The role involves evaluating technology risks and controls across applications, infrastructure, ERP platforms, cloud environments, and custom-developed systems. The ideal candidate will possess strong experience in IT General Controls (ITGC), IT Application Controls (ITAC), user access management, change management, SDLC governance, and technology risk assessments, while partnering with business and technology stakeholders to strengthen governance, compliance, and operational effectiveness.

Your Responsibilities

Lead and execute Technology Audit, IT Risk, SOX, Controls Assurance, and Internal Audit engagements.
Perform risk assessments and develop risk-based audit plans, testing strategies, and work programs.
Conduct walkthroughs, control testing, issue validation, and root cause analysis.
Evaluate the design and operating effectiveness of technology controls across applications, infrastructure, databases, and cloud environments.
Identify control deficiencies, technology risks, and process improvement opportunities and recommend practical remediation actions.
Prepare audit reports, executive summaries, and management presentations.
Track audit observations and remediation plans through closure.
Assess controls related to:
User Access Management
Privileged Access Management
Segregation of Duties (SoD)
Change Management
Computer Operations
Backup and Recovery
Job Monitoring and Batch Processing
Review joiner, mover, leaver (JML) controls and user access governance processes.
Evaluate emergency/firefighter access and privileged user monitoring controls.
Perform testing of:
Automated Controls
Interface Controls
Configuration Controls
Workflow Controls
System-Enforced Controls
Information Produced by the Entity (IPE)
Validate system-generated reports and automated business process controls.
Assess application security and data integrity controls across ERP and business applications.
Evaluate Software Development Lifecycle (SDLC) controls, including:
Change Governance
Requirements Management
Development Standards
Code Reviews
Testing Approvals
Release Management
Deployment Controls
Review evidence supporting peer reviews, testing, approvals, and production migrations.
Assess governance practices across DevOps and Agile environments where applicable.
Assess technology controls across cloud environments including:
Microsoft Azure
AWS
Google Cloud Platform (GCP)
Review cloud identity and access management controls, security configurations, and governance processes.
Evaluate risks associated with modern technology platforms and digital transformation initiatives.
Manage day-to-day interactions with technology stakeholders, application owners, infrastructure teams, and business process owners.
Present audit findings, risk observations, and recommendations to management.
Facilitate discussions related to remediation activities and control enhancements.
Build and maintain strong relationships with client stakeholders and engagement leadership.
Manage multiple engagements and ensure timely delivery of high-quality work.
Review workpapers and deliverables for quality and compliance with firm methodologies.
Mentor and coach junior team members.
Support engagement planning, resource management, and knowledge-sharing initiatives.
Support proposal development, client presentations, and business pursuit activities.
Contribute to development of technology audit methodologies, accelerators, and reusable testing assets.
Participate in internal training, thought leadership, and practice development initiatives.
Identify opportunities to expand existing client relationships and support business growth objectives.

Key Skills Required

Education: Bachelor's or Master's degree in Information Technology, Computer Science, Information Systems, Accounting, Finance, or related disciplines.
Professional certifications such as CISA, CIA, CISSP, CRISC, CPA, CA, or equivalent preferred.
3-5 years of experience in Technology Audit, IT Risk, SOX, Internal Audit, Controls Assurance, or related consulting services.
Strong understanding of ITGCs, ITACs, technology risk management, and governance frameworks.
Experience performing walkthroughs, controls testing, reporting, and stakeholder management.
Excellent analytical, communication, presentation, and project management skills.

Preferred Skills

Strong hands-on experience in ITGC and ITAC testing.
Experience auditing ERP environments such as SAP, Oracle, Workday, or similar platforms.
Exposure to cloud platforms including Azure, AWS, and GCP.
Experience reviewing Active Directory and Identity & Access Management controls.
Understanding of SOX compliance and Controls Assurance programs.
Exposure to SDLC governance and code review controls.
Working knowledge of SQL, Python, Java, or similar technologies sufficient to understand system functionality and control implementation.
Experience with data analytics and visualization tools such as Alteryx, Power BI, SQL, Tableau, or similar platforms.
Banking, Financial Services, Insurance, Capital Markets, or FinTech industry experience is highly desirable.