← Browse all jobs

M

Information Technology Internal Auditor

Mizuho · India

FULL TIME

Job Description

Mizuho Global Services Pvt Ltd (MGS) is a subsidiary company of Mizuho Bank, Ltd, which is one of the largest banks or so called Mega Banks of Japan. MGS was established in the year 2020 as part of Mizuhos long-term strategy of creating a captive global processing center for remotely handling banking and IT related operations of Mizuho Banks domestic and overseas offices and Mizuhos group companies across the globe.

At Mizuho we are committed to a culture that is driven by ethical values and supports diversity in all its forms for its talent pool. Direction of MGSs development is paved by its three key pillars, which are Mutual Respect, Discipline and Transparency, which are set as the baseline of every process and operation carried out at MGS.

Whats in it for you?

  • Immense exposure and learning
  • Excellent career growth
  • Company of highly passionate leaders and mentors
  • Ability to build things from scratch

Know more about MGS: -

Job Role: Senior Internal Auditor IT Audit

Role Summary

The Senior Internal Auditor IT Audit is a key role within the MGS Internal Audit function, responsible for providing independent assurance over the organization's technology risk landscape. This individual will lead and execute complex IT audits covering IT governance, infrastructure, cybersecurity, data security, applications, third party vendor management and IT service delivery within MGS. The role requires deep technical expertise and the ability to translate complex technical risks into business impact.

The Senior IT Auditor will manage audit projects, engage with senior IT and business leadership, and be a key contributor to the Audit department's strategic objectives. The role also contributes to continuous audit monitoring, risk assessment, and audit planning and strengthens the organizations technology risk and control framework.

  • IT Audit & Assurance : Minimum 10 years of dedicated experience in IT internal audit, risk management, or information security assurance, with at least 2 years of leading IT Audit engagements.
  • BFSI, GCCs, Shared Services : Demonstrable experience auditing the technology environment of a Global Capability Center (GCC) or shared services environment of large banking or financial services entities, including infrastructure, service delivery, applications and data security.
  • Technical Audit Domains : Extensive hands-on experience leading audits of IT General Controls (ITGCs), cybersecurity, cloud environments (IaaS, PaaS, SaaS), network security, application controls, third party risks (TPRM) and IT service management (ITSM).
  • Third-party Risk Assurance : Experience auditing the full lifecycle of third-party risk management (TPRM), including vendor due diligence, contract reviews (SLAs, right-to-audit), ongoing monitoring, and offboarding, with a focus on Cloud Service Providers (CSPs).
  • Technology Resilience & Business Continuity: Proven experience auditing technical disaster recovery (DR) and business continuity (BCP) programs. Expertise in validating RTO/RPO capabilities, DR testing, and BIA alignment.
  • Project & Team Leadership : Proven ability to lead complex IT audit engagements from planning to reporting, including managing and reviewing the work of other auditors
  • Integrated Audits with Data-focus : Experience working with Business auditors for end-to-end process and control assurance and partnering with data teams to define audit use cases, perform analytics-based testing.

Mandatory Qualifications : Bachelors or Masters degree in Information Technology, Computer Science, or a related field

Preferred : CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), CRISC (Certified in Risk and Information Systems Control)

Certifications : CISA (Certified Information Systems Auditor) OR Cloud-specific certifications (e.g., AWS Certified Security - Specialty, Microsoft Azure Security Engineer), CGEIT (Certified in the Governance of Enterprise IT)

Knowledge of Governance Standards --

  • COBIT Framework : Deep understanding and practical application of the COBIT (Control Objectives for Information and Related Technologies) framework for IT governance and management.
  • Security & Risk Frameworks: Expertise in applying industry-standard frameworks such as the NIST Cybersecurity Framework (CSF), ISO 27001/27002, Digital and Operational Resiliency Act (DORA) and ITIL for service management
  • Data Privacy & Regulations : Strong knowledge of data protection regulations and standards relevant to the GCC and the financial services industry (e.g., GDPR, local data privacy laws)
  • Banking & GCC governance: Strong understanding of governance frameworks in global banking organizations and governance, risk, and compliance considerations unique to GCCs
  • Risk Management & Integrated assurance : Knowledge of Enterprise Risk Management (ERM), risk assessment frameworks, continuous monitoring concepts and coordination across business, IT, and compliance assurance functions.

Technical Decision Areas

  • Audit Scoping & Approach : Defines the technical scope and testing approach for IT audits, including determining the appropriate use of vulnerability scanning, configuration reviews, and log analysis, with due guidance from the Head of Internal Audit.

  • Audit Execution : Autonomously performs walkthroughs, risk assessments, and control testing across domains - IT General Controls (ITGCs), cybersecurity, cloud environments (IaaS, PaaS, SaaS), network security, application controls, IT service management (ITSM), Third Party Risk management and IT DR. Collaborate with Business audit teams to perform integrated audits covering business and technology controls. Work with data analysts to leverage data analytics and digital audit techniques to enhance audit effectiveness and coverage.

  • Vulnerability & Risk Assessment : Exercises expert judgment to assess the severity of identified vulnerabilities and control deficiencies, analyse root causes, and determine the business impact.

  • Evidence & Workpaper documentation : Responsible for the documentation of technical audit evidence (e.g., system configurations, firewall rules, user access listings) to ensure it is sufficient and reliable.

  • Stakeholder Management : Manage and debrief senior IT stakeholders on audit scope, progress, findings, and final conclusions.

  • Reporting & Drafting : Draft high-quality audit reports, including findings, risk statements, and actionable recommendations.

  • Remediation Assessment : Critically evaluates and validates the technical effectiveness of management's remediation plans to ensure risks are adequately mitigated.

  • Risk Assessment & Continuous audit monitoring : Contribute to enterprise-wide audit risk assessment and annual audit planning processes. Support development and execution of continuous auditing/monitoring initiatives with respect to IT risks and auditable areas.

Skills & Competencies

  • Technical Acumen : Expert technical knowledge across multiple domains, including operating systems, databases, networks, cloud architecture, and security principles specific to BFSI GCCs.

  • Stakeholder Communication : Ability to effectively communicate complex technical issues and their business implications to both technical (e.g., CIO, CISO) and non-technical (e.g., business heads) stakeholders, challenge constructively and influence senior management.

  • Analytical Mindset : Strong ability to analyse complex IT ecosystems, identify potential control failures or security gaps, and think critically about how systems interact.

  • Collaboration & Influence : Proven ability to lead IT audits, manage projects effectively, and influence senior IT leadership to drive improvements in the control environment.

Other responsibilities & expectations

  • IT Risk Assessment & Planning : Play a critical role in the annual IT risk assessment process and provide key input into the technology-focused components of the annual audit plan.
  • Integrated Audits : Act as the IT audit lead on integrated audits, working seamlessly with business auditors to provide a holistic view of end-to-end process risk
  • Data Analytics & Innovation : Partner with data analysts to identify sources of technical data (e.g., system logs, change management records) and develop analytics to test controls and identify anomalies. Promote adoption of innovation, automation, and digital audit techniques
  • Risk Culture : Contribute to strengthening risk awareness and IT control culture within MGS
  • Global Coordination : Collaborate with global audit teams across regions (Japan, EMEA, Americas) as required
  • Travel : Willingness to travel occasionally for audits or stakeholder engagement.

Thanks!

Details

CompanyMizuho
LocationIndia
TypeFULL TIME
Nichegeneral

Similar Jobs

V

Senior Manager

Vahura

H

Site Inspector/Project Executive-Interiors(Thane/Navi Mumbai)

HomeLane

B

Special Education Team Lead

Brain Bristle

P

Business Development Executive

Painting drive

S

Project Director

Straive