Audit Remediation Jobs in Bengaluru
233 Jobs Found
It System And Security Engineer
Locus
IT System and Security Engineer Location: Bengaluru Work Type: Full-Time Company Overview Locus is a battle-tested, agentic Transportation Management System powering logistics across 30+ countries. In 2025, Locus joined the Ingka Group (IKEA Retail), combining high-growth tech agility with the scale of a global enterprise while continuing to operate independently. Role Overview We are seeking an IT System and Security Engineer to manage core IT operations, strengthen endpoint security, and ensure compliance. This hands-on role requires technical expertise to maintain a secure, compliant, and efficient environment across Google Workspace, Okta, and Jamf. Key Responsibilities Operations Management: Oversee user onboarding/offboarding, hardware provisioning, and complex troubleshooting. Security Administration: Monitor Okta, Jamf Pro, and Jamf Protect to ensure MFA enforcement and device encryption. Remediation: Proactively review and fix security vulnerabilities and compliance findings. Automation: Streamline routine tasks using Python, Bash, or Google Apps Script. Compliance & Audits: Maintain asset inventories and prepare evidence for SOC2 and ISO27001 readiness. Skills & Qualifications 2 5 years of experience in IT administration or security operations. Expertise: Google Workspace security and Identity Management (Okta). MDM Platforms: Proven experience with Jamf Pro, Intune, or equivalent tools. Scripting: Ability to write automation scripts in Python or Bash. Frameworks: Familiarity with SOC2 / ISO27001 compliance processes. What We Value Global Mindset: Curiosity about diverse markets. Driven: Energized by complex challenges. Thoughtful: Analytical and deliberate approach. Exact in Craft: Commitment to detail and excellence. Help redefine logistics through innovation. We offer competitive compensation, a supportive work environment, and the opportunity to scale IT security within the IKEA ecosystem.
Business Finance
Dozee
Business Finance Location: Bengaluru Department: Finance Employment Type: Full-Time About Dozee Dozee Health AI is a pioneer in AI-powered, contactless Remote Patient Monitoring (RPM) and Early Warning Systems (EWS). Headquartered in Bengaluru, Dozee is India s #1 RPM company, transforming healthcare delivery at scale. Trusted by leading healthcare providers across India, the USA, and Africa, Dozee s solutions continuously monitor patients, detect early signs of clinical deterioration, and enable timely interventions. Role Overview We are looking for a high-impact Business Finance professional to partner closely with business leaders and drive financial discipline, strategic decision-making, and sustainable growth. This role offers a unique opportunity to work at the intersection of finance, strategy, and healthcare innovation in a fast-growing AI health-tech company. Key Responsibilities Business Partnership & Strategic Decision Support Partner with Sales, Operations, and cross-functional teams to drive commercial success and financial discipline. Lead pricing strategy, customer-level profitability analysis, and financial modelling for new products and services. Evaluate business cases for expansion, partnerships, and large strategic deals. Participate in strategic discussions, providing financial insights and risk assessment. FP&A, Budgeting & Reporting Lead the annual operating plan and rolling forecasts in collaboration with functional leaders. Track performance against budgets, prepare variance analysis, and identify risks. Own monthly and quarterly management reporting, including key financial and operational KPIs. Revenue & Cost Optimisation Monitor and improve gross margins, unit economics, and CAC/LTV metrics. Drive initiatives to optimize costs, improve working capital, and support EBITDA targets. Identify opportunities for automation and process improvements in tracking. Requirements Experience & Qualifications 2 4 years of relevant experience in Business Finance, FP&A, or Commercial Finance. CA (Qualified/Semi-qualified), MBA, or CFA preferred. Skills Strong analytical, financial modelling, and stakeholder management skills. Proficiency in Excel, Google Sheets, and BI tools. Experience with pricing and margin analysis in a SaaS or recurring revenue environment is a plus. Personal Attributes Business-oriented, proactive, and detail-focused. Comfortable working in a fast-paced, evolving environment. Why Join Dozee Be part of a mission-driven company transforming healthcare with AI. Opportunity to influence strategic decisions in a high-growth Series A+ organization. Collaborative culture with a strong focus on innovation and impact. Qualification : CA (Qualified/Semi-qualified), MBA, or CFA preferred
Information Security Engineer
Altisource
Job Title: Information Security Engineer Location: Bengaluru Company: Altisource (NASDAQ: ASPS) About Altisource At Altisource, we develop cutting-edge technologies and services for the mortgage and real estate industry. We re a trusted partner to 7 of the top 10 U.S. mortgage servicers, operate one of the leading real estate auction platforms, and support a cooperative with over 15% market share in the $1.8 trillion U.S. originations market. If you're passionate about cybersecurity and want to make an impact in a high-growth, tech-driven environment this is the role for you. Position Summary We re looking for a highly motivated Information Security Engineer to support our growing security operations. You will play a vital role in identifying and mitigating security risks across applications, systems, and networks. This role involves vulnerability assessments, code reviews, and automation of security tasks ensuring Altisource remains secure and compliant in a fast-paced environment. Key Responsibilities Conduct vulnerability assessments on applications, networks, and systems. Perform manual verification to reduce false positives and validate security fixes. Communicate identified vulnerabilities and recommend remediation steps to internal teams. Perform secure code reviews and assist development teams in fixing identified issues. Identify and mitigate risks throughout the software development lifecycle. Leverage commercial and open-source tools for vulnerability detection (e.g., Qualys, Nessus, Burp Suite). Assist in internal penetration testing initiatives. Develop internal tools and automate security tasks, leveraging AI where applicable. Stay updated on the latest threats, tools, and best practices in cybersecurity. Create detailed assessment reports and present findings to technical and non-technical stakeholders. Train and mentor team members on vulnerability management processes and tools. Required Qualifications Bachelor s degree in Computer Science, Engineering, or a related field. 3 to 5 years of hands-on experience in information security or related roles. Relevant certifications such as CEH, GIAC, or similar. Solid experience in: Network vulnerability assessments Application scanning and secure code review Windows, Linux, and Unix operating systems Familiarity with OWASP tools, methodologies, and security best practices. Strong communication skills both written and verbal. Preferred Skills Experience with tools like: Qualys, Nessus, Nexpose, SAINT Burp Suite Pro, HP WebInspect Static analysis tools (e.g., IBM AppScan Source, Fortify) Proficiency in one or more programming languages: Java, C, C++, .NET (C#, VB). Experience delivering training or presenting technical content to teams. Background in technical writing or web development is a plus. Be part of a team securing technologies used by top players in the mortgage and real estate space. Work with modern tools and frameworks. Enjoy a collaborative environment that supports innovation, growth, and learning. Qualification : Bachelors degree in Computer Science, Engineering, or a related field
Assistant Manager - Risk
Groww
Position: Assistant Manager - Risk Location: Bengaluru About Groww At Groww, we are a passionate team dedicated to making financial services accessible to every Indian. Through our multi-product platform, we help millions of customers take control of their financial journeys. Customer obsession is at the heart of everything we do. From every product design to each algorithm, we focus on delivering the best experience, making financial services simple, transparent, and convenient. Our values include ownership, customer-centricity, and integrity. We believe in constantly challenging the status quo to drive meaningful change. Our Vision We aim to empower every individual with the knowledge, tools, and confidence to make informed financial decisions. Groww s long-term vision is to be India s most trusted financial partner, offering innovative financial solutions across various services. Our Core Values Radical Customer Centricity Ownership-Driven Culture Simplicity Long-Term Thinking Complete Transparency About the Role We re looking for a highly motivated Risk Manager to join our team and play a crucial role in overseeing the development and implementation of the operational risk management framework across the organization. In this role, you will collaborate with cross-functional teams, senior leadership, and external stakeholders to identify, assess, and mitigate risks effectively. The ideal candidate will have a strong problem-solving mindset, excellent analytical skills, and a proven track record of managing risk in a result-oriented environment. As a Risk Manager, you will contribute to shaping a robust risk culture and ensuring smooth operations within the organization. Key Responsibilities: Risk Identification & Assessment: Perform risk identification and assessments across various functions, and recommend process changes to mitigate operational risks. Cross-Functional Collaboration: Work closely with teams like Credit, Risk, Compliance, and Technology to implement effective risk mitigation strategies. Monitoring & Reporting: Track and analyze key risk indicators, and provide regular updates to management and stakeholders. Risk Committee Coordination: Lead and orchestrate Monthly Risk Committee meetings, providing insightful reports to senior leadership and key stakeholders. Incident Management: Examine reported incidents and validate the implementation of corrective and preventive actions. Audit Coordination: Collaborate with internal audit teams to align risk management efforts with audit activities. Root Cause Analysis: Conduct root cause analysis (using methods like 5 Whys, Fishbone, etc.) to identify corrective and preventive actions. Risk Awareness & Training: Conduct training sessions to promote risk awareness and adherence to risk management practices across the organization. Required Skills & Expertise: Experience: 2-5 years of experience in operational risk management, preferably within the financial industry. Risk Assessment & Mitigation: Deep knowledge of risk assessment methodologies and risk mitigation strategies. Regulatory Knowledge: Clear understanding of regulatory requirements related to risk management. Audit Knowledge: Familiarity with auditing principles and standards (e.g., ISO, CMMI). Problem-Solving: Strong analytical skills and the ability to solve complex problems with a detail-oriented approach. Communication Skills: Excellent interpersonal and communication skills to collaborate with senior leaders, cross-functional teams, and external stakeholders. Ownership & Responsibility: A high level of accountability and ownership in driving initiatives to completion. Qualifications: Educational Background: Graduate degree (CA, MBA from a Tier 1 Institute preferred). Technical Skills: Strong proficiency in Excel (knowledge of SQL will be an added advantage). Certifications (Preferred): Knowledge of internal and external audit standards like ISO, CMMI, etc. Impact: Shape the future of risk management in one of India s fastest-growing financial services platforms. Growth Opportunities: Take ownership of key risk management projects and contribute to the company s overall strategy. Culture: Work in a collaborative, transparent, and innovative environment where your contributions are valued. If you're passionate about risk management and want to make a significant impact in a fast-growing fintech company, we d love to hear from you. Qualification : Graduate degree (CA, MBA from a Tier 1 Institute preferred)
Sr. Manager, Internal Audit
Shopup
Sr. Manager, Internal Audit Location: Bengaluru, India Company: ShopUp HQ Role Overview The Senior Manager of Internal Audit will lead the planning, execution, and reporting of audits across multiple departments. This role focuses on evaluating risk management processes, internal controls, and compliance with both organizational policies and external regulations. The ideal candidate will bring extensive experience auditing FMCG companies and distribution operations, with a strong emphasis on process improvement, regulatory adherence, and supporting organizational governance. Key Responsibilities Plan, lead, and conduct internal audits across departments to assess risks, control effectiveness, and compliance with policies and regulations. Perform targeted audits related to FMCG and distribution house operations, addressing operational risks and process inefficiencies. Analyze current business processes to identify inefficiencies or risk areas, and recommend actionable process improvements. Develop and implement audit strategies, methodologies, and frameworks aligned with organizational objectives. Collaborate with internal stakeholders to communicate audit findings, provide guidance, and drive timely corrective actions. Prepare comprehensive audit reports, highlighting key risks, gaps, and recommendations for senior management and leadership. Track and monitor the implementation of audit recommendations and follow-up actions to ensure closure. Design and deliver training programs to foster awareness of internal controls, risk management, and compliance culture throughout the company. Conduct field visits and on-site audits as per the audit calendar and perform unannounced surprise audits. Qualifications & Experience Professional Experience: Minimum 8 years of experience in Internal Audit, risk management, compliance, and process improvement. Hands-on experience auditing FMCG companies and distribution-heavy operations is strongly preferred. Educational Qualifications: Bachelor s degree in any discipline with a strong academic record. Qualification : Bachelors degree in any discipline with a strong academic record.
Audit Analyst II - IT Audit & Compliance
Swiggy Careers
Audit Analyst II - IT Audit & Compliance Location: Bangalore, Karnataka Full Time Experience: 3-4 Years Work Environment: Work from Office (Occasional travel required) About the Team & Role: We are seeking a motivated and detail-oriented IT Audit Analyst to join our Audit & Compliance team. This role involves planning, executing, and reporting on IT audits across various domains, including IT infrastructure, cloud environments, SaaS applications, and compliance frameworks like ISO 27001, ISO 27701, and PCI DSS. The successful candidate will evaluate IT controls, identify risks, and recommend practical solutions to improve the organization's IT governance, risk management, and control environment. You will work independently on moderately complex audits and assist senior auditors on larger engagements. Key Responsibilities: Audit Planning & Execution: Assist in the development of risk-based IT audit plans. Plan and execute audits covering infrastructure, cloud services (AWS), and SaaS applications. Develop audit programs and testing procedures to evaluate IT controls. Compliance & Framework Audits: Conduct audits against IT security and privacy frameworks, including ISO 27001 (Information Security), ISO 27701 (Privacy Information), and PCI DSS (Payment Card Industry Data Security Standard). Risk Assessment & Analysis: Identify IT risks and control weaknesses during audits. Analyze findings and assess potential business impacts. Evaluate risk mitigation strategies. Reporting & Communication: Document audit work, prepare draft reports with findings and recommendations, and communicate results to management and stakeholders. Collaboration & Improvement: Collaborate with IT teams, business units, and external auditors. Stay up-to-date with emerging technologies, IT security threats, and audit methodologies. Contribute to continuous improvement efforts for the audit function. Qualities We re Looking For: Education & Experience: Education: Bachelor s degree in Information Systems, Computer Science, Cybersecurity, Business Administration, or related field. Experience: 3-4 years of progressive experience in IT Audit, Information Security, IT Risk Management, or a related field. Technical Skills: Strong understanding of IT infrastructure components (networks, operating systems, databases, servers, virtualization). Solid knowledge of cloud computing, specifically auditing cloud environments (AWS focus). Experience auditing SaaS solutions and assessing third-party/vendor risk management. Knowledge of IT general controls (ITGCs) and application controls. Framework & Standard Knowledge: Demonstrated experience with ISO 27001, ISO 27701, and PCI DSS standards. Familiarity with other frameworks such as NIST Cybersecurity, COBIT, and SOX ITGCs is a plus. Audit Skills: Proficiency in IT audit methodologies, risk assessment techniques, and control testing procedures. Strong analytical, problem-solving, and critical-thinking skills. Excellent written and verbal communication skills, with the ability to articulate technical issues to both technical and non-technical audiences. Attention to detail and ability to manage multiple tasks and deadlines. Proficiency with Microsoft Office Suite. Certifications & Tools: Professional certifications such as CISA, CISSP, CISM, CRISC, AWS Certified Security Specialty or similar are highly desirable. Experience with GRC (Governance, Risk, Compliance) tools. Experience with data analysis tools like ACL, IDEA, or Excel PowerQuery/Pivot. Joining our team means becoming part of a dedicated, high-performing group focused on IT governance, risk management, and compliance. As an IT Audit Analyst, you'll have the opportunity to work on exciting, challenging audits, develop your skills, and contribute to continuous improvement initiatives. We offer a collaborative and innovative environment where you can grow professionally while making an impact on the organization s success. Equal Employment Opportunity: We are an Equal Employment Opportunity employer. We do not discriminate based on race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. Qualification : Bachelors degree in Information Systems, Computer Science, Cybersecurity, Business Administration, or related field.
Audit Officer/executive
Pharmed Limited
Audit Officer/Executive Location: Rajkot Key Skills: Internal Audit, Control Audit, Operational Audit Education: B.Com, M.Com, MBA, or CA/ICWA Inter Experience: Minimum 4-5 years in an Audit Firm or Internal Audit Department Gender Preference: Male candidates are preferred due to the travel requirements. Travel Requirement: Willingness to travel regularly to company warehouse, CFA/CSA locations for audit purposes. Role Overview We are looking for an Audit Officer/Executive to join our team. This role is vital in performing internal and operational audits across various business functions. The successful candidate will be responsible for conducting critical business process audits, preparing audit findings, and assisting in improving internal processes and policies. This position will also require extensive travel to various company locations for surprise audits and monitoring. Key Responsibilities Critical Business Process Audits: Conduct audits of key business processes such as third-party procurement, supply chain, affiliation, HRD, commission structures, brand reminder purchases, freight bills, travel claims, and training expenses (DN/CN). Process & SOP Audits: Assist in reviewing processes, conducting SOP audits, and evaluating internal policies and limits of authority to ensure compliance and operational efficiency. Statutory Payments Audit: Audit statutory payments to ensure compliance with legal and regulatory requirements. Stock Audits: Perform periodic stock audits at warehouses to ensure accurate inventory records and assess stock management processes. Surprise Audits: Travel to CFA/CSA locations for surprise audits as required, ensuring integrity and compliance with policies in remote locations. Reporting & Documentation: Document audit activities thoroughly, prepare clear audit findings reports, and ensure all audit processes and results are well-documented. Maintain and manage audit-related documents, including query sheets and the resolutions to those queries. Follow-Up Audits: Conduct follow-up audits to monitor the implementation of corrective actions identified in previous audits. Risk Identification & Cost-Saving: Identify loopholes in processes, recommend risk aversion measures, and suggest cost-saving initiatives to improve operational efficiency. Knowledge Development: Stay updated on rules, regulations, best practices, and new audit tools and techniques to ensure consistent improvement and development in audit standards and performance. Skills & Qualifications Educational Qualifications: Experience: At least 4-5 years of experience working in an audit firm or within an internal audit department. Core Skills: Strong knowledge and experience in internal audit, control audits, and operational audits. Strong understanding of business processes, including procurement, HR, supply chain, and statutory payments. Technical Skills: Proficient in Microsoft Office (Excel, Word, PPT) for audit documentation and reporting. Ability to prepare and present audit findings and reports effectively. Communication Skills: Excellent oral and written communication skills. Attention to Detail: Strong attention to detail and the ability to identify risks, inefficiencies, and cost-saving opportunities. Travel Flexibility: Willingness and readiness to travel extensively to various CFA/CSA locations for surprise audit assignments as needed. This is an excellent opportunity for a seasoned audit professional to join a growing organization where you can expand your career in a diverse and dynamic role. You ll gain exposure to multiple business processes and industries while working with a team of experienced professionals. We provide an open and collaborative work environment, with ample opportunities for learning and career advancement. Qualification : B.Com, M.Com, MBA, or CA/ICWA Inter.
Supplier Governance Specialist
International Business Machines Corporation
Job Title: Supplier Governance Specialist Location: Bengaluru, India Company: IBM Finance Organization Introduction This role requires a detail-oriented individual with strong organizational skills, capable of handling sensitive information with discretion and professionalism. The incumbent must also be adaptable, given the dynamic nature of supplier relationships and risk management scenarios. Your Role and Responsibilities The Supplier Governance Specialist will play a crucial role within the Client Supplier Governance team. This role involves supporting various stages of supplier governance, from initial risk assessments through to ongoing due diligence and reporting. The incumbent will be responsible for facilitating initial supplier risk screenings, conducting initial and ongoing due diligence, providing reporting support, and ensuring adherence to business rules and requirements. Key Responsibilities: Supplier Risk Assessment Support: Assist business/contract owners in completing the assessment questionnaire. Guide them through navigating secondary risk teams. Report the outcomes of the questionnaires. Repeat assistance as necessary until satisfactory completion. Due Diligence Questionnaire Support: Distribute the due diligence questionnaire to relevant parties. Validate that responses align with Telstra's business rules and requirements. Trigger appropriate actions based on Procurement and Specialist Risk Teams' inputs. Identify required follow-up actions, track their progress, and report status. Ongoing Supplier Due Diligence: Monitor contract and supplier risk alerts, triaging and escalating as per business rules. Maintain currency of questionnaire responses and supplier information. Track activities needed for remediation of identified gaps in questionnaires. Provide support in updating and maintaining the Risk Framework. Offer reporting support for risk-related activities. Required Education Associate s Degree/College Diploma in a relevant field (e.g., Supply Chain Management, Business Administration, or related field). Required Technical and Professional Expertise Relevant experience in supplier governance, risk management, or procurement. Strong understanding of procurement processes and risk management principles. Excellent communication skills to guide non-expert users through processes. Strong analytical skills to interpret data and make informed decisions. Proficient in using digital tools and systems for questionnaire distribution, tracking, and reporting. Ability to work independently and as part of a team, managing multiple tasks simultaneously. Preferred Technical and Professional Experience NA (Not Applicable) About IBM Finance Organization The IBM Finance Organization is responsible for driving enterprise performance and transformation. As the financial stewards of IBM, we deliver IBM s financial strategy, develop new business models, and mitigate enterprise risk. If you have a passion for creating business value, join our team in areas such as accounting, financial planning, pricing, business controls, tax, treasury, business development (acquisitions & divestitures), and global financing. Qualification : Associates Degree/College Diploma in a relevant field (e.g., Supply Chain Management, Business Administration, or related field).
Grc Specialist
Locus
Job Title: GRC Specialist Location: Bangalore (On-site; full-time) About Locus: At Locus, we are redefining logistics decision-making with deep-tech solutions that drive efficiency, consistency, and transparency across industries like retail and FMCG/CPG. Founded in 2015 by Nishith Rastogi and Geet Garg, Locus has evolved from a women s safety geo-tracking app into a globally recognized logistics optimization platform. Our technology has empowered enterprises such as Unilever and Nestl to execute over a billion deliveries across 30+ countries. Guided by our commitment to innovation and sustainable growth, we transform complex supply chains into strategic growth enablers. Join us at Locus and be part of a team shaping the future of global logistics. Job Overview: About the Role Governance Risk and Compliance Specialist (GRC Specialist) We're looking for a candidate with 2-4 years of relevant experience. Key Responsibilities: Define, implement, and maintain the Information Security Management System (ISMS) and Privacy Information Management System (PIMS). Plan and execute periodic risk assessments. Work directly with the business units to facilitate risk assessment and risk management processes. Define, Review and Maintain the organizational information security policies, processes, procedures and control framework to ensure it is adequate to address the emerging risks due to changing environment, technology and legal requirements. Align customer and internal information security objectives to the ISMS and PIMS. Monitor and fulfill client contractual (MSA) information security and privacy obligations. Monitor and fulfill legal obligations related to protection of personal information across different jurisdictions like GDPR, CCPA. Prepare metrics based periodic reports and dashboards with support from the stakeholder functions for management review. Liaise with security vendors, suppliers, service providers and external resources for new security tools for improving security. Lead the Information Security audits / assessments / remediation and present key risks to the management. Perform the Third party Risk Assessment of Critical Vendors. Conduct Information Security and Privacy awareness and training programs for the employees as part of their induction and regular awareness. Oversee information security and privacy incident management process for incident reporting, containment, resolution and root cause analysis. Plan and coordinate BCP and DR tests. Setup guidelines for secure coding practices. Recommend security and privacy controls based on people, process and technology approach and industry best practices. Identifying solutions or writing automation scripts for solving regular tasks or optimizing processes. SOC Monitoring Activities such as. Firewall, Vulnerability, Inspector, Guarduty etc. Log Review, Incident Handling & Compliance adherence. Qualifications: Good understanding of information security compliance requirements like ISO27001, SOC2, CSA STAR and Privacy requirements like BS10012 & ISO27701. Good understanding of legal obligations towards protection of personal information across different jurisdictions like GDPR, CCPA, etc. Experience in creating and auditing security and privacy best practices and implementation of security and privacy principles across organization, to meet business goals along with customer and regulatory requirements. Experience implementing security and privacy controls for cloud platforms like AWS, Azure. Experienced in solving Audit and Regulatory Issues. Experience in auditing MDM, SSO solutions, AWS (Cloud Infra), Firewall, WAF, DLP etc. Good at solving information security compliance challenges by recommending solutions and best practices. Join Locus and become part of a visionary team that is redefining logistics through innovation and smart distribution. We provide competitive compensation, comprehensive benefits, and a collaborative environment where your expertise will drive both your growth and that of the organization. Locus is an equal opportunity employer dedicated to creating a diverse and inclusive workplace.
Security Engineer - II
Locus
Job Title: Security Engineer - II Location: Bangalore (On-site; full-time) About Locus: At Locus, we are redefining logistics decision-making with deep-tech solutions that drive efficiency, consistency, and transparency across industries like retail and FMCG/CPG. Founded in 2015 by Nishith Rastogi and Geet Garg, Locus has evolved from a women s safety geo-tracking app into a globally recognized logistics optimization platform. Our technology has empowered enterprises such as Unilever and Nestl to execute over a billion deliveries across 30+ countries. Guided by our commitment to innovation and sustainable growth, we transform complex supply chains into strategic growth enablers. Join us at Locus and be part of a team shaping the future of global logistics. Job Overview: Key Responsibilities: Conduct comprehensive threat modeling for applications, cloud infrastructure, and overall systems architecture. Perform secure code reviews and security assessments for web, Android, and iOS applications, with a strong focus on cloud infrastructure security. Proactively identify and mitigate vulnerabilities across platforms, collaborating with development and DevOps teams to implement secure solutions. Automate and streamline security processes, aligning with the principle that Complexity is the enemy of Security. Oversee Vulnerability Management and Patch Management processes, ensuring timely remediation. Design and implement robust security measures and contribute to Red Team activities, including assessments of cloud, network, wireless, physical, and social engineering scenarios. Take ownership of assigned tasks and drive the continuous improvement of security practices across the organization. Assist in setting up and maintaining monitoring systems to identify and respond to potential incidents in real time. Develop custom tools, scripts, and scanners to address unique security challenges and automate repetitive tasks. Provide architectural guidance for securing cloud-based applications and DevOps pipelines. Continuously stay updated on emerging security technologies and techniques, sharing knowledge with the team. Qualifications: 3-5 yrs experienced Sr security engineer. Expertise in cloud security (AWS, Azure, or GCP) with a strong understanding of securing applications and infrastructure in cloud environments. Proficiency in DevOps and DevSecOps practices, including secure CI/CD pipeline integration and automation. Strong knowledge of OWASP and SANS testing methodologies for identifying and mitigating security vulnerabilities. Good understanding of software security weaknesses, architecture vulnerabilities, and mitigation strategies. Hands-on experience in threat modeling, vulnerability assessments, and penetration testing. Proficiency in any scripting language - Python. Experience in developing or customizing tools, scanners, or extenders for specific security needs. Ability to work independently and collaboratively within a team to solve complex security challenges. Experience in implementing security monitoring systems for early incident detection. Strong problem-solving skills and the ability to think creatively to simulate attack scenarios. Certification in security-related fields (e.g., AWS Certified Security, CISSP, CEH, OSCP). Experience with container security and orchestration platforms like Kubernetes and Docker. Knowledge of Infrastructure as Code (IaC) tools like Terraform or CloudFormation. Familiarity with modern DevOps tools (e.g., Jenkins, GitLab, Ansible). Join Locus and become part of a visionary team that is redefining logistics through innovation and smart distribution. We provide competitive compensation, comprehensive benefits, and a collaborative environment where your expertise will drive both your growth and that of the organization. Locus is an equal opportunity employer dedicated to creating a diverse and inclusive workplace.
IMPO UAM Authorization Analyst
Johnson & Johnson
Job Title: IMPO UAM Authorization Analyst Location: Bengaluru, India Unit: Johnson & Johnson Innovative Medicine Principal Operations (IMPO) Job Type: Full-Time Employment Type: Permanent About Johnson & Johnson: At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, profoundly impacting health for humanity. Role Purpose: The IMPO UAM Authorization Analyst role at Johnson & Johnson is responsible for enhancing user access security and compliance within global SAP S/4 systems, while driving key User Access Management (UAM) initiatives. This role supports business adaptation through SAP S/4 HANA implementation, focusing on core SAP Manufacturing, Order to Cash, Procure to Pay, and Finance processes. The position is part of the IMUAM team, ensuring security requirements are designed and implemented compliantly within the Transcend Program, a global initiative for business transformation. Key Responsibilities: Security Workshops & Role Design: Lead security workshops to gather business and compliance requirements for role design, ensuring validation post-build for S/4 HANA Roles and Authorization requirements. UAM Strategy Development: Develop UAM strategies involving composite roles, Fiori tiles, business roles/user personas, and data security/UI masking concepts for S/4HANA. Data Validation & Compliance Documentation: Perform data validation, conduct health checks, and provide compliance documentation to ensure proper security implementation. Role Design & Testing: Design, test, and implement rule sets for SAP S/4HANA role design, ensuring they align with security protocols. User Account Setup & Support: Support role data and user account setup. Provide advice on role design testing and coordinate business UAT activities. Authorization Defects Management: Manage authorization defects and provide support for user cutover and Hypercare activities during and post-implementation. Collaboration & Training: Work closely with the Business Adaptation team to facilitate training, communication, and readiness across regions. Assist in transitioning between project phases and operational support teams. Compliance & Security Audits: Ensure compliance with internal and external standards through regular SAP security assessments and audits. Issue Troubleshooting & Resolution: Troubleshoot and resolve complex SAP security issues to maintain a secure environment. Documentation Management: Develop and maintain comprehensive documentation for SAP security policies, procedures, and configurations. Mentorship & Team Development: Train and mentor junior team members, promoting the implementation of SAP security standard processes. Qualifications: Required: Educational Background: Bachelor s degree in a relevant field (preferably Risk Management, Compliance, Audit). Experience: 6-8 years of experience in UAM within an enterprise risk management framework. Demonstrated expertise in SAP GRC Access Control and Identity Management tools. Hands-on experience with end-to-end SAP S/4HANA implementation, including Fiori. Deep knowledge of SAP authorization concepts, Segregation of Duties (SoD) mitigation, and remediation strategies. Proficiency in risk matrix/rule set maintenance, data analysis, conversion, and migration. Tools & Platforms: Experience with teamwork platforms (e.g., Confluence, Jira, MS Teams). Project Management: Strong project management and collaboration skills with experience in remote and virtual environments. Language Skills: Fluent in English with outstanding oral and written communication skills. Additional Experience: Experience in the pharmaceutical domain is a plus. Preferred: Industry Experience: Experience in Life Sciences, Pharmaceuticals, or similar industries. Leadership & Innovation: Demonstrated leadership skills with the ability to embrace innovation and promote a culture of continuous improvement. Project Management: Previous experience in a PMO role managing large-scale SAP implementation projects. Cross-Cultural Team Collaboration: Ability to work effectively with team members from different cultural and technical backgrounds. Other Requirements: Hybrid Work: Ability to work on-site a minimum of three days per week, with up to two remote workdays based on the flexible work policy. Travel: May require up to 10% domestic and/or international travel. Diversity & Inclusion: Johnson & Johnson is an Affirmative Action and Equal Opportunity Employer. We are committed to fostering an inclusive and diverse work environment, and we encourage applicants from all backgrounds to apply. We value diversity and do not discriminate based on race, color, religion, sex, sexual orientation, gender identity, age, national origin, or veteran status. Qualification : Bachelors degree in a relevant field, with a preference for studies in Risk Management, Compliance, and Audit.
Application Security Engineer
Phonepe
Job Title: Application Security Engineer About PhonePe Group PhonePe is India s leading digital payments company with 500 million registered users and 37 million merchants, covering over 99% of India s postal codes. Building on its leadership in digital payments, PhonePe has expanded into financial services, including insurance, mutual funds, stock broking, and lending. It has also ventured into adjacent tech-enabled businesses such as Pincode for hyperlocal shopping and Indus App Store, India s first localized app store. The PhonePe Group is a portfolio of businesses aligned with the company s vision to offer every Indian an equal opportunity to accelerate their progress by unlocking the flow of money and access to services. Culture At PhonePe, we empower our people and trust them to do the right thing. We create an environment that enables you to give your best every day, from day one. If you are passionate about building technology that impacts millions, ideating with the brightest minds, and executing with purpose and speed, PhonePe is the place for you! Job Description We are looking for a skilled Application Security Engineer to join our team and strengthen our security posture. You will proactively identify and mitigate vulnerabilities across our web applications, APIs, and mobile apps. The ideal candidate will have a strong background in penetration testing, secure code review, and security automation. Roles & Responsibilities (What You Will Do) Penetration Testing: Perform penetration testing on web applications, APIs, and mobile apps, providing in-depth vulnerability analysis and remediation guidance. Secure Code Review: Conduct both manual and automated secure code reviews, primarily in Java, Python, and JavaScript. Security Automation: Develop security automation solutions using Python to streamline testing, improve coverage, and reduce manual effort. Collaborate with Development Teams: Work closely with development teams to ensure timely resolution of security issues within fast-paced release cycles. Threat Modeling: Create and maintain threat models, applying threat modeling techniques to proactively identify and mitigate design-level security risks. Security Education: Foster a security-first mindset by educating developers on secure coding practices, common vulnerabilities, and attack vectors. Effectively communicate security findings to stakeholders. What Makes You a Great Fit Experience: 1-5 years of experience in application security, penetration testing, or related fields. Penetration Testing Expertise: Strong penetration testing expertise with tools like Burp Suite, OWASP ZAP, semgrep, MobSF, Jadx-GUI, and other mobile security testing frameworks. DevSecOps Knowledge: Experience integrating security into the SDLC and familiarity with DevSecOps tools. Secure Coding Knowledge: Proficiency in secure coding principles, OWASP Top 10, CWE, and exploit techniques. Scripting Skills: Strong scripting skills (Python preferred) for security automation. Communication Skills: Excellent communication and stakeholder management abilities. Continuous Learning: Passion for continuous learning and staying updated on security trends. Certifications (Optional): Certifications like OSCP, OSWE, CRTP, or a proven Bug Bounty track record and/or CTF participation are a plus. PhonePe Full-Time Employee Benefits Insurance Benefits: Medical Insurance, Critical Illness Insurance, Accidental Insurance, Life Insurance. Wellness Program: Employee Assistance Program, Onsite Medical Center, Emergency Support System. Parental Support: Maternity and Paternity Benefits, Adoption Assistance Program, Day-care Support. Mobility Benefits: Relocation Benefits, Transfer Support Policy, Travel Policy. Retirement Benefits: Employee PF Contribution, Flexible PF Contribution, Gratuity, NPS, Leave Encashment. Other Benefits: Higher Education Assistance, Car Lease, Salary Advance Policy. Why Work at PhonePe Working at PhonePe is a rewarding experience. With great people, a work environment that thrives on creativity, and the opportunity to take on roles beyond your defined job description, PhonePe offers a chance to grow your career in an innovative, dynamic company.
Security Architect (identity & Access Management)
Blue Yonder
Job Title: Security Architect Identity & Access Management Location: Bengaluru, India Company: Blue Yonder Experience: 10+ years (including at least 5+ years in IAM) Education: Bachelor's or Master's degree in Cybersecurity, Computer Science, or related field About Blue Yonder Blue Yonder is a recognized leader in AI-driven supply chain solutions, trusted by global brands to optimize their digital commerce and supply chain operations. We thrive on innovation, collaboration, and creating technology that powers smarter supply chains. As we continue to strengthen our security posture, we are seeking a Security Architect IAM to own, evolve, and safeguard Blue Yonder s identity landscape, ensuring consistent and compliant IAM controls across the organization s global footprint. Role Scope The Security Architect IAM will play a strategic and hands-on role in defining, implementing, and managing end-to-end identity and access management capabilities for Blue Yonder. This role requires deep technical expertise, leadership acumen, and a strong understanding of cloud-based identity ecosystems, ensuring secure access to critical systems and data. Key Responsibilities Define, develop, and manage a comprehensive IAM strategy, aligned with Blue Yonder s business goals, security policies, and compliance mandates. Design, implement, and enhance authentication, authorization, identity provisioning, access governance, and privileged access management (PAM) solutions, adopting best practices and industry standards. Conduct risk assessments to identify IAM vulnerabilities and define risk mitigation plans. Lead the technical implementation of IAM solutions and provide ongoing oversight to ensure operational excellence. Develop and enforce IAM policies, procedures, and standards to foster consistent security across the enterprise. Ensure IAM solutions adhere to regulatory requirements (GDPR, HIPAA, PCI DSS, SOX) and align with frameworks like NIST-CSF and ISO/IEC 27001. Integrate IAM capabilities with other security solutions (SIEM, endpoint security, etc.) for comprehensive protection. Establish and track Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) for the IAM program. Stay updated with emerging threats, technology advancements, and industry trends, adapting the IAM strategy accordingly. Conduct maturity assessments and develop continuous improvement plans for the IAM service. Participate in security architecture reviews and work with enterprise architects to embed IAM controls into broader IT and product architecture. Partner with GRC teams to ensure all IAM-related risks are properly documented and managed, driving remediation where necessary. Collaborate with application development teams to ensure secure-by-design development and deployment of new applications. Required Qualifications & Experience 10+ years of overall cybersecurity experience, with at least 5+ years specifically focused on IAM. Strong background designing and implementing cloud-based IAM solutions (Azure AD, AWS IAM, GCP IAM). Proven expertise across: Active Directory, LDAP, SSO, MFA SAML, OAuth, OpenID Connect Privileged Access Management (PAM) and Identity Governance (IGA) Experience managing IAM programs across hybrid environments (on-prem & cloud). Strong understanding of: Secrets management, encryption, PKI, digital certificates Zero Trust Security models Experience identifying, analyzing, and remediating IAM-related security risks. Knowledge of regulatory requirements (GDPR, HIPAA, SOX, PCI DSS) and experience translating those into practical IAM controls. Demonstrated ability to lead complex IAM projects, collaborating across multiple business units and technical teams. Excellent communication and stakeholder management skills, capable of interacting with both technical teams and business leadership. Preferred Certifications CISM Certified Information Security Manager CISSP Certified Information Systems Security Professional Relevant Cloud Security certifications (Azure Security Engineer, AWS Security Specialty, GCP Security Engineer) Good to Have Skills Experience integrating IAM with: CI/CD pipelines and DevSecOps practices Containerized environments (Kubernetes, Docker) Exposure to distributed tracing and logging tools for IAM services. Experience automating IAM processes for provisioning, deprovisioning, and audit reporting. Be a part of a global leader in supply chain technology. Work on cutting-edge IAM technologies in a cloud-first environment. Partner with cross-functional teams to drive impactful security programs. Join a culture that values diversity, innovation, and continuous learning. Diversity & Inclusion at Blue Yonder At Blue Yonder, we celebrate diversity in all forms. Our DIVE (Diversity, Inclusion, Value & Equity) strategy ensures every associate feels included, respected, and empowered to bring their authentic self to work. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, sexual orientation, gender identity, national origin, disability, or veteran status. Qualification : Bachelor's or Master's degree in Cybersecurity, Computer Science, or related field
Infosec Lead
Gameskraft
Infosec Lead Experience: 5-7 Years | Location: Bengaluru About Gameskraft: Founded in 2017, Gameskraft is one of India s fastest-growing online gaming companies. Our mission is to build a safe, secure, and responsible gaming ecosystem while delivering unmatched experiences through innovation and technology. As the industry s only ISO 27001 and ISO 9001 certified company, we set the highest benchmarks in security, design, and performance. Job Summary: We are seeking an experienced Infosec Lead to drive our security strategy, ensuring robust web security, application security, and compliance across the organization. You will be responsible for leading a team of security professionals, implementing best-in-class security measures, and ensuring compliance with industry regulations such as HIPAA, PCI-DSS, ISO, and GDPR. Key Responsibilities: Security Strategy & Program Management: Develop, implement, and maintain a comprehensive security program to safeguard company assets, systems, and data. Collaborate with cross-functional teams to integrate security into product development and business operations. Conduct risk assessments and vulnerability analyses to identify and mitigate security threats. Compliance & Regulatory Adherence: Ensure compliance with HIPAA, PCI-DSS, ISO, GDPR, and other relevant security frameworks. Maintain security certifications and drive adherence to regulatory standards. Develop and enforce security policies, standards, and procedures. Incident Response & Risk Management: Lead incident response efforts, including investigation, containment, and remediation. Continuously monitor security threats, emerging trends, and vulnerabilities to strengthen cyber resilience. Provide security guidance and risk analysis during product launches and infrastructure changes. Team Leadership & Stakeholder Collaboration: Lead and mentor a team of security professionals, fostering a culture of security awareness across the organization. Work closely with engineering, IT, legal, and business teams to embed security best practices. Present regular security reports and key performance metrics to senior management. What You Bring to the Table: Education: Bachelor s or Master s degree in Computer Science, Information Security, or a related field. Experience: 5-7 years of experience in information security, with a strong focus on web security, application security, and compliance. Proven track record in leading security teams and managing enterprise security programs. Technical Expertise: Strong knowledge of security technologies such as firewalls, IDS/IPS, SIEM, encryption, authentication protocols, and penetration testing tools. Experience with cloud security (AWS, Azure, GCP) and DevSecOps methodologies. Familiarity with secure coding practices and application security frameworks (OWASP, NIST, CIS Controls). Hands-on expertise in risk assessment, vulnerability management, and security architecture design. Certifications (Preferred): CISSP, CISM, CISA, CEH, or equivalent industry-recognized security certifications. Soft Skills & Leadership: Strong analytical and problem-solving skills. Excellent communication and stakeholder management abilities. Ability to influence and drive security initiatives across multiple teams. Work Culture at Gameskraft: Startup Environment: Fast-paced, ownership-driven culture where innovation and agility thrive. Impactful Work: Direct contribution to securing one of India s largest gaming platforms. Collaboration: Work alongside some of the best minds in the gaming and consumer internet industry. Data-Driven: Leverage analytics to enhance security posture and decision-making. Compensation & Benefits: Attractive Compensation & ESOPs Competitive salary with equity options. Health Insurance 5 Lakh medical cover for you and your family. Car Lease Policy Exclusive leasing options for employees. Relocation Benefits Assistance with moving to Bengaluru. Free Lunch & Stocked Pantries Enjoy great food while you work! Performance-Based Growth Transparent appraisals and rapid career progression. Join Us & Secure the Future of Gaming! If you re passionate about cybersecurity, risk management, and building secure digital ecosystems, we d love to have you on board. Apply now and be part of an exciting journey at Gameskraft! Qualification : Bachelors or Masters degree in Computer Science, Information Security, or a related field.
Risk Management & Compliance Analyst
Johnson & Johnson Services, Inc
Description At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at https://www.jnj.com/. Johnson & Johnson is recruiting for some great opportunities for its Global Services (GS) in Bangalore, India which is well equipped with the latest technology and modern infrastructure. This is your chance to work with the best talent in a workforce that reflects the diverse markets Johnson & Johnson serves around the world, and an inclusive culture that values different perspectives and life experiences. Reimagine the possibilities at Johnson and Johnson Global Finance! We live this motto every day by creating exciting business solutions for the world s largest and most broadly-based healthcare company. As a member of our Global Finance team, you will have exclusive access to a network of financial professionals located in over 60 countries. This new network will help you build on your current skills and explore opportunities to grow your career in J&J. At J&J Global Finance, we value ideas for innovation and improvement and are committed to diversity and inclusion. Together we will reinvent business processes to become more effective, more efficient, and improve customer experience. We are proud to be an equal opportunity employer. The Global Services Finance organization provides best-in-class, cost-effective financial services, and compliance support in a J&J way to our Operating Companies around the world. Risk Management & Compliance (RM&C) is one of such initiative under Global Services Finance. RM&C, ASPAC is seeking a Risk Management & Compliance Analyst who will have responsibility for fulfilment of the SOX and Compliance programs across J&J entities, training and advisory along with all Compliance related support to different sectors and performing walkthroughs, sampling, testing the effectiveness of control deployment, documentation of testing results, remediation support, monitoring, audit support, project support etc. Key Responsibilities 1. Be compliant with applicable laws and regulations, and follow guidelines in the J&J Credo 2. Maintain Operational Excellence Deep expertise and knowledge of the Worldwide Procedures and compliance requirements for respective areas. Identify compliance risks and recommend solutions to remediate / prevent breach. Ensure strong internal controls are in place and maintain compliant environment across the Organisation. Responsible for performing Compliance Health Checks and other internal reviews to test the effectiveness of the control placement. Support timely closing & execution of financial periods as per closing calendar and in accordance with SLA commitments, fully observing Compliance, Internal Audit & SOX requirements. Accountable for supporting completeness, accuracy and validity of the actuals reported within process/entity scope. Work closely with all business process and IT team members to communicate compliance requirements, documentation standards, sign-offs and review processes. Provide trainings to all business process owners for any change/update in financial procedures. Support projects, business partnering with collaborators, assisting business process owners with adoption of J&J policies & procedures. Support in standard Compliance document requirements: Risk Control Matrix, Hand-off s, SOPs and submission of required SOX templates (system inventory templates, SOX questionnaires etc.). Performs control walkthrough, operational testing and discusses the findings with the process owners. Conduct compliance due diligence for transitions in-scope. Testing of preventive & detective UA/SOD Controls (e.g. granting, facilitating appropriateness & semi-annual reviews) across all ERP systems. Support Sectors during Corporate Financial Audits. Supervise and drive the Corrective Action Plan (CAP) process, to ensure audit(internal & external) recommendations and key control gaps per SOX testing are implemented and other internal control gaps are closed timely and effectively. Be A Trusted Business Partner Implement global Strategy & Solutions in line with taxonomy. Support Process Subject Matter Experts (SME's) and Operational Key Contacts (OKC's) to ensure cross sector, cross region, and cross process alignment, ensuring good documentation is maintained and consistency of a global approach Create radical Innovation Generate ideas, fosters, and implements continuous improvement attitude, identifying and pursuing process efficiency opportunities. Manage operational improvements, generating ideas and implementing in line with global standards. Qualifications Qualifications Education A minimum of a Bachelor s level degree or equivalent is required, preferably in accounting, finance, or related business subject area. ACA, CPA and/or other financial certifications is highly preferred. Required At least 1 - 3 years of post qualification experience is required: Strong knowledge and understanding of accounting and financial processes (for Trading as well as Manufacturing business), shared services and related subject matter Understanding of internal controls, risk management, US GAAP accounting, financial systems, IT development and/or production support Clear understanding of SOX 404 requirements Understanding of audit procedures and auditing practices Experience in developing and managing audit programs desirable Experience in performing audits of financial processes and systems required, preferably in manufacturing/trading/service industry At least 1 year Management / Supervisory / team handling experience i...
Tech Lead
24]7.ai
Summary of Essential Job Functions The primary responsibility of the InfoSec Tech Lead is to ensure the organization's global information security, compliance, and risk management. The role involves collaborating with various teams to identify and implement security requirements for product applications and infrastructure. Minimum Requirements (Education & Work Experience) Education: Bachelor s/Master s degree in Computer Engineering or Information Science. Certifications (Preferred): OSCP, OSCE, ECSA|LPT, CPT, CEH. Experience: 5-7 years in Vulnerability Management, covering Application, Infrastructure, Cloud, Mobile Security, Secure Code Review, and IoT. Work Location: Bangalore, India (May require travel). Competency Requirements Hands-on experience in Network, Web-based, and Cloud Application Security Assessments including threat modeling, vulnerability assessments, and penetration testing. Knowledge of current information security trends. Familiarity with security bug classification frameworks (e.g., CVSS, DREAD) and application of classification methods. Expertise in Web Service vulnerability assessments. Understanding of Mobile Application Security (iOS/Android). Experience in code review methods and standards. Ability to develop proof-of-concept (POC) exploits for security vulnerabilities. Proficiency with web application vulnerability scanning tools (e.g., Acunetix, NTO Spider, BurpSuite Pro, WebInspect, Core Impact). Experience with network assessment tools and exploitations (e.g., Kali Framework, QualysGuard, Nessus, Nexpose, Nmap, Metasploit, Saint). Experience in static code review tools (e.g., Checkmarx, HP Fortify, IBM AppScan Source). Proficiency in at least two scripting languages (e.g., Python, Perl, PHP, Ruby, etc.). Ability to assess applications using OWASP, OSSTMM, CESG, CREST, NIST, ISSAF, PTES methodologies. Understanding of SDLC practices and adaptability to Agile methodologies. Experience in high-level programming languages (e.g., Java, C, C++, .NET (C#, VB)), with DAST code review as an added advantage. Knowledge of operating systems (Windows/Linux/UNIX IBM AIX, Sun Solaris, HP UX) and network equipment. Experience providing technical oversight to project teams to ensure quality engagements. Strong experience in mentoring, coaching, and leading teams in challenging environments. Familiarity with security compliance frameworks (PCI, SOC, GDPR). Other Requirements Strong ethics and integrity in business and information security. Proficiency in English (written and verbal communication skills). Ability to prepare professional reports and present findings to technical and executive stakeholders. Ability to interact with customers and understand security requirements. Job Responsibilities Conduct and manage Vulnerability Assessments and Penetration Testing (VAPT) for Infrastructure, Web Applications, and Web Services/APIs. Perform manual and automated security testing to identify vulnerabilities. Conduct periodic configuration audits for network devices, servers, and critical functions. Perform secure code reviews across multiple programming languages and recommend corrective actions. Assess SDLC processes for security compliance. Develop security testing scripts and procedures. Participate in security-related projects as per skillset. Continuously evaluate application architecture to enhance security processes. Analyze suspected vulnerabilities, collaborate with subject matter experts, and recommend remediation measures. Evaluate and recommend security products and solutions. Act as a security advisor for secure coding standards and security information management. Qualification : Bachelors/Masters degree in Computer Engineering or Information Science.
Senior Oracle Cloud Security Analyst
Oracle India
About Oracle Customer Success Services Oracle Customer Success Services (CSS) follows a One Oracle approach to ensure customer success by offering a comprehensive range of services and solutions. Supported by certified and experienced professionals, CSS accelerates the customer journey by providing expert implementation and support. Through a customer-centric, integrated service model, CSS collaborates closely with Oracle Development to deliver exceptional solutions. Role Overview As a Senior Cloud Security Engineer, you will be responsible for delivering high-quality support and services in Oracle Database, Engineered Systems, and Cloud Technologies for premium customers. This role covers the entire product lifecycle, including architecture design, implementation, optimization, and maintenance. You will work directly with customers to ensure they maximize the value of Oracle s technology solutions. Career Level: IC4 Key Responsibilities 4.5 to 10 years of experience in Oracle Cloud Infrastructure (OCI). Lead the full cycle of Oracle Cloud Security assessments, design, and implementations, ensuring adherence to best practices. Hands-on expertise in Oracle Identity and Access Management (IAM), Identity Cloud Service (IDCS), and cloud security solutions. Implement and manage Active Directory (AD) and IDCS connectivity. Define and maintain role hierarchies, function security policies, and provisioning mechanisms. Perform vulnerability scanning using Qualys Guard and recommend remediation actions. Customize roles and responsibilities while configuring Single Sign-On (SSO) solutions. Analyze and report on application security configurations and compliance status. Support Software Development Life Cycle (SDLC) processes, including environment configuration and migration. Ensure robust User Access Provisioning, Application Control, and Security management. Deliver end-to-end Oracle Cloud Applications Security & Controls services. Required Skills & Expertise Cloud Security Cloud Services Cloud Technologies Diversity & Inclusion at Oracle At Oracle, we believe innovation thrives in an inclusive environment that embraces diverse perspectives. Our career opportunities span industries, roles, countries, and cultures, allowing employees to grow, innovate, and maintain work-life balance. With over 40 years of industry leadership, Oracle operates with integrity and excellence, serving some of the world s top companies. We are committed to fostering an inclusive workforce that encourages thought leadership and innovation. Oracle offers a highly competitive suite of employee benefits, including: Medical and life insurance Retirement planning options Parental leave policies Flexible work arrangements Opportunities to give back to the community through volunteer programs
Member Of Technical Staff - Qa Security
Aryaka Networks
Position Overview: We are seeking a highly skilled and experienced Member of Technical Staff QA Security to join our dynamic team at Aryaka. As a Senior QA Engineer, you will play a crucial role in ensuring the security and integrity of our SASE products by conducting thorough security assessments, designing and executing test plans, and collaborating with development teams to address vulnerabilities. Your expertise will help shape our network security solutions and contribute to the success of organizations worldwide. Key Responsibilities: 1. Conduct Security Assessments: Perform comprehensive security assessments of SASE products to identify vulnerabilities, weaknesses, and misconfigurations. Utilize both manual and automated testing tools to uncover security vulnerabilities and potential exploitation vectors. 2. Design and Execute Test Plans: Develop and implement test plans and methodologies to evaluate the effectiveness of firewall configurations in defending against unauthorized access, malicious activities, and other security threats. Perform penetration testing on firewall devices to simulate real-world attacks and assess resilience against advanced threats. 3. Analyze and Report Findings: Analyze firewall logs, traffic patterns, and rule sets to identify anomalies and security incidents. Generate detailed reports outlining findings, including identified vulnerabilities, potential impacts, and recommended remediation measures. 4. Collaborate with Development Teams: Work closely with firewall development teams to prioritize and address security issues identified during testing phases. Provide technical guidance and recommendations regarding firewall security best practices, configuration hardening, and threat mitigation strategies. 1. Stay Informed on Security Trends: Keep up to date with the latest firewall technologies, security trends, and industry best practices to continuously improve firewall testing methodologies. Participate in the development and implementation of security policies, procedures, and standards related to firewall security testing. Qualifications: Education: Bachelor s degree in Computer Science or a related field. Experience: 3-7 years of experience as a QA Engineer. Technical Skills: Strong understanding of firewall technologies, including stateful inspection, packet filtering, application layer filtering, and intrusion prevention systems (IPS), CASB, and DLP. Knowledge of common security vulnerabilities and attack vectors, including OWASP Top 10, SQL injection, cross-site scripting, and buffer overflows. Familiarity with web application security standards and protocols (e.g., SSL/TLS, OAuth, SAML). Experience with cloud security (AWS, Azure, GCP) and container security is a plus. Hands-on experience with firewall testing tools such as Nmap, Nessus, Metasploit, and Wireshark. Understanding of network protocols, the TCP/IP stack, and common attack vectors used to exploit firewall vulnerabilities. Experience with scripting languages (e.g., Python) for automation and custom tool development is a plus. Soft Skills: Excellent analytical and problem-solving skills with the ability to identify and mitigate security risks effectively. Strong communication skills to convey technical concepts to both technical and non-technical stakeholders. Ability to work independently and as part of a team in a dynamic and fast-paced environment. Certifications: CISSP, CCSP, or CEH certifications are preferred. Employee Value Proposition (EVP): At Aryaka, we offer a dynamic and innovative work environment where you will have the opportunity to make a significant impact in the network security industry. Our commitment to cutting-edge technology and customer satisfaction provides a platform for continuous learning and professional growth. Qualification : Bachelors degree in Computer Science or a related field.
Information Technology Auditor
Intel Technology India Pvt Ltd
Job Description Internal Audit is chartered by the Audit and Finance Committee of Intel's Board of Directors to provide the Board and management with independent, objective assurance and advisory services. We advise and assist Intel in the wholistic oversight of enterprise risk management and propel Intel's risk management culture to help Intel achieve its purpose. Our work spans the breadth of Intel's operations, including manufacturing, engineering, technology development. The primary responsibilities for this role will include, but are not limited to: Evaluates risks and controls for software development, service operation, IT infrastructure, cyber security, information security, and related processes. Develops draft audit reports by identifying and gathering support for potential issues and recommending solutions. Contributes to planning, scope development, and project execution for sophisticated technology related audits and performs audit test work and preparation of adequate and sufficient audit documentation in accordance with prescribed methodology. Identifies root cause and opportunities for improvement of internal controls and acquires consensus on remediation plans with key business partners (IT operations, information security, SOX teams, etc.). Collaborates with the external auditors in the planning and execution of SOX requirements and ensures all deadlines are met with high quality deliverables. Acts as a primary interface between IT management and the external auditors to provide guidance, support, training, and project management. Establishes and maintains strong customer relationships with internal stakeholders, managers and staff. Qualifications Minimum qualifications are required to be initially considered for this position. Preferred qualifications are in addition to the minimum requirements and are considered a plus factor in identifying top candidates.Minimum Qualifications: Bachelor's degree in accounting, Finance, Business, Management Information Systems, Information Technology, Computer Science, Information Security, or similar field. 3+ years of experience in core internal audit processes including audit testing, documentation, reporting, and follow up. 2 + plus years of experience auditing or operating information technology or security processes or internal controls sufficient to provide requisite IT audit skills in areas such as, but not limited to, access to systems and data, change management/control, computer operations, system development/implementation, infrastructure, information and cyber security, etc. Willing to travel locally or internationally for 2-week periods up to 20 percent of the year depending on individual project requirements. Preferred Qualifications: Professional certification such as Certified Information System Auditor (CISA), Experience leveraging or innovating modern approaches to delivering IT audits. Experience in internal audit or public accounting. Inside this Business Group As members of the Finance team, employees act as full partners in making and supporting business decisions that are aimed at maximizing shareholder value. Intel Finance has a strong focus on facilitating change and improvement both within finance and in the operations supported. Qualification : Bachelor's degree in accounting, Finance, Business, Management Information Systems, Information Technology, Computer Science, Information Security, or similar field.
Internal Auditor - Operations
Hp
Description - We are seeking an experienced Internal Audit Principal Auditor with a specialization in Order to Cash (O2C) and a strong focus on Sarbanes-Oxley (SOX) compliance. The successful candidate will lead and execute internal audit engagements within the Order to Cash process, ensuring adherence to SOX requirements and identifying opportunities for process improvement and risk mitigation. What an Internal Audit SOX Principal Auditor does at HP: Oversee aspects of the O2C SOX compliance program in accordance with SOX and PCAOB standards, including scoping, planning, execution, and reporting. Ensure alignment with regulatory requirements and industry best practices. Perform risk assessments and design audit procedures to address key risk areas within the O2C process. Assess the effectiveness of internal controls within the O2C cycle, identifying control gaps, weaknesses, and areas for enhancement. Collaborate with process owners to implement remediation plans and drive continuous improvement. Communicate audit findings, recommendations, and risk insights to senior management and key stakeholders. Provide timely updates on audit progress and ensure alignment with organizational objectives. Lead a team of audit professionals, providing guidance and mentorship to enhance their skills. Provide technical guidance and professional development to junior staff, fostering their growth within the audit function. Collaborate with control owners to identify and document changes to internal controls, ensuring alignment with evolving business processes and regulatory requirements. Coordinate with auditors and co-sourcing partners for controls testing and process walkthroughs. Streamline audit impact on business operations and align test results for efficiencies. Take the lead in implementing effective project management strategies within the O2C SOX compliance program. Develop and implement robust project management methodologies tailored to the specific needs of SOX compliance activities. Ensure accurate tracking of compliance activities and deadlines, maintaining the project management framework to support ongoing SOX initiatives. Review and assess reported control deficiencies with business process owners. Identify root causes and collaborate on corrective actions to strengthen internal controls. Recommend improvements to enhance key controls, driving ongoing optimization of the SOX program. Lead various SOX meetings, facilitating discussions and decision-making processes to support compliance objectives. Work with IT and Compliance teams to ensure alignment with SOX requirements, fostering cohesive compliance efforts. Prepare and present SOX findings and assertions to both the SOX PMO and HP Leadership Team, providing insights for enhancing control effectiveness. Continuously improve the SOX program through optimization and automation initiatives, leveraging technology and best practices. Provide support for internal audit projects, addressing control-related issues and contributing to overall assurance efforts. Individuals who do well in this role at HP, usually possess: Minimum of 8+ years of progressive experience in Internal Audit, Finance, Business management, Accounting, or a related field preferably with exposure to Sarbanes-Oxley (SOX) compliance and Order to Cash (O2C) processes. Experience in public accounting or working with publicly listed companies may also be beneficial. Bachelor's degree in accounting, finance, business management, or a related field. A professional certification related to internal audit or accounting is preferred, such as: Certified Internal Auditor (CIA) Certified Public Accountant (CPA) Certified Information Systems Auditor (CISA) Chartered Accountant (CA) Demonstrated expertise in Sarbanes-Oxley (SOX) compliance, including in-depth knowledge of regulatory requirements such as Sections 302 and 404, and proficiency in internal control frameworks like COSO. Extensive understanding of the Order to Cash process, spanning sales order processing, credit management, invoicing, and revenue recognition, ensuring comprehensive control management. Competency in audit methodologies, with a focus on risk assessment, planning, execution, and reporting, along with the ability to tailor audit procedures for the O2C process. Robust project management capabilities, encompassing effective project planning, resource allocation, stakeholder engagement, and timely delivery of objectives within SOX compliance initiatives. Excellent communication skills, both verbal and written, enabling clear conveyance of findings, recommendations, and insights to stakeholders at all levels, including senior management. Prior experience and proven leadership in managing audit teams, fostering collaboration, and driving continuous improvement within the compliance function. Proficiency in SOX compliance tools and Microsoft Office applications, facilitating efficient compliance processes and documentation management. Strong analytical aptitude to assess control effectiveness, identify deficiencies, determine root causes, and propose effective remediation actions, ensuring robust risk mitigation. Up-to-date knowledge of regulatory developments in SOX compliance and O2C processes, with adaptability to evolving standards to maintain compliance alignment. Solution-focused problem-solving capabilities to address complex control issues encountered during compliance processes, driving effective resolutions and improvements. Proactive mindset towards continuous improvement, emphasizing optimization through automation, standardization, and adoption of best practices to enhance efficiency and effectiveness. Ability to collaborate effectively with cross-functional teams, providing strategic guidance for complex business transactions across multiple countries, ensuring alignment with compliance objectives and business goals. Candidates should be okay with 1) Individual contributor role 2) Hybrid model of work...
1 - 20 of 0 jobs
* No exact matches found. Showing closest results insteadNo results found
Modify search criteria or create an alert to get relevant jobs as soon as they’re posted