Posted 19 July, 2026
Business Risk and Controls
ClifyX
Bengaluru,Karnataka,India
Full Time
Reference: 365_594563_25-03549
Role : TS-ID- 15241- Business Risk and Controls
| Number of Openings | 1 |
| ECMS ID in sourcing stage | TS-ID-15241 |
| Assignment Duration | 6 Months |
| Total Yrs. of Experience | 8+ years |
| Relevant Yrs. of experience | 5 +years |
| Detailed JD (Roles and Responsibilities) | Responsibilities : |
| Organize, conduct and perform technology and information security risk assessments to identify and evaluate risks in technology delivery. | |
| The successful candidate is expected to handle the following responsibilities: | |
| 1. IT Risk Management: | |
| • Organize, conduct and perform technology and information security risk assessments to identify and evaluate risks in technology delivery areas and staff functions. | |
| • Assist the Management in developing plans to mitigate such risks. | |
| • Monitor compliance with the Firm's IT Security standards, Policy and Architecture | |
| • Work with functional and technology teams to ensure regulatory compliances. | |
| • Front-end interactions with internal and external auditors and regulators as required. | |
| • Prepare monthly management summaries on end user risk, vendor risk, technology infrastructure hygiene, technology resiliency and status of regulatory compliances. | |
| • Conduct Monthly/Quarterly Risk meetings. | |
| • Conduct periodic Audit Awareness meeting. | |
| • Drive risk awareness sessions. | |
| • Conduct Security Health check (SHC) for banking applications as per the ISF Standard of Good Practice for Information Security (SOGP). | |
| 2. IT Audit Management: | |
| • Acts as liaison for internal management, internal auditors, internal audit clients and business associates. | |
| • Recommends revisions to audit procedures to enhance efficiency. Reviews internal controls throughout the firm by evaluating the adequacy of system controls and recommends improvements. | |
| • Reviews and analyses the control structure, performs walkthrough and testing procedures, documents testing results that are reviewed by internal auditors, and communicates results to the process owners. | |
| • Evaluates the adequacy and timeliness of management's response and the corrective action taken on significant audit recommendations. | |
| • Performs other duties as assigned. | |
| 3. The successful candidate is expected to have the following skills: | |
| Desirable Certifications: CRISC, CISA, or equivalent | |
| • Good knowledge of IT Risk Management and IT Audit Management process/ procedure. | |
| • Ability to evaluate business processes and IT technology, identify risks and evaluate controls. | |
| • Clear oral and written communication skills | |
| • Good investigative and analytical skills. | |
| • Organizational and time management skills | |
| • Ability to work well within a team environment and participate in department projects. | |
| • Ability to balance detail with departmental goals/objectives. | |
| • Ability to conduct Security Health check integrated with ISF Benchmark using QIRAM (Quantitative Information Risk Assessment Methodology). | |
| • Ability to coordinate and perform multiple tasks/projects simultaneously, balancing priorities and deliverables. | |
| Domain | Business Risks and Controls |
| Max Vendor Rate in Per Day (Currency in relevance to work location) | 12000 INR |
| Work Location given in ECMS ID | Bangalore/Pune |
| WFO/WFH/Hybrid WFO | Hybrid |
| BG Check (Before OR After onboarding) | As per Infosys Policy |
| Is there any working in shifts from standard Daylight (to avoid confusions post onboarding) YES/ NO | NO |