Skip to main content
Posted 19 July, 2026

Business Risk and Controls

ClifyX
Bengaluru,Karnataka,India Full Time
Reference: 365_594563_25-03549

Role : TS-ID- 15241- Business Risk and Controls
Number of Openings 1
ECMS ID in sourcing stage TS-ID-15241
Assignment Duration 6 Months
Total Yrs. of Experience 8+ years
Relevant Yrs. of experience 5 +years
Detailed JD (Roles and Responsibilities) Responsibilities :
Organize, conduct and perform technology and information security risk assessments to identify and evaluate risks in technology delivery.
The successful candidate is expected to handle the following responsibilities:
1. IT Risk Management:
• Organize, conduct and perform technology and information security risk assessments to identify and evaluate risks in technology delivery areas and staff functions.
• Assist the Management in developing plans to mitigate such risks.
• Monitor compliance with the Firm's IT Security standards, Policy and Architecture
• Work with functional and technology teams to ensure regulatory compliances.
• Front-end interactions with internal and external auditors and regulators as required.
• Prepare monthly management summaries on end user risk, vendor risk, technology infrastructure hygiene, technology resiliency and status of regulatory compliances.
• Conduct Monthly/Quarterly Risk meetings.
• Conduct periodic Audit Awareness meeting.
• Drive risk awareness sessions.
• Conduct Security Health check (SHC) for banking applications as per the ISF Standard of Good Practice for Information Security (SOGP).
2. IT Audit Management:
• Acts as liaison for internal management, internal auditors, internal audit clients and business associates.
• Recommends revisions to audit procedures to enhance efficiency. Reviews internal controls throughout the firm by evaluating the adequacy of system controls and recommends improvements.
• Reviews and analyses the control structure, performs walkthrough and testing procedures, documents testing results that are reviewed by internal auditors, and communicates results to the process owners.
• Evaluates the adequacy and timeliness of management's response and the corrective action taken on significant audit recommendations.
• Performs other duties as assigned.
3. The successful candidate is expected to have the following skills:
Desirable Certifications: CRISC, CISA, or equivalent
• Good knowledge of IT Risk Management and IT Audit Management process/ procedure.
• Ability to evaluate business processes and IT technology, identify risks and evaluate controls.
• Clear oral and written communication skills
• Good investigative and analytical skills.
• Organizational and time management skills
• Ability to work well within a team environment and participate in department projects.
• Ability to balance detail with departmental goals/objectives.
• Ability to conduct Security Health check integrated with ISF Benchmark using QIRAM (Quantitative Information Risk Assessment Methodology).
• Ability to coordinate and perform multiple tasks/projects simultaneously, balancing priorities and deliverables.
Domain Business Risks and Controls
Max Vendor Rate in Per Day (Currency in relevance to work location) 12000 INR
Work Location given in ECMS ID Bangalore/Pune
WFO/WFH/Hybrid WFO Hybrid
BG Check (Before OR After onboarding) As per Infosys Policy
Is there any working in shifts from standard Daylight (to avoid confusions post onboarding) YES/ NO NO

Sign up for Job Alerts