
Senior Analyst- IT Audit
- Bangalore, Karnataka
- Permanent
- Full-time
- Maintain compliance with audit methodology, while also operating within industry best practices, applicable regulations, and internal and external professional practice expectations.
- Act as a leader and role model and continuously improve self and department.
- Working experience in Cybersecurity.
- Build relationships with peers and clients within organization and exhibit a high standard of performance and professional conduct that will create a culture of integrity and inclusion, where all individual and departmental choices are rooted in good judgment and support MUFG's Principal of Ethics and Conduct.
- Operate with an innovative and flexible mindset by continuously identifying ways to enhance consistency, efficiency, quality and/or value.
- Demonstrate professional skepticism and personal accountability.
- Lead walkthrough meetings and interviews with business stakeholders to develop an understanding of business processes.
- Lead formal discussions with business stakeholders throughout the duration of audit engagements to communicate status or concerns.
- Identify potential risks and controls and assist in developing scope and work programs.
- Evaluate design and operational effectiveness of internal controls and identify control weaknesses.
- Generate insightful, meaningful observations that effectively convey significance and impact on risk and/or risk management practices, reporting findings and audit issues to Audit Management.
- Prepare workpapers and audit reports with documented results that adhere to methodology, applicable standards and regulatory requirements, using appropriate business and technical language.
- Document workpapers demonstrating the work was appropriately performed (e.g., detailed lead sheets describing the control attributes that were tested, and the results were documented in a manner to support the conclusions reached, effectiveness and sustainable controls are evident in documentation). Documentation should stand alone to enable re-performance.
- Identify control weaknesses and escalate and discuss findings with Audit Management and business stakeholders as appropriate.
- Complete work on a timely basis and deliver work products that meet objectives and standards of methodology, applicable standards and regulatory requirements.
- A bachelors degree, preferably in Computer Science, Information Systems, Engineering or related business discipline at an accredited college or university.
- Good to have certifications, such as Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), or Certified Information Systems Security Professional (CISSP) preferred.
- Minimum of 4 years and / or equivalent of experience of internal audit and/or equivalent of experience with the financial services industry, related markets, and related regulatory agencies.
- IP networks infrastructure (network topology, switches, routers, firewalls, intrusion detection / prevention)
- Windows Active Directory, Azure and LDAP (policies, structure, elements)
- Good to Have-Databases (SQL, Oracle, DB2, monitoring tools)
- Mobile and DLP technologies (Data Leakage Prevention, BYOD security)
- Good to have Cloud Computing.
- Standards / Frameworks (e.g., CoBIT 5, ITIL, NIST series 800 guidance, FFIEC)
- Experience in IT audit(Internal or External Audit).
- Exhibits effective communication (both verbal and written), negotiation and presentation skills; strong interpersonal skills; and ability to engage with all levels of internal audit and business line management.
- Strong analytical and problem-solving skills.
- Employs critical thinking skills to identify pragmatic recommendations within an evolving and increasingly complex regulatory and risk management environment.
- Proficiency in technology as required for assigned areas (MS Office, audit data analytics, etc.).
- Ability to travel may be required.
The MUFG Group is committed to providing equal employment opportunities to all applicants and employees and does not discriminate on the basis of race, colour, national origin, physical appearance, religion, gender expression, gender identity, sex, age, ancestry, marital status, disability, medical condition, sexual orientation, genetic information, or any other protected status of an individual or that individual's associates or relatives, or any other classification protected by the applicable laws.