Associate - Senior IT Audit And Risk Analyst [T500-26875]
Internshala
About the job
About Deutsche Brse Group:Headquartered in Frankfurt, Germany, Deutsche Brse Group is a leading international exchange organization and market infrastructure provider. They empower investors, financial institutions, and companies by facilitating access to global capital markets.Their India centre is located in Hyderabad, serves as a key strategic hub and comprises Indias top-tier tech talent. They focus on crafting advanced IT solutions that elevate market infrastructure and services. Deutsche Brse Group in India is composed of a team of capital market engineers forming the backbone of financial markets worldwide." Your area of work:The Chief ICT Risk Office (CISO) combines IT & IS Risk Management in the 2nd Line of Defense. The departments mandate is to set the IT and IS (ICT) risk governance and framework, set the control objectives, control review methodology and risk assessment methodology, conduct independent risk assurance of 1st LoD ICT controls ( IT and IS controls), and independently monitor and report on the level of ICT risks as well as to drive transformation and collaboration.In this role, you will be part of ICT Risk Assurance team, performing continuous monitoring and oversight to confirm that our ICT controls are well-designed, correctly implemented, and operating effectively to protect the organization. Your responsibilities:
- Design and implement risk-based assurance plans aligned with internal and regulatory requirements
- Lead and execute IT & IS assurance assessments to evaluate risks across applications, infrastructure, cloud platforms, and network/security processes
- Ensure IT systems and processes comply with relevant laws, regulations, and standards, including DORA, MaRisk, CSSF, NIST, ISO 27000, etc.
- Test the effectiveness of IT General Controls (ITGC) and cybersecurity controls across Access Management, SDLC & Change Management, Encryption, Third Party Risk, Patch & Vulnerability Management, SIEM, Penetration Testing, IT Operations, and other security domains to identify gaps and improvement areas
- Prepare high-quality assurance reports with clear observations, identified risk, and actionable recommendations for management; effectively communicate complex technical issues to both technical and non-technical stakeholders
- Track and monitor remediation actions, validate closure, and ensure sustainability of corrective measures
- Collaborate with IT, Security teams, and other cross-functional stakeholders to provide risk insights or guidance on risk and control expectations for new and existing systems
- Contribute to the continuous improvement of assurance methodologies, frameworks, and processes
- Stay updated with emerging cyber threats, industry trends, evolving technologies, cloud risks, and changes in the regulatory landscape
Don't want to miss the next one?
Subscribe to daily email alerts for roles matching your interests.