ITGC Auditor / SOX IT Controls Analyst
Location: India
Experience: 3–5 years
Role type: Full-time
Duration: 6 - 10 months with possibility of extension
We are looking for an ITGC Auditor to support IT general controls testing and SOX compliance activities for a global client environment. The role requires hands-on experience in IT General Controls, including, but not limited to, Segregation of Duties (SoD), access controls, password controls, change management, and IT operations controls, along with strong documentation and stakeholder management skills.
Key responsibilities
- Perform ITGC and SOX control testing across applications, infrastructure, databases, and supporting IT processes.
- Perform IT General Controls (ITGC) testing across key domains including access management, change management, IT operations, backups, and system monitoring to assess design and operating effectiveness.
- Review and test Segregation of Duties (SoD) conflicts and remediation actions.
- Assess user access controls, including provisioning, deprovisioning, periodic access reviews, and privileged access management.
- Test password controls such as complexity, expiry, lockout, reset, and emergency access procedures.
- Evaluate change management controls for application, database, OS, and infrastructure changes.
- Review IT operations controls including backups, batch/job monitoring, incident management, interface controls, and system monitoring.
- Perform control walkthroughs, prepare test workpapers, and document results clearly and accurately.
- Identify control deficiencies, assess impact, and track remediation to closure.
- Coordinate with IT, business, and compliance stakeholders to collect evidence and resolve issues.
- Support internal, external, and SOX audit requirements.
Required skills and experience
- 3–6 years of experience in ITGC, SOX testing, IT audit, internal audit, or risk/compliance.
- Strong understanding of SoD, access management, password controls, and change management.
- Experience in control design and operating effectiveness testing.
- Good knowledge of audit documentation, evidence validation, and issue reporting.
- Strong communication skills and ability to work with cross-functional teams.
- Ability to manage multiple priorities in a deadline-driven environment.
Preferred qualifications
- Post-graduate in information security or related areas.
- CISA, CIA, CISSP, or similar certification.
- Exposure to ERP, Windows, databases, Active Directory, or cloud environments.
- Experience working with global teams or shared services environments.
- Familiarity with audit tools, GRC tools, or ticketing systems.
Ability to commute/relocate:
- Chennai, Tamil Nadu (Chennai, Chennai District): Reliably commute or planning to relocate before starting work (Required)
Education:
Experience:
- IT auditing: 3 years (Required)
Language:
Work Location: In person