The Role
Leads IT and cloud security audits across ITGC, information security, network security, vulnerability management, cloud environments, and vendor risk. Assesses regulatory and policy compliance, validates controls, documents findings, manages remediation, and oversees third-party risk assessments. Develops security policies and procedures, supports cloud and network security implementations, and contributes security expertise to technology selection. Requires extensive information security auditing experience, cloud security knowledge, banking-sector familiarity, and relevant certifications.
Summary Generated by Built In
About the role
We are seeking an experienced and detail-oriented Information Security and Cloud Security Auditor to join our team. The ideal candidate will have 3-7 years of expertise in data security and privacy control implementation, internal auditing, third-party risk management, cybersecurity governance, and cloud security (banking sector preferred). This role will be responsible for conducting comprehensive IT and cloud security audits, ensuring compliance with regulatory requirements, and enhancing our information security policies and procedures.
Key Responsibilities
-Conduct IT and cloud security audits across various domains, including IT General Controls (ITGC), Information Security Controls, Cloud Security, Network Security, Vulnerability Management, and Vendor Risk Assessments.
-Assess compliance with relevant laws, regulations, industry standards, and organizational policies across both on-premises and cloud environments.
-Develop and enhance information security and cloud security policies and procedures in alignment with industry best practices.
-Maintain thorough documentation of audit findings, risk assessments, security measures, working papers, audit program checklists, and evidence for internal and external reporting.
-Validate ITGC, cloud security, and application-specific controls and manage audit documentation, risk assessments, evidence gathering, and control testing.
-Follow up on audit findings and ensure timely closure of non-compliance and security issues identified during audits.
-Manage and oversee third-party risk assessments and audits, ensuring robust security controls are implemented across traditional and cloud-based service providers.
-Lead and participate in the development, migration, and implementation of security controls and policies for network and cloud security solutions.
-Conduct risk-based security assessments of internal, vendor, and third-party hosted environments, covering both traditional IT infrastructure and cloud environments.
-Participate in product and vendor selection processes, contributing security and risk expertise to the evaluation, implementation, and integration of new technologies, with a strong focus on cloud security solutions.
Experience & Skills Required
-Minimum 10 years of experience in Information Security and Auditing, with a strong background in Cloud Security and the Banking and IT industries.
-Proven experience in conducting IT and cloud security audits, validating ITGC and cloud application controls, and maintaining comprehensive audit documentation.
-Hands-on experience in vulnerability management, risk management, physical security, identity and access management, encryption, secure development, incident management, security infrastructure, and security policies across on-premises and cloud environments.
-Strong expertise in third-party risk management, regulatory compliance, and management of IT audit findings across traditional and cloud-based environments.
-Strong analytical and problem-solving skills with excellent communication, stakeholder management, and documentation abilities.
-Ability to manage multiple projects, prioritize tasks, and meet deadlines effectively.
-Strong understanding of IT, cloud security, cybersecurity frameworks, standards, and industry best practices.
-Proficiency in security assessment tools and technologies, particularly those related to cloud environments.
Qualifications & Certifications
-Bachelor’s or Master’s degree in Information Technology, Cyber Security, Computer Science, or a related field.
-Preferred certifications include ISO 27001, CNSS, CCNA, CISA, CISM, and CISSP.
Detailed knowledge of security tools, PCI-DSS, ITGC controls, compliance testing, cloud risk assessment, GRC, OWASP, MITRE ATT&CK, change management, and security policies and procedures.
-Proficiency in security and cloud technologies including AWS, Azure, Google Cloud Platform (GCP), Palo Alto, Fortinet, Check Point Firewalls, SOAR (Cortex), and Forcepoint.
Why Join Us
-Be part of a collaborative, output-driven program that brings cohesiveness across businesses through technology.
-Contribute to improving average revenue per user by increasing cross-sell opportunities.
-Receive strong 360-degree feedback from peer teams on your contribution and support toward their goals.
-Earn respect through meaningful contributions and strong performance with peers and managers.
-Join an organization with 500M+ registered users, 21M+ merchants, and a deep data ecosystem, with the opportunity to contribute to India’s largest digital lending story.
-If you are the right fit, we believe in creating wealth and meaningful growth opportunities for you.
Skills Required
- Minimum 10 years of experience in information security and auditing
- Strong background in cloud security and the banking and IT industries
- Experience conducting IT and cloud security audits
- Experience validating ITGC and cloud application controls
- Experience maintaining comprehensive audit documentation
- Hands-on experience in vulnerability management, risk management, physical security, identity and access management, encryption, secure development, incident management, security infrastructure, and security policies
- Strong expertise in third-party risk management, regulatory compliance, and management of IT audit findings
- Strong analytical, problem-solving, communication, stakeholder management, and documentation skills
- Ability to manage multiple projects, prioritize tasks, and meet deadlines
- Strong understanding of IT, cloud security, cybersecurity frameworks, standards, and industry best practices
- Proficiency in security assessment tools and cloud security technologies
- Bachelor's or Master's degree in Information Technology, Cyber Security, Computer Science, or a related field
- ISO 27001 certification
- CNSS certification
- CCNA certification
- CISA certification
- CISM certification
- CISSP certification
- Knowledge of PCI-DSS, compliance testing, cloud risk assessment, GRC, OWASP, MITRE ATT&CK, change management, and security policies and procedures
- Proficiency with AWS, Azure, Google Cloud Platform, Palo Alto, Fortinet, Check Point Firewalls, Cortex SOAR, and Forcepoint
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Paytm started the Digital Revolution in India. And we went on to become India’s leading Payments App. Today, more than 20 Million merchants & businesses are powered by Paytm to Accept Payments digitally. This is because more than 300 million Indians use Paytm to Pay at their stores. And that’s not all, Paytm App is used to Pay bills, do Recharges, Send money to friends & family, Book movies & travel tickets. With innovations to Financial services & products in pipeline, this is but one of the milestones achieved towards our mission – to bring 500 million unserved and underserved Indians to the mainstream economy.









