- Location
- Bangalore, Velankani Tech Park, India · Pune - Business Bay
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Finance
- Seniority
- Lead
- Experience
- 8+ years
- Source
- Workday
Description
Job Description:
Job Title: Assurance Team Lead – Audit and Risk Management
Corporate Title: Vice President
Location: Bangalore, Pune, India
Role Description
The Assurance Team Lead – Audit and Risk Management is responsible for leading audit, risk, vendor risk management, governance, and risk reporting activities for the Hybrid Cloud Infrastructure division. The role drives end-to-end delivery of risk reduction and audit remediation initiatives, ensures timely closure of audit findings, strengthens the control environment, and provides transparent risk reporting to senior stakeholders. Strong project management, stakeholder engagement, governance discipline, and technology risk oversight are key success factors for the role. The role also drives proactive risk management by identifying emerging risks, assessing control weaknesses, initiating early mitigation actions, and ensuring risks are managed before they materialize into audit findings or control issues.
What we’ll offer you
As part of our flexible scheme, here are just some of the benefits that you’ll enjoy,
Best in class leave policy.
Gender neutral parental leaves
100% reimbursement under childcare assistance benefit (gender neutral)
Sponsorship for Industry relevant certifications and education
Employee Assistance Program for you and your family members
Comprehensive Hospitalization Insurance for you and your dependents
Accident and Term life Insurance
Complementary Health screening for 35 yrs. and above
Your key responsibilities
Lead audit, risk, VRM, governance, and risk reporting activities for HCI, ensuring alignment with GTI priorities, internal frameworks, and regulatory expectations.
Manage the full audit finding lifecycle, including challenge, management action plans, remediation tracking, evidence coordination, validation support, and timely closure.
Drive proactive risk management by identifying emerging risks, control weaknesses, recurring themes, and dependencies before they become audit findings or control issues.
Maintain a forward-looking risk profile for HCI through risk identification, assessment, monitoring, reporting, and early mitigation planning.
Identify and prioritise material remediation actions across GTI, including cross-divisional dependencies and control improvement initiatives.
Track remediation progress, overdue actions, and closure readiness, ensuring documentation is complete, evidence-based, and audit-ready.
Oversee vendor risk management activities, including risk assessments, recertifications, control reviews, issue management, subcontractor oversight, and regulatory obligations.
Represent the controls and assurance function in governance forums, providing clear updates on risks, audit findings, vendor issues, remediation status, and key themes.
Escalate risks, delays, gaps, and dependencies early, ensuring decisions and actions are tracked through to completion.
Partner with Audit, 2nd Line of Defence, Divisional Control, Embedded Risk, Service Owners, and Technology teams to strengthen the control environment.
Deliver timely and action-oriented risk reporting to senior stakeholders, highlighting risk posture, remediation progress, overdue items, and areas requiring management attention.
Promote a proactive IT/IS risk culture through early issue identification, transparent escalation, strong evidence discipline, and sustainable control improvements.
Service Owner
Risk Assessment and Management: Complete risk assessments, ensure proper screening, and report third-party issues.
Regulatory Compliance: Nominate Local Service Owners and ensure compliance with local regulatory requirements.
Third-Party Selection and Screening: Select third parties, consider risk aspects, and review screening outputs.
Control Assessments and Mitigation: Ensure third parties complete required tasks, develop continuity plans, and manage risk mitigation actions.
Continuous Monitoring and Termination: Update risk assessments, perform post go-live controls, and execute termination strategies.
Contracting and Payment: Complete risk assessments before service commencement, ensure contractual clauses are included, and execute risk process activities for contract renewals or amendments.
Stakeholder Management – Identify, Partner, and Collaborate
Establish relationship with external and internal Audit teams to ensure effective and robust challenge to finding and to establish smart management action plans.
Partner with 2nd LoD functions within the bank to ensure alignment towards Group wide minimum control standards
Collaborate closely and proactively with Divisional Control teams and Embedded Risk teams to manage the audit finding lifecycle
Promote and support proactive IT/IS risk culture at the Bank
Your skills and experience
8–10 years of experience in a global bank, preferably within Technology, IT/IS Audit, Risk and Controls, Vendor Risk Management, or Control Assurance.
Minimum 5 years of experience in technology risk and control, including risk framework implementation, control assessments, remediation tracking, and governance reporting.
Proven experience in managing audit remediation, risk reduction initiatives, vendor governance activities, issue closure, and stakeholder delivery in a global organisation.
Strong understanding of proactive risk management, including early identification of emerging risks, control gaps, recurring themes, and preventive mitigation actions.
Good knowledge of technology and control frameworks such as NIST, COBIT, ITIL, ISO 27001, and related industry practices.
Strong awareness of the technology risk landscape, regulatory expectations, third-party risk requirements, and operational resilience considerations.
Experience in preparing clear, accurate, and action-oriented risk reporting for governance forums and senior stakeholders.
Cloud technology knowledge or certifications across GCP, AWS, Azure, or similar domains would be advantageous.
Professional qualifications or certifications in technology risk management, audit, information security, vendor risk management, or cloud governance would be beneficial.
Proven ability to leverage AI tools to enhance productivity, optimise workflows to solve business problems, while applying critical judgment to ensure responsible and ethical use of data and AI outputs.
How we’ll support you
Training and development to help you excel in your career.
Coaching and support from experts in your team.
A culture of continuous learning to aid progression.
A range of flexible benefits that you can tailor to suit your needs.
About us and our teams
Please visit our company website for further information:
https://www.db.com/company/company.html
We strive for a culture in which we are empowered to excel together every day. This includes acting responsibly, thinking commercially, taking initiative and working collaboratively.
Together we share and celebrate the successes of our people. Together we are Deutsche Bank Group.
We welcome applications from all people and promote a positive, fair and inclusive work environment.