- Location
- Bangalore, Velankani Tech Park, India · Pune - Business Bay
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Finance
- Seniority
- VP
- Source
- Workday
Description
Job Description:
Job Title- Assurance Team Specialist – Audit and Risk Management
Corporate Title- Assistant Vice President
Location- Bangalore, India
Role Description
- The Assurance Team Specialist – Audit and Risk Management supports the delivery of audit, technology risk, vendor risk management, governance, and risk reporting activities for the Hybrid Cloud Infrastructure division. The role coordinates assigned risk reduction and audit remediation initiatives, monitors the timely closure of audit findings and risk actions, supports a strong control environment, and prepares clear reporting for management and governance forums. Effective project coordination, stakeholder engagement, attention to detail, and sound technology risk knowledge are key success factors. The role also contributes to proactive risk management by identifying emerging risks and control weaknesses, coordinating mitigation actions, and escalating material issues or delays to the appropriate accountable owner.
What we’ll offer you
As part of our flexible scheme, here are just some of the benefits that you’ll enjoy
- Best in class leave policy
- Gender neutral parental leaves
- 100% reimbursement under childcare assistance benefit (gender neutral)
- Sponsorship for Industry relevant certifications and education
- Employee Assistance Program for you and your family members
- Comprehensive Hospitalization Insurance for you and your dependents
- Accident and Term life Insurance
- Complementary Health screening for 35 yrs. and above
Your key responsibilities
- Support audit, risk, vendor risk management, governance, and risk reporting activities for HCI in line with GTI priorities, internal frameworks, and regulatory expectations.
- Coordinate assigned activities across the audit finding lifecycle, including challenge support, management action planning, remediation tracking, evidence collation, validation support, and closure readiness.
- Identify emerging risks, control weaknesses, recurring themes, and dependencies, and work with accountable owners to define and track preventive actions.
- Maintain accurate risk and issue records for HCI through timely assessment, monitoring, reporting, and follow-up of mitigation actions.
- Analyse and prioritise assigned remediation actions, including cross-divisional dependencies and control improvement activities, and escalate material constraints.
- Track remediation progress, overdue actions, and closure readiness, ensuring supporting documentation is complete, evidence-based, and audit-ready.
- Coordinate vendor risk management activities, including risk assessments, recertifications, control reviews, issue management, subcontractor oversight, and regulatory obligations.·
- Prepare materials and provide updates for governance forums on risks, audit findings, vendor issues, remediation status, and emerging themes.
- Escalate risks, delays, control gaps, and dependencies promptly, and follow agreed decisions and actions through to completion.
- Work with Audit, Second Line of Defence, Divisional Control, Embedded Risk, Service Owners, and Technology teams to improve control effectiveness and remediation outcomes.
- Produce timely, accurate, and action-oriented risk reporting for management and governance stakeholders, highlighting risk posture, remediation progress, overdue items, and required decisions.
- Promote a proactive IT/IS risk culture through early issue identification, transparent escalation, disciplined evidence management, and sustainable control improvement.
Service Owner
- Risk Assessment and Management: Coordinate risk assessments, confirm required screening and evidence are completed, track third-party issues, and escalate material exceptions to the accountable Service Owner.
- Regulatory Compliance: Support Local Service Owner nominations and monitor completion of applicable local regulatory and policy requirements.
- Third-Party Selection and Screening: Support due diligence and selection activities by reviewing risk inputs, screening outputs, and required approvals with relevant stakeholders.
- Control Assessments and Mitigation: Coordinate completion of third-party control tasks, continuity requirements, and mitigation actions, and maintain evidence of progress and closure.
- Continuous Monitoring and Termination: Support periodic risk assessment updates, post-go-live control monitoring, issue follow-up, and execution of approved termination or exit activities.
- Contracting and Payment: Track completion of required risk activities before service commencement and support confirmation that relevant contractual clauses, renewals, and amendments follow the applicable third-party risk process.
Stakeholder Management – Identify, Partner, and Collaborate
- Build effective working relationships with internal and external Audit teams, coordinate responses to challenge, and support the development of clear, achievable management action plans.
- Partner with Second Line of Defence functions to understand requirements and support alignment with Group-wide minimum control standards.
- Collaborate proactively with Divisional Control, Embedded Risk, Service Owners, Technology teams, and remediation owners to progress audit and risk actions.
- Communicate risk, issue, and remediation status clearly; challenge constructively; and escalate material concerns, dependencies, or missed commitments in a timely manner.
- Contribute to a proactive IT/IS risk culture by sharing lessons learned, promoting control ownership, and supporting consistent governance practices.
Your skills and experience
- Typically 6–8 years of relevant experience in a global bank, financial services organisation, or comparably regulated environment, preferably within Technology, IT/IS Audit, Risk and Controls, Vendor Risk Management, or Control Assurance.
- Practical experience in technology risk and controls, including risk assessments, control testing or assurance, remediation tracking, evidence management, and governance reporting.
- Demonstrated experience coordinating audit remediation, risk reduction initiatives, vendor governance activities, issue closure, or related control improvement work.
- Ability to identify emerging risks, control gaps, recurring themes, and dependencies, and translate analysis into practical mitigation and escalation actions.
- Working knowledge of technology and control frameworks such as NIST, COBIT, ITIL, ISO 27001, and relevant industry practices.
- Awareness of technology risk, regulatory expectations, third-party risk requirements, and operational resilience considerations within a regulated organisation.
- Strong analytical, organisational, and written communication skills, with the ability to prepare concise, accurate, and action-oriented materials for management and governance forums.
- Confidence in working across multiple stakeholder groups, constructively challenging information, managing competing priorities, and escalating material issues appropriately.
- Knowledge of cloud technologies across GCP, AWS, Azure, or similar domains would be advantageous.
- Professional qualifications or certifications in technology risk management, audit, information security, vendor risk management, or cloud governance would be beneficial.
Proven ability to leverage AI tools to enhance productivity, optimise workflows to solve business problems, while applying critical judgment to ensure responsible and ethical use of data and AI outputs.
How we’ll support you
- Training and development to help you excel in your career
- Coaching and support from experts in your team
- A culture of continuous learning to aid progression
- A range of flexible benefits that you can tailor to suit your needs
About us and our teams
Please visit our company website for further information:
https://www.db.com/company/company.html
We strive for a culture in which we are empowered to excel together every day. This includes acting responsibly, thinking commercially, taking initiative and working collaboratively.
Together we share and celebrate the successes of our people. Together we are Deutsche Bank Group.
We welcome applications from all people and promote a positive, fair and inclusive work environment.