Audit Specialist at EaseMyTrip.com · Noida · 2 - 5 years · ₹4L - ₹7L / yr · Profitable · Posted 27 Mar 2025

Job Title: Audit Specialist
Location: Noida 63
Experience Required: 2-5 years
Employment Type: Full-Time
We are seeking a detail-oriented Audit Specialist to join our compliance team. The ideal candidate will have experience in auditing and ensuring compliance with PCI DSS, ISO 27001, ISO 9001, SOC 2, and other regulatory frameworks. You will conduct internal audits, manage compliance processes, and collaborate with teams to ensure alignment with regulations.
Key Responsibilities:
- Conduct internal audits for PCI DSS, ISO 27001, ISO 9001, and other compliance frameworks.
- Develop and implement audit plans and ensure regular assessments.
- Identify compliance gaps, document findings, and recommend corrective actions.
- Prepare detailed audit reports and track remediation progress.
- Assist with external audits and liaise with regulatory bodies.
- Provide training on compliance best practices.
Required Skills & Qualifications:
- Strong knowledge of compliance standards (PCI DSS, ISO 27001, ISO 9001, SOC 2, etc.).
- Experience in internal and external auditing, risk assessment, and compliance processes.
- Strong analytical, problem-solving, and communication skills.
- Preferred certifications: CISA, CISM, ISO 27001 Lead Auditor, CRISC (not mandatory).

About EaseMyTrip.com
About
EaseMyTrip commenced its operations in 2008 by focusing on the B2B2C (business to business to customer) distribution channel and providing travel agents access to its website to book domestic travel airline tickets in order to cater to the offline travel market in India. Subsequently, by leveraging its B2B2C channel, the company commenced operations in the B2C (business to customer) distribution channel in 2011by primarily focusing on the growing Indian middle class population's travel requirements. With our presence in the B2B2C and B2C channels, we were able to commence operations in the B2E (business to enterprise) distribution channel in 2013 with the aim of providing end-to-end travel solutions to corporates. Our presence in three distinct distribution channels provide us with a diversified customer base and wide distribution network. We believe that the strength of our brand, the quality of our services, our user-friendly websites (www.easemytrip.com and www.easemytrip.in), android and iOS based mobile applications (EaseMyTrip), our customer centric approach, as well as our efficient marketing programs have enabled us to develop significant market share in the domestic airline ticket business in India. In Fiscal 2019, GoAir, and SpiceJet, recognized us as amongst the top travel partners in terms of revenue and passenger count. The strength of our brand has increased significantly over the years. Our technology-enabled infrastructure and systems have enabled us to operate and maintain an efficient and lean organization related to the size of our operations. We have not required any equity infusion subsequent to our original incorporation requirements, and we have historically financed our working capital requirements and the expansion of our business and operations primarily through funds generated from our operations and debt financing.
Connect with the team
Similar jobs (9)
Job title Sox Compliance Officer
Reporting to Potentiam company background (The Employer) Potentiam is a global provider of highly qualified professionals to European SMEs from our offices in Romania, South Africa and India. Potentiam works with clients in finance, energy, leisure, marketing, business services and technology industries, providing technical, professional multi- lingual highly motivated staff, most of whom have had experience of working for international companies. Staff cover a wide range of roles from accounting, marketing, data management, HR, sales/account management, engineering, technology, and operations. Potentiam manages our staff’s career development and personal development training, all infrastructure, HR and payroll with our clients directly managing day-to-day staff responsibilities and role training and development. Company website - https://potentiam.co.uk/
Potentiam’s client: It is a leading provider of independent medical examinations, peer reviews, bill reviews, Medicare compliance, record retrieval, document management and related services. It provide IME services through their medical panel of credentialed physicians and allied medical professionals. Their independent medical review process is fully contained within their private cloud network. Custom portals, applications, workflow enhancements and systems integration are part and parcel of their service. Their clients include property and casualty insurance carriers, law firms, third-party claim administrators and government agencies that use independent services to confirm the veracity of claims by sick or injured individuals under automotive, disability, liability and workers' compensation insurance coverages. They help clients in the U.S., Canada, the United Kingdom and Australia manage costs and enhance their risk management processes by verifying the validity of claims, identifying fraud and providing fast, efficient and quality IME services.
Industry: legal, insurance, and healthcare services.
Purpose of role:
We are seeking a Compliance Officer to join our compliance team. This role is responsible for auditing IT control activities, ensuring adherence to Sarbanes Oxley (SOx) requirements, and maintaining governance standards. The ideal candidate will work closely with external auditors, perform Entity-Level Controls (ELCs), and document narratives, processes, and procedures in a fast paced environment. Potentiam | Job Specification 2 of 2
Duties and responsibilities: Compliance & Audit Activities • Audit IT control operations performed by IT Controls Analysts to ensure compliance with SOx requirements. • Perform walkthroughs and testing of ITGCs and ELCs to validate control design and operating effectiveness. • Develop, maintain, and update SOx narratives, process flows, and control documentation. • Coordinate and liaise with external auditors during SOx audits and provide requested evidence. • Identify control gaps and recommend remediation plans in collaboration with stakeholders. • Experience with ISO 27001 and NIST CSF, including understanding of information security controls, risk management, control assessments, compliance requirements, and security governance practices. • Familiarity with Cyber Essentials Plus (CE+) and related security/compliance requirements, along with knowledge or experience using Vanta or similar GRC/compliance management platforms, is a strong plus. Governance & Reporting • Prepare compliance reports and dashboards for management review. • Ensure timely completion of SOx testing cycles and documentation updates. • Support risk assessments and contribute to strengthening the overall control environment. Collaboration & Communication • Work closely with IT, Finance, and Compliance teams to align SOx requirements with business processes. • Act as a point of contact for external auditors and internal stakeholders. • Provide training and guidance on SOx compliance and control documentation standards.
Skills/Experience • Experience in SOx compliance, auditing, and governance processes. • Strong knowledge of Entity-Level Controls (ELCs), ITGCs, and SOx documentation standards. • Experience with ISO 27001 and NIST CSF, including security controls, risk assessment, and compliance. • Familiarity with CE+ and Vanta or similar GRC/compliance platforms is a strong plus. • Ability to create and maintain narratives, process flows, and control matrices. • Excellent communication and stakeholder management skills. • Detail-oriented with strong analytical and problem-solving capabilities. Why Join Us? • Opportunity to play a critical role in compliance and governance initiatives. • Collaborative team environment with exposure to senior leadership and external auditors. • Professional growth in a dynamic, fast-paced environment.
Additional benefits • Health Insurance • Referral Bonus • Performance Bonus • Flexible Working options
Location and hours Bangalore Office / UK hours
Read less
This role is focused on Cyber Security Risk, Governance, Risk & Compliance (GRC), IT Controls, and Security Audits, with strong emphasis on Backup, Disaster Recovery (DR), and Business Continuity (BCP).
Key responsibilities:
- Perform security control assessments against organizational policies, security standards, and regulatory requirements.
- Identify control gaps, risks, audit findings, and compliance issues, and monitor remediation until closure.
- Assess Backup, Disaster Recovery, and Business Continuity processes and controls.
- Validate backup availability, restoration/recovery procedures, DR readiness, and evidence of periodic DR/BCP testing.
- Conduct control testing and risk assessments and support internal/external security audits.
- Review security policies, procedures, standards, and governance frameworks for compliance.
- Maintain audit evidence, track findings, and coordinate with stakeholders for remediation.
- Support overall security governance, regulatory compliance, and IT risk management activities.
Required Skills
- Cyber Security Risk & Compliance / GRC
- IT Risk & Controls
- Security Control Assessment & Testing
- Security Audits
- Backup & Disaster Recovery
- BCP / DR
- Risk Assessment
- Compliance & Governance
- Security Policies & Standards
- Audit Finding & Remediation Management
IT Compliance Manager – Web3 & Digital Assets
📍 Location: Dubai, UAE
💼 Employment Type: Full-Time
🏢 Department: Technology / Compliance
📊 Experience: 5+ Years
🌐 Industry: FinTech / Web3 / Digital Assets
About the Role
We are looking for an experienced IT Compliance Manager – Web3 & Digital Assets to lead technology compliance, IT governance, risk management, and cybersecurity controls within a regulated FinTech and digital-asset environment.
The ideal candidate will have strong experience in IT GRC, technology risk, cybersecurity governance, Web3/blockchain, digital assets, and regulatory compliance, with UAE regulatory experience being highly preferred.
Key Responsibilities
- Manage IT governance, compliance frameworks, policies, procedures, and technology risk assessments.
- Support compliance with UAE virtual asset and financial-services regulations, including VARA, DFSA, FSRA, and UAE Central Bank requirements, where applicable.
- Assess technology risks across blockchain infrastructure, crypto wallets, custody, APIs, cloud platforms, databases, smart contracts, and dApps.
- Review controls related to crypto deposits, withdrawals, transfers, wallet operations, and transaction monitoring.
- Develop and monitor controls aligned with ISO 27001, SOC 2, NIST, PCI DSS, and relevant regulatory requirements.
- Coordinate IT audits, regulatory audits, compliance assessments, evidence collection, and remediation activities.
- Maintain technology risk registers, control assessments, compliance reports, and management dashboards.
- Partner with Engineering, Product, Security, Legal, Risk, AML/KYC, Finance, and Operations teams.
- Embed compliance and technology-risk requirements into product development, system changes, and technology architecture.
- Support regulatory licensing, assessments, and ongoing compliance requirements for digital-asset services.
Requirements
- Bachelor's degree in IT, Computer Science, Cybersecurity, Finance, Risk Management, or a related discipline.
- 5+ years of experience in IT Compliance, IT GRC, Technology Risk, Cybersecurity Governance, or a related field.
- Experience in FinTech, banking, payments, cryptocurrency, blockchain, digital assets, or financial services.
- Strong understanding of Web3, blockchain networks, crypto wallets, digital-asset transactions, custody, and smart-contract risks.
- Hands-on experience with IT governance, risk assessments, control testing, audits, and compliance frameworks.
- Strong knowledge of ISO 27001, SOC 2, NIST, PCI DSS, ITGC, or similar frameworks.
- Experience working with auditors, regulators, and cross-functional technology teams.
- Strong analytical, documentation, communication, and stakeholder-management skills.
UAE / Web3 Experience – Preferred
- Experience with VARA, DFSA, FSRA, UAE Central Bank, or other UAE financial regulators.
- Experience supporting VASP licensing or regulatory approvals.
- Previous experience in crypto exchanges, digital-asset platforms, blockchain companies, Web3 startups, or FinTech organizations.
- Understanding of AML/KYC, transaction monitoring, custody, wallet security, and digital-asset controls.
Preferred Certifications
- CISA
- CISM
- CISSP
- CRISC
- ISO 27001 Lead Auditor / Lead Implementer
- CAMS
Key Skills
IT GRC | IT Compliance | Technology Risk | Web3 Governance | Blockchain Risk | Digital Asset Compliance | VASP Licensing | UAE Regulatory Compliance | ITGC | Cybersecurity Governance | ISO 27001 | SOC 2 | NIST | PCI DSS | IT Audit | Risk Assessment | Crypto Transaction Monitoring | Stakeholder Management
The Security Analyst assists the Data Security team to help ensure the security of the company and its clients. Looking for immediate joiners.
KEY RESPONSIBILITIES
All employees are expected to use good business judgment and appropriate discretion and decision making while performing responsibilities of the position, and to incorporate EVA’s Core Beliefs in their daily work.
- Performs daily health checks as documented by the IT Security team.
- Supports the Security team by documenting and performing support tasks.
- Participates in change management, incident management, audit and business continuity processes.
- Plans and implements security policies and procedures to protect computer systems, networks and data from unauthorized access.
- Participates in internal and external compliance (SOC 2) audits.
- Recommends security enhancements.
Job specifics:
- Familiarity with standard security concepts, practices and procedures.
- Knowledge of Windows operating systems.
- Strong Documentation, communication skills and attention to detail.
- Able to work independently and as a part of a team to deliver completed projects on-time.
- Identifies ways to continuously improve own and/or company performance.
- Knowledge of security toolsets
- Knowledge of compliance activities (GDPR, SOC 2, ISO:27001).
- Knowledge of database security.
- Knowledge of SIEM technology and security event correlation and monitoring.
- Experience with AWS.
- Proficient with computer software including Salesforce
EDUCATION & EXPERIENCE
- Bachelor’s Degree in computer science, mathematics, Information Systems or equivalent experience preferred.
- Minimum of 3 years of hands-on IT Security & Audit experience.
- Professional IT Security Certifications are strongly preferred, such as Security+, CISSP, CISM, CISA, GSEC, etc.

We are seeking an experienced Governance, Risk & Compliance (GRC) Lead to spearhead the
design, implementation, and maintenance of our ISO 27001 Information Security Management
System (ISMS). This is a hands-on leadership role responsible for establishing a robust security
governance framework, achieving ISO 27001 certification, and embedding a culture of
continuous security improvement across the organization.
Key Responsibilities
● ISMS Implementation & Certification: Lead end-to-end ISO 27001 implementation
from gap analysis through to successful Stage 1 and Stage 2 certification audits;
manage external auditor relationships
● Risk Management: Develop and operationalize the information security risk
management framework; conduct risk assessments, treatment planning, and risk
acceptance processes.
● Policy & Governance : Author, approve, and maintain the Statement of Applicability
(SoA), information security policies, standards, and procedures aligned with ISO 27001
Annex A controls.
● Control Implementation: Translate ISO 27001 Annex A controls into operational
security measures; coordinate with IT, Accounts, HR, Backoffice, and business units to
implement and validate controls.
● Compliance Monitoring: Establish continuous monitoring, internal audit programs, and
KPIs/KRIs to measure ISMS effectiveness; manage non-conformities and corrective
actions.
● Third-Party Risk: Oversee vendor security assessments and ensure supply chain
security controls meet organizational and ISO 27001 standards.
● Stakeholder Management: Report ISMS performance, risks, and compliance status to
senior leadership and the board; act as primary liaison for external auditors and
regulators.
Required Qualifications
● 5+ years of experience in information security governance, risk, and compliance
● Proven track record of leading at least one full ISO 27001:2022 certification cycle (gap
analysis → certification)
● Deep expertise in ISO 27001:2022 standard, Annex A controls, and ISMS
documentation requirements
● Strong understanding of risk assessment methodologies (e.g., ISO 27005, NIST RMF,
OCTAVE, FAIR)
● Familiarity with internal audit practices and managing external certification bodies
● Excellent stakeholder management and ability to influence across technical and non-
technical teams
● Strong documentation and communication skills — able to translate complex standards
into actionable guidance
Preferred Qualifications
● Experience implementing ISMS in fintech, healthcare, or regulated industries
● Experience with SOC 2, GDPR, NIST CSF, PCI-DSS, or other compliance frameworks
● Background in cloud security (AWS, Azure, GCP) and DevSecOps environments
● Knowledge of automation for compliance evidence collection and control testing
● Certifications: CISM, CRISC, CISA, ISO 27001 Lead Auditor, or ISO 27001 Lead
Implementer
Why Join Us
● Opportunity to build the security governance function from the ground up
● High-visibility role with direct impact on customer trust and market differentiation
● Collaborative environment that values security as a business enabler, not a blocker
Company Profile:
We are a one-stop financial services shop, widely known for quality of its advice, personalized
service and cutting-edge technology. We started our journey in 2008. Currently we are serving
more than 50,000 investors with a team of 100 members. Our core product offering is mutual
fund, FD, Govt. Bonds, Debenture, etc.
Position: Chartered Accountant
Location: Devanahalli
Reporting to: Deputy Manager / CFO
Key Responsibilities:
Financial Reporting
o Preparation of monthly standalone and consolidated financial statements.
o Coordination with group entities for timely submission of monthly compliance requirements.
o Preparation of monthly expense variance analysis and reporting to management.
Compliance & Audit
o Addressing monthly requirements of Adani Group and other stakeholders.
o Coordinating with statutory auditors / Internal Auditors for quarterly closures and ensuring timely completion.
o Performing quarterly 26AS reconciliation with books of accounts.
Fixed Assets & Banking
o Managing and reviewing the consolidated fixed assets register, including monthly computation and reconciliation.
o Handling monthly banking requirements related to company financiers and ensuring smooth liaison with banks.
General Responsibilities
o Supporting management in ad-hoc requirements related to finance, accounting, and compliance.
o Assisting in process improvements, system enhancements, and strengthening internal controls.
Hi Folks, we are currently Hiring for Security Engineer.
Gemini said
Hiring: Security Engineer
Company : Pentabay Softwares
Location : Anna salai, Mount Road
Mode: Fulltime
Pentabay Softwares INC is looking for a proactive Security Engineer (2–7 Years Exp) to fortify our global digital solutions. As we scale our footprint in the Healthcare IT sector, you will play a critical role in safeguarding sensitive data (ePHI) and ensuring our cloud-native architectures are resilient against evolving threats.
The Mission
You will be the architect of our defense, bridging the gap between high-speed development and rigorous security standards. Your day-to-day will involve "shifting security left" by embedding DevSecOps practices into our CI/CD pipelines and leading our compliance efforts for SOC 2, ISO 27001, and HIPAA.
Key Responsibilities
Defense & Architecture: Design and maintain secure cloud (AWS/Azure/GCP) and on-prem environments. Implement IAM policies, Zero Trust frameworks, and robust secrets management.
Offensive Testing: Conduct regular vulnerability assessments (VAPT), penetration testing, and code reviews using tools like Burp Suite and Nessus.
DevSecOps & Automation: Integrate SAST/DAST/SCA scanning into engineering workflows. Automate security tasks using Python or Bash.
Incident Response: Monitor SIEM tools (Splunk/CrowdStrike), respond to threats, and develop risk mitigation strategies.
Healthcare Compliance (Plus): Ensure data integrity for HL7/FHIR APIs and maintain HIPAA/HITECH audit readiness for healthcare clients.
What You Bring
Experience: 2–7 years in Information/Application Security with a strong grasp of the OWASP Top 10 and threat modeling (STRIDE).
Technical Depth: Proficiency in network/endpoint security, PKI, encryption standards (TLS/SSL), and container security (Docker/Kubernetes).
Compliance Knowledge: Familiarity with NIST, GDPR, and SOC 2 frameworks.
Tools: Hands-on experience with Metasploit, Wireshark, and Infrastructure-as-Code (Terraform).
Bonus Points: Industry certifications like OSCP, CISSP, or CEH, and experience in Healthcare IT workflows.
Auditing space like ISO27001 , ISO9001 prefered
Why Pentabay?
At Pentabay, we offer more than just a job; we offer a security-first engineering culture.
Growth: A dedicated learning budget for certifications and conferences.
Impact: Work on cutting-edge Healthcare projects that demand the highest levels of data privacy.
Send resumes to : sandhiya.m at pentabay.com
DevOps & Cloud Security Specialist to architect enterprise-grade AWS networking, implement strict IAM security boundaries (HIPAA/GDPR compliance), automate infrastructure via IaC, and maintain crystal-clear technical documentation.
1. Primary Must-Have Competencies (Core Priorities)
A. AWS Networking & VPC Topology (Top Priority)
- Advanced VPC Architecture: Mastery in designing multi-VPC topologies, isolated subnets, custom Route Tables, NAT Gateways, Transit Gateways, and Cross-Region VPC Peering.
- Private Network Security: Extensive experience using VPC Endpoints (Gateway & Interface/PrivateLink) to keep internal AWS traffic completely off the public internet.
- Traffic Ingestion & Edge Security: Expertise in AWS WAF (custom rules, bot control, rate limiting), API Gateway throttling, ALB configuration, and Route 53 global routing.
B. AWS Security, IAM Architecture & Compliance
- Enterprise IAM Governance: Expertise in AWS Organizations, IAM Identity Center (SSO), Permission Boundaries, Service Control Policies (SCPs), and temporary role assumption across multi-account setups.
- Data Protection & Key Management: Deep knowledge of AWS KMS (customer-managed keys, envelope encryption at rest and in transit) and AWS Secrets Manager.
- Audit & Compliance: Setting up centralized logging pipelines (CloudTrail, GuardDuty, AWS Config, CloudWatch Audit Logs) for strict HIPAA/GDPR compliance.
C. Infrastructure as Code (IaC) & Containerization
- Terraform / AWS CDK: Must write production-grade, modular IaC templates from scratch—enforcing network topology and security guardrails directly in code.
- Container Orchestration: Hands-on setup and management of AWS ECS (Fargate) or EKS (Kubernetes) and automated CI/CD pipelines (GitHub Actions, GitLab CI).
D. Architecture Documentation & Systems Mapping
- Technical Documentation: Ability to author clean, standardized architecture diagrams (e.g., C4 model, Draw.io, Lucidchart) and maintain comprehensive runbooks, incident response plans, and compliance documentation.
2. Secondary Competency (Strong Advantage, Not Mandatory)
- Backend Software Development: Hands-on experience or a background in writing/debugging backend code in Node.js, Python, or Go.
- Note: The primary responsibility is cloud infrastructure, security, and automation. However, the ability to read backend code, debug API bottlenecks, or assist developers with microservice integrations is a major bonus.
Manage day-to-day accounting operations and end-to-end payroll processing, and ensure timely, accurate compliance with government statutory requirements, supporting the organisation's financial reporting, audit readiness and regulatory standing.





