HirePortal

Senior IT Pillar Specialist

  • McDermott
  • Gurugram, India
  • INR 2,500,000 – INR 4,000,000

Job Overview:

The Senior IT Pillar Specialist – Applications Controls and Compliance is a hands-on compliance professional supporting the organization's SOX compliance program, ISO certification, IT audits and maintaining an effective IT control environment.

The primary objective is to focus on current applications architecture and ensure future applications are compliant to McDermott’s standards.

This role works hand in hand with IT, cybersecurity, finance, business process owners, Internal Audit, and external auditors to document controls, perform walkthroughs, validate evidence, execute control testing, support audits, and suggest process improvements. The position requires strong communication skills, attention to detail, analytical capabilities, and the ability to build productive working relationships across technical and non-technical teams.

The successful candidate will help ensure IT controls are consistently executed, properly documented, supported by appropriate evidence, and maintained in a manner that supports external audit requirements and overall audit readiness.

  • Key Tasks and Responsibilities:

  • Maintain and continuously improve SOX IT General Controls (ITGCs), IT Application Controls (ITACs), and IT-Dependent Manual Controls (ITDMs) supporting financial reporting.

  • Develop and maintain audit-ready documentation including narratives, process flows, risk and control matrices (RACMs), control procedures, evidence requirements, and testing support materials for Business Applications .

  • Coordinate and perform process walkthroughs with control owners, technology teams and process owners to validate control execution and identify control gaps.

  • Evaluate control design and operating effectiveness across:

    • Access Management
    • Change Management
    • System Development Lifecycle (SDLC)
    • Disaster Recovery Definition for Critical applications
    • Definition and implementation Segregation of Duties (SoD)
    • IT-Dependent Manual Controls (ITDMs)
    • Management Review/Certification Controls
  • Assess completeness and accuracy of reports, system-generated data, and evidence used to support key controls.

  • Support annual SOX testing, management assessments, and external audit activities.

  • Assist control owners in addressing deficiencies and strengthening control execution.

  • Conduct interviews and walkthroughs with, business stakeholdersPerform testing of controls, evaluate supporting evidence, document results, and communicate findings.

  • Develop practical recommendations that improve controls while minimizing unnecessary operational burden.

  • Track audit findings and remediation activities through resolution.

  • Analyze large data sets with the use of AI tools to support audits, control testing, and risk assessments.

  • Perform user access reviews, role analysis, segregation of duties assessments, exception analysis, sampling, reconciliations, and trend analysis.

  • Validate system populations and report completeness and accuracy used for SOX testing.

  • Identify anomalies, outliers, control failures, and compliance concerns through data analysis.

  • Partner with IT and business stakeholders to improve control processes, documentation quality, and audit readiness.

  • Recommend opportunities to simplify, standardize, and mature governance and compliance activities.

  • Support compliance initiatives aligned with SOX and ISO 27001 requirements.

  • Participate in reviews of third-party assurance reports (SOC reports) and technology risk assessments as assigned.

  • Build working relationships with IT, cybersecurity, finance, Internal Audit, external auditors, and control owners.

  • Translate technical risks, control issues, and audit findings into clear business language.

  • Influence positive change through collaboration, credibility, and strong communication rather than formal authority.

  • Essential Qualifications and Education:

  • 8+ years of direct-full-time experience in IT audit, SOX compliance, IT controls, cybersecurity governance, internal controls or Technology compliance programs

  • Bachelor’s degree in Information Systems/ IT/ Cybersecurity/ Computer Science or a related field

  • Experience Pathway: Equivalent direct, full-time, hands-on experience specialized in SOX and IT audits in lieu of a degree

    • Demonstrated experience performing 5 of the following:
      • ITGC testing
      • ITAC testing
      • ITDM testing
      • Management Review Control assessments
      • Risk assessments
      • Audit execution
      • Control effectiveness reviews
      • Deficiency remediation support
    • Strong understanding of:
      • SOX 404
      • Internal Control over Financial Reporting (ICFR)
      • IT General Controls
      • Identity & Access Management
      • Change Management
      • ERP and Financial Reporting Systems
      • Cybersecurity Controls
  • Advanced Microsoft Excel skills including pivot tables, reconciliations, data analysis, exception reporting, and audit sampling or experience using AI tools.

  • Excellent written, verbal, facilitation, interviewing, and relationship management skills.

  • Ability to work independently while managing multiple concurrent audits, reviews, and compliance initiatives.

Preferred Qualifications and Education:

  • CISA and ITIL certification are preferred.
  • Additional certifications such as CISSP, CRISC, CIA, CISM, CGRC are desirable.
  • Experience supporting SOX readiness, IPO readiness, or public-company compliance programs.
  • Experience with large-scale ERP environments.
  • Experience with ServiceNow, AuditBoard, Oracle Fusion ERP, JDE , Azure, Saviynt, or similar enterprise platforms.
  • Experience working within engineering, construction, energy, EPC, manufacturing, or industrial environments.
  • Experience supporting global technology organizations across multiple geographic regions and third-party service providers.
  • US visa would be a good to have.

Skills

  • SOX Compliance
  • IT General Controls (ITGC)
  • IT Application Controls (ITAC)
  • IT audit
  • Risk and Control Matrix (RACM)
  • Control Testing
  • Stakeholder Communication

Related jobs

McDermottApply for this job