Website:
sarc.global
Job details:
About SARC Global
SARC Global is a multidisciplinary advisory firm with over 40 years of experience, 100+ partners, 500+ professionals, and a presence across India, the UK, USA, Singapore, and UAE. Our cybersecurity and data governance practice serves large, regulated enterprises across banking, financial services, manufacturing, energy, and the public sector, with an operating model that spans consulting, assessment, and audit through to solution implementation and managed services.
The Role
SARC is seeking a Consultant to join its cybersecurity and GRC practice, executing IT controls, risk, governance, and compliance assessments for enterprise clients. This is a hands-on delivery role. You will work as part of an engagement team, under the direction of a senior lead, performing controls testing, governance and compliance review, technical security assessment coordination, and on-site operational technology walkdowns producing audit-grade documentation throughout.
The role suits a consultant who has spent three to six years in IT audit, GRC, or security assessment — ideally within a Big 4, consulting firm, internal audit function, or specialist security firm — and who wants to work across the full breadth of a modern assessment, from ITGC and regulatory compliance through to cloud posture and OT security.
What You'll Do
IT General Controls (ITGC)
- Test IT general controls across SAP S/4HANA and core financial applications — covering access to programs and data, change management, SDLC discipline, and computer operations.
- Perform controls testing aligned to COBIT 2019 and ICFR requirements, to audit-grade evidence standards.
- Design and document test procedures, gather and evaluate evidence, identify control gaps and deficiencies, and articulate findings with clear risk ratings and remediation guidance.
- Prepare working papers, control matrices, and testing documentation that withstand review by internal audit, external auditors, and audit committees.
Governance, Risk & Compliance (GRC)
- Assess policy and governance architecture, cyber risk management processes, and Risk Management Committee (RMC) reporting readiness.
- Evaluate regulatory compliance posture across the DPDP Act 2023, CERT-In directions, and SEBI LODR requirements.
- Review third-party and vendor risk management practices.
- Support the assessment of the client's ISO 27001 certification scope and the path to extend certification beyond currently certified sites.
Enterprise IT & Cloud Security
- Support review of data centre and disaster recovery environments.
- Coordinate and support VAPT and defined-scenario Breach & Attack Simulation activities across network, application, data, and identity layers, working with technical testers.
- Assess the maturity of Vulnerability Management and Incident Detection & Response capabilities.
- Review security posture across AWS, SAP, and Microsoft 365 environments.
Operational Technology (OT) — Plant Walkdowns
- Conduct on-site walkdowns at manufacturing plants — validating PLC, SCADA, and DCS inventory.
- Assess IT-OT segmentation against IEC 62443 zone-and-conduit principles.
- Review vendor and integrator remote access, and OT patching and recovery practices.
- Perform all OT assessment work on a strictly passive, read-only basis, with zero production impact.
Across All Workstreams
- Produce clear, structured, audit-grade documentation and contribute to client-ready assessment reports.
- Map findings to applicable frameworks and regulatory requirements.
- Manage your own workstreams to deadline, and communicate progress and issues to the engagement lead.
Who You Are
- 3-6 years of experience in IT audit, IT risk, GRC, or security assessment — within a Big 4, consulting firm, internal audit function, GRC practice, or specialist cybersecurity firm.
- Hands-on ITGC testing experience — you have independently tested access, change management, SDLC, and IT operations controls, and you understand what audit-grade evidence looks like.
- Working knowledge of ERP control environments, ideally SAP S/4HANA, and an understanding of application controls in a financial reporting context (ICFR).
- Familiarity with control and governance frameworks — COBIT 2019, ISO 27001, NIST CSF, and ITGC/ICFR concepts.
- Awareness of the Indian regulatory landscape — DPDP Act 2023, CERT-In directions, and SEBI LODR — and how they translate into assessment criteria.
- Exposure to technical security assessment — you understand VAPT and vulnerability management concepts well enough to scope and coordinate them, even if you are not the hands-on tester.
- Strong documentation and analytical skills — you write clearly, structure evidence logically, and produce work that stands up to audit committee-level scrutiny.
- Willingness to travel for on-site plant walkdowns and client work.
- Professional, discreet, and detail-oriented — comfortable working in sensitive client environments and handling confidential information with care.
Preferred Certifications (one or more valued, none mandatory)
CISA | ISO 27001 Lead Auditor | CRISC | CISSP | CEH | COBIT 2019 | cloud security certifications (AWS/Azure/M365)
What Sets You Apart
- Experience delivering ITGC or ICFR engagements in a SAP S/4HANA environment.
- Exposure to OT/ICS security assessment or familiarity with IEC 62443.
- Experience with cloud security posture assessment across AWS, SAP, and M365.
- Prior Big 4 or established consulting firm background with strong working-paper discipline.
- Experience across both IT and OT environments in a manufacturing or industrial context.
Location: New Delhi (Okhla Phase 1), with travel/deployment to client sites across India.
Joining: Immediate
Click on Apply to know more.