IDT Assurance Advisor
Shell · Bangalore RMZ-ECO WORLD
Shell · Bangalore RMZ-ECO WORLD
, IndiaJob Family Group: Information Technology (IT)Worker Type: RegularPosting Start Date: August 3, 2026Business Unit: Experience Level: Experienced ProfessionalsJob Description: Where You Fit In? • As the energy industry transitions to cleaner forms of energy, Shell is actively leveraging technology across its business. This exposes us to risk in Information security and regulatory requirements that come along with it. • IDT Assurance Advisors play a vital role in ensuring compliance with IRM policies and standards. • This role involves managing operational responsibilities related to IT controls, delivering assurance services, leading improvement projects, and championing risk management initiatives. • Effective collaboration with stakeholders, managing impact from Shell-wide projects, and staying informed about internal policies and external risks are key challenges. If you are interested in Information Risk Management (IRM) and desire to sit into the driver’s seat where we provide assurance to the organization on the risks we carry in IT world, Enterprise Assurance Services (EAS) is the team you would want to be in. Join our EAS team, where it is a great opportunity for those looking to develop IT Risk review/audit skills. What is the Role? As an IDT Assurance Advisor, you play a key role in strengthening the organization's IT risk and control environment through independent assurance, risk oversight, and control testing activities. You will conduct comprehensive risk management reviews, identify gaps, and meticulously track remediation progress, assess the design and operating effectiveness of IT controls, identify and report control weaknesses, and provide strategic guidance to stakeholders on risk management and governance practices. Your key responsibilities include: • Risk Oversight & Assurance Planning: Lead IT assurance reviews across infrastructure, applications, and cybersecurity domains, ensuring alignment with enterprise risk management objectives. • Quality Review: Review ITGC and ITC testing for quality, completeness, and correctness of outcome. • ITGC Testing: Conduct testing of IT General Controls (ITGCs) and ITAC to ensure compliance and effectiveness. • Test Scripts: Developing and executing test scripts, documenting test procedures, and evaluating results to identify control gaps. • Reporting: Ensure adherence to the approved assurance plan and provide regular updates on progress. • Issue Management: Review quality of remediation and documentation of the same before issue closure. • Process & Policy Governance: Oversee the evaluation of IT processes, policies, and standards to ensure compliance with regulatory requirements and industry frameworks (e.g., ISO 27001, NIST, COBIT). • Strategic Advisory: Provide expert guidance to first line of defense on risk mitigation strategies, control enhancements, and remediation planning for identified gaps. • Stakeholder Engagement: Collaborate with first line of defense and business focal points to promote a strong risk-aware culture and ensure effective governance practices. • ESSA Leadership: Drive Eliminate, Simplify, Standardize, Automate (ESSA) initiatives within assurance services, ensuring timely reporting and continuous improvement. • Oversight of Tools and Reports: Oversee the accuracy and relevance of tools and reports used by the team and stakeholders, making updates based on evolving business needs. This role demands a strong expertise in IT security and risk management, with a focus on proactive risk management and continuous improvement. What We Need from You?Experience: • IT Audit Expertise: 5-8 significant experience in IT audits or ITGC testing or conducting risk reviews. Education: • Academic Background: Bachelor’s degree in technology is highly desirable. • Certifications: Preferred certifications include those in IT security and Risk Management. Technical Skills: • IT Audit and Risk Management: Good knowledge of IT audit processes, risk management, and control testing. • Security Standards: Familiarity with internal and external IT security standards such as ISO 27001 and COBIT. • Certifications: Relevant certifications like ISO 27001, CISA, CISM, CRISC are desired. • Information Risk Management: Strong understanding of information risk management and associated processes. • Application Proficiency: Experience with widely used applications such as SAP, Power Platform, and Cloud technologies is desirable. • Continuous Improvement: A mindset geared towards continuous improvement and project management experience. Soft Skills: • Leadership: Demonstrated ability to deliver through others, is essential. • Team Collaboration: Highly motivated team player who volunteers, supports, and collaborates effectively. • Proactive Problem-Solving: Skilled in identifying potential challenges and proposing effective solutions. • Learner Mindset: Demonstrates professional curiosity and a strong desire to learn. • Prioritization: Capable of managing multiple tasks simultaneously with strong prioritization skills. • Interpersonal Communication: Strong communication skills, with the ability to build strong relationships with stakeh