Role snapshot
An on-site Associate IT Auditor position is open in Madhapur, HITEC City, Hyderabad, working within a cybersecurity team that reviews internal controls across the company's technology systems. The role reports to the audit function rather than to security operations, though the two groups sit close enough to collaborate most weeks.
Pay for this seat goes up to ₹62,000 per month, which aligns with other IT auditor salary figures in Hyderabad for an associate-level opening. It's a full-time position, not a contract or project-based engagement.
The audit team here is small, four people including the audit lead, and everyone works across the full range of systems rather than owning a single narrow area. That means this hire will end up looking at everything from access management on the finance systems to patch cadence on internal servers within the first few months, not just one slice of the environment. The rotation is informal rather than scheduled, so it depends more on the current audit calendar than on any fixed assignment plan.
What the job involves
- Review systems and applications for vulnerabilities as part of scheduled and ad hoc audits
- Evaluate whether existing security controls are actually working the way policy says they should
- Support the incident response team when an audit finding overlaps with an active issue
- Document findings clearly enough that a non-technical stakeholder can act on them without a follow-up meeting
- Recommend fixes and track them until they're closed, not just logged and forgotten
Requirements
The baseline ask is a bachelor's degree, usually in cybersecurity or IT, though a general computer science background works fine too. One year of relevant experience is expected, ideally in a role that involved audits, compliance work, or hands-on security monitoring rather than a purely academic project. Internship time counts toward that year if it involved real client or internal audit work rather than shadowing. Naukri Mitra occasionally sees fresh graduates apply here straight out of a security certification course, and a few have gotten through when their coursework included genuine audit documentation rather than theory alone.
Beyond the degree and the year of experience, what matters most is whether someone can sit with a messy system, work out where the real risk sits, and write it up so someone else can follow the logic on the first read. A finding that says "access controls are weak" isn't useful to anyone. One that names the specific accounts still active from a contractor who left six months ago is the kind of detail this role actually needs, and it's the difference between a report that gets filed away and one that gets acted on the same week.
- Risk assessment across IT systems and processes
- Familiarity with compliance frameworks relevant to the industry
- Audit documentation that holds up under review
- Attention to detail when reconciling controls against what's actually implemented
Nice to have
None of this is mandatory, but each item on this list tends to shorten the ramp-up in a specific way.
- Exposure to ISO 27001 or SOC 2 audit cycles
- Hands-on time with vulnerability scanners such as Nessus or Qualys, since it makes conversations with the security team go faster
- A CISA track, even partway through; the company reimburses the exam fee once someone clears it
- Comfort with Excel for control testing and evidence tracking, which matters more day-to-day than most candidates expect
- Prior exposure to a GRC platform, whatever the vendor, since most of the learning curve here is about the tooling rather than the underlying audit concepts
Where this can go
This is an associate-level opening. The usual path from here is toward a senior auditor role after roughly two to three years, assuming the audit cycles continue to go well and the person wants to stay in audit rather than move sideways into security operations.
A couple of people from this team have made that sideways move, usually after picking up enough hands-on security work through incident response support to make the case for it. Neither path gets pushed on anyone. The audit lead has said more than once that a good auditor who stays an auditor is worth more to the team than someone rushed into a title change before they're ready.
Benefits
- Health insurance
- Paid time off
- Provident fund contributions
- On-site cafeteria at the Madhapur office
- Cab or commute support
These apply from day one rather than after a probation period, which comes up often enough in interviews that it's worth stating here directly.
Location and schedule
This is a full-time, on-site role based in Madhapur, HITEC City, Hyderabad, Telangana, with no remote or hybrid option for this opening. Audit cycles tend to run in bursts tied to quarter close and external audit windows, so the workload isn't evenly distributed throughout the month. A given week in March might mean long days pulling evidence for an external auditor, while a week in May could be closer to routine control checks and documentation cleanup. The office itself is a shared floor with two other teams from the same company, and desks aren't assigned, so most people settle into the same general area out of habit rather than any formal seating plan.
Applying
Send a resume and, if you have one, a short writing sample such as an audit finding or risk summary you've drafted before, even from a course or internship. The hiring team reviews applications on a rolling basis rather than waiting for a fixed cutoff, so earlier applications tend to get a faster first response. A short screening call comes first. That's followed by a technical conversation about how you'd approach evaluating a specific control, and then a final conversation with the audit lead about fit and expectations on both sides. Most candidates go through all three stages within about two weeks, though it can stretch longer around quarter-end when the team's own audit deadlines take priority over interviews. There's no separate written test beyond the writing sample already mentioned.