I didn't plan on IT audit. My degree was in Electronics & Telecommunications at the University of Mumbai. But my first job as a Risk Analyst at Deloitte in 2018 put me in front of real IT systems and control frameworks, and something clicked. Auditing was less about ticking boxes and more about understanding how things could break.
Four years at Deloitte and PwC in Mumbai gave me the technical foundation: ITGCs, application controls, and external audits across banks, insurers, and manufacturers. In 2021 I moved to the UK to do an MSc in Information Security at the University of Surrey (NCSC-accredited).
After graduating I joined Deloitte's UK cyber practice, working on data and digital risk projects. In late 2023 I moved in-house. That was the shift that mattered most. What in-house means, for me, is that audit findings actually land on the desks of people who act on them. That changed how I think about what a good audit looks like.
Now I write, build tools, and mentor early-career auditors, because the field needs less mystique and more people who can explain it plainly.
The work itself has spanned ITGCs and application controls, ITIL processes like change and configuration management, and cyber assessments across patching, vulnerability, and endpoint security. On the regulatory side, I've led compliance reviews against FCA, BaFin, and DORA, and worked with frameworks including ISO 27001, NIST, and COBIT. Not glamorous work, but the kind that adds up to actually understanding how IT breaks and how organisations control it.