- Posted a month ago
- Be among the first 10 applicants
Job Description
Established in 2004, Dubai Holding is a global investment company with investments in more than 34 countries and a combined workforce of nearly 45,000 individuals. In line with the vision of Dubai's leadership and economic diversification strategy, Dubai Holding companies have nurtured sectors, irrevocably transforming Dubai's socio-economic landscape and positioning Dubai as a diversified, globally integrated economy.
Dubai Holding is committed to the diversification of Dubai's non-oil economy. Our portfolio, valued at over AED 280+ billion, spans 10 sectors, including real estate, hospitality, leisure & entertainment, ICT, design, education, media, retail, manufacturing & logistics, and science.
For the Good of Tomorrow
Dubai Holding is currently seeking a Manager - Internal Audit, Information Technology, reporting to the Associate Director - Technology Audit. You will be responsible for providing independent and objective assurance over the effectiveness of technology-related governance, risk management, and internal control frameworks across Dubai Holding. The role focuses on evaluating IT systems, infrastructure, cybersecurity, and technology-enabled business processes to ensure that risks are appropriately identified, managed, and mitigated.
The role supports the execution of the Group's risk-based Internal Audit plan in line with the Group-wide Audit Manual and the International Standards for the Professional Practice of Internal Auditing, while delivering clear, practical, and value-adding insights to management and key stakeholders.
Key Accountabilities
IT Audit Planning & Risk Assessment
- Contribute to the enterprise-wide IT risk assessment to identify key technology and cyber risk exposures across the Group.
- Support the development and maintenance of the risk-based Technology Audit plan, ensuring alignment with enterprise risk priorities and emerging technology risks.
- Perform preliminary risk analysis and scoping for audit engagements, including understanding business context, technology architecture, and key control environments.
Technology Audit Execution
- Plan and execute IT audit engagements in accordance with approved audit plans, covering areas such as IT governance and management practices, information security and cybersecurity controls, application and infrastructure controls, and technology-enabled business processes.
- Evaluate the design and operating effectiveness of IT general controls (ITGCs), automated application controls, and supporting manual controls.
- Identify control deficiencies, root causes, and risk implications, applying sound professional judgement and internal audit methodologies.
Reporting & Issue Management
- Prepare clear, concise, and well-evidenced audit reports that articulate findings, risks, and practical recommendations.
- Engage constructively with management to agree appropriate, risk-responsive corrective action plans.
- Track and follow up on the implementation of agreed audit actions, escalating overdue or high-risk issues in accordance with Internal Audit protocols.
Stakeholder Engagement & Advisory
- Build effective working relationships with technology and business stakeholders to facilitate efficient audit delivery and constructive outcomes.
- Act as a trusted Internal Audit partner by providing insight on technology risks, control design, and good practice, without assuming management responsibility.
- Support Internal Audit leadership in responding to ad-hoc requests, regulatory reviews, and coordination with external audit or assurance providers.
Continuous Improvement & Professional Development
- Stay current on emerging technology risks, cybersecurity trends, regulatory developments, and industry best practices relevant to IT auditing.
- Contribute to the continuous improvement of Internal Audit methodologies, tools, and templates related to technology and cyber assurance.
- Share knowledge and insights within the Internal Audit function to strengthen overall capability.
Who We Are Looking For
- 6–8 years of progressive experience in IT audit, technology risk, or information security assurance.
- Experience in a Big 4 firm or large internal audit function within a complex, multi-entity organisation is preferred.
- Experience of working in an international capacity and a solid understanding of cultural and market differences (especially those of the Middle East and Asia).
Education/ Professional Certification
- Bachelor's degree in Information Technology, Computer Science, Information Systems, or a related field.
- Professional certifications: CISA (required); CISM, CRISC, CIA, or ISO 27001 Lead Auditor (advantageous).
Technical Competencies
- Technology audit delivery, including planning, fieldwork and reporting (IIA Standards and Internal Audit methodology).
- IT governance, risk and control assessment (ITGCs and application controls; COBIT).
- Information security and cyber assurance (secure architecture, security testing; ISO 27001 / NIST CSF).
- Cloud and enterprise platforms exposure (cloud administration; ERP environments).
- Audit analytics and clear technical writing (data analysis, documentation, stakeholder-ready reporting).
- Audit management software proficiency (e.g., TeamMate+, AuditBoard, or equivalent) for planning, workpapers, reporting and issue tracking.
- Project management and Agile ways of working awareness (e.g., SDLC delivery models, change management and governance).
- Practical data analysis skills to support audit scoping and testing (e.g., Excel, SQL basics, and/or BI tools).
- Awareness of UAE regulatory requirements impacting technology and information security (e.g., NESA, data protection).
Behavioural Competencies
- Strong analytical and critical thinking skills
- Clear and structured written and verbal communication
- Professional integrity and objectivity
- Ability to manage multiple engagements and competing priorities
- Collaborative and relationship-oriented approach
As much as we would be delighted to entertain all applicants, due to high volumes of applications only successful applicants will be contacted within 14 business days.
This job description is not all inclusive. Dubai Holding reserves the right to amend this job description at any time. Dubai Holding is an Equal Opportunity Employer, committed to a diverse and inclusive work environment.
More Info
Key Skills
risk assessments
forecasting data models
data analytics tools
Audit Management software
IT systems
cyber security principles
UAE Personal Data Protection Law
Git branching
