Role Summary
The
Senior Internal Auditor – Technology is responsible for leading end-to-end IT audit engagements across General IT Controls (GITCs), Application Controls, Cloud Computing, and Cybersecurity. Reporting to the Senior Manager of Technology Audit, this role ensures technology operations, infrastructure, and systems align with global security frameworks, internal risk thresholds, and international auditing standards.
Responsibilities
Pre-Audit Planning:
- Perform engagement risk assessment and be able to draft a tailored audit program.
- Attend opening planning meetings with the Head of the Department/Section/Function under review.
- Document the work done during the understanding of the business of the Department/Section/Function under review.
- Identify sufficient, factual, reliable, relevant, and useful information to support test results.
Audit Execution:
- Conduct and execute audit assignments, tests of controls, prepare working papers, and audit reports.
- Perform testing of internal technology controls identified during the planning phase to the extent documented in the risk assessment and conclude on the internal control's effectiveness (General IT Controls, Application Controls, Process Reviews, and others).
- Document and confirm the issues raised and the management response.
- Write clear, concise, and constructive IT audit reports based on facts, severity, and risks.
- Perform analysis and resolve issues requiring a high degree of quality and precision.
Post-Audit Activities
- Participate in the drafting of the Internal Audit report.
- Participate in conducting follow-up assignments to ensure the proper implementation of corrective actions agreed upon in the report
Communication And Coordination
- Communicate audit results and observations to the Senior Manager of Technology Audit.
- Coordinate and interact with management, senior management, staff, external audit regulators, vendors, and other parties if required.
Compliance and Professional Standards:
- Achieve high professional standards of audit performance, reports, and recommendations in conformity with International Standards of Internal Audit. Requirements
- Bachelor's Degree of Computer Science, Business Information Systems, Computer Systems, Computer engineering, Industrial Engineering or any relevant degree
- Mandatory Certificate: Certified Information Systems Auditor (CISA)
- Optional Certificate:
- Certified Internal Auditor (CIA)
- COBIT5 Foundation
- ISO270001 Lead Implementer or Lead Auditor
- ITIL
- Certified Information Security Manager (CISM)
Technical Skills and Competencies Internal audit delivery
- International professional practice framework (IPPF)
- Technology Risk Assessment
- Excellent knowledge in IT Audit principles.
- Knowledge of ITIL principles.
- Knowledge of Cloud Computing principles.
- Knowledge of Cyber Security principles
- Knowledge of General IT Controls
- Knowledge of Application Controls
- Knowledge of NIST
- Knowledge of COBIT5