KEY ACCOUNTABILITIES:
- Conduct and carry out technology audits covering, among others, ITGCs, ITACs, IT infrastructure, IT Security, cybersecurity, and data management processes, in line with AAIB's risk-based multiyear audit plan and risk assessment framework.
- Analyze process flow, identifying missing controls that must be in place to mitigate the associated risks and test the design and operating effectiveness of the operating automated and manual controls within Technology space including but not limited to business applications, core banking systems, and network configurations.
- Apply audit professional judgment in evaluating evidence, interpreting policies, and understanding process risks.
- Identify control weaknesses, evaluate risks, analyse root causes and recommend measures to strengthen AAIB's Technology controls posture. Identify emerging risks related to AI, cloud computing, digital banking channels, and information security.
- Assist in reviewing cybersecurity frameworks, including incident response, access controls, and penetration testing.
- Prepare detailed audit working papers and reports, summarizing audit findings, criteria, risks, root causes and recommendations, maintaining complete and accurate audit working papers in Teammate+ aligned with audit methodology and standards.
- Work closely with IT, Cybersecurity, Information Security and technology related teams to discuss audit findings and support the implementation of risk mitigation strategies.
- Keep updated on IT audit trends, regulatory expectations, and new risks associated with digital. Stay informed on emerging IT risks, technologies, and industry standards.
- Use data analytics tools (Teammate Analytics, Power BI) as needed to enhance technology audit depth and efficiency. Apply data analytics and statistical sampling using Teammate Analytics to improve audit efficiency.
- Participate in agile audit engagement requiring quick sprints, stakeholder interaction, and adaptability.
- Collaborate with business auditors in other verticals, IT teams, and data analytics team to achieve integrated assurance.
- Collaborate with Follow and Monitoring progress audit team to support the follow-up process on open technical technology audit issues, ensuring agreed-upon actions are implemented.
- Participate in the configuration as well the testing of the release updates of the Audit Management System (Teammate+) to ensure that the system is addressing the growing audit and business needs.
- Follow and implement all relevant department policies, processes, standard operating procedures and instructions so that work is carried out in a controlled and consistent manner.
QUALIFICATIONS, EXPERIENCE & SKILLS:
- Qualifications & Experience:
- Bachelor's degree in computer science, Information Technology, or related field.
- Minimum of 3 years for Auditor with relevant experience.
- Certified Information Systems Auditor (CISA) required; other certifications (e.g., CISSP, CISM, CDPSE, CIA, advanced certifications in data analytics) are advantageous.
- Proficiency in Arabic and English.
- Familiarity with IT risk frameworks, cybersecurity, and regulatory standards.
- Skills:
- Strong analytical skills.
- Effective communication.