Internal Audit Specialist - IT
Business unit Purpose:
Internal Audit (IA) assists EKFC in accomplishing its objectives by bringing a systematic and disciplined approach to evaluate and improve the effectiveness of risk management, internal controls and governance processes and provides independent and objective assurance and advisory services to improve the operations of EKFC.
Job Purpose:
The jobholder will support the audit team to plan and conduct assurance and advisory assignments across Company using specialist skills, with the objective of providing assurance on risks controls and developing actions to mitigate identified risks.
Key Result Areas:
Job Context:
With the new Corporate ERP and HR system, workflows and other IT solutions within the organization, the requirement for an Internal Audit Specialist with IT background, skillset & expertise is critical to assess and ensure the effectiveness, security, and compliance of the organization’s systems, processes and infrastructure. Further, our technology landscape keeps evolving in most dynamic businesses and requires regular evaluation and oversight. With this, IT audits provide critical assurance over functions like change management, system configuration and segregation of duties, data integrity, compliance, risk and security assessment, business continuity and disaster recovery.
Knowledge, Skills & Minimum Experience:
Education and Qualification:
Bachelor’s degree or Honours (12+3 or equivalent) in a subject relevant to IT (e.g., Computer Science, Software Engineering).
Professional IT Audit qualification (CISA, CISM, CISSP, etc.).
Work Experience:
Minimum 5 Years of relevant experience in IT and Cybersecurity.
Experience in auditing / risk management or equivalent exposure in jobs involving review of IT systems, processes, systems and procedures, cyber security, analysis of management information, etc.
Knowledge of generally accepted auditing standards and common audit procedures and techniques.
Data Analytics Experience.
Work experience is preferred in Audit Firms, Airlines, Transportation and Logistics, Manufacturing, Retail, F&B and Hospitality.
Skills:
Expertise in Firewalls, Intrusion Detection System, Intrusion Prevention System, Routers, Switches, Servers, Databases, and Business Applications.
Hands-on experience with Nessus, Qualys, and Open-Source Vulnerability Assessment and Penetration Testing tools; strong understanding of Common Vulnerabilities and Exposures, Common Vulnerability Scoring System scoring, and exploitability assessment.
Proficiency in Computer-Assisted Audit Techniques (Tableau, PowerBI, MicroStrategy), SQL-based data mining, and Extract, Transform and Load tools like Informatica PowerCenter.
Strong grasp of Windows/Linux fundamentals, automation via PowerShell, Bash scripting, Python basics.
Knowledge of Development, Security, and Operations, Server provisioning, Containerization, and Secure Cloud Deployments.
Familiarity with ISO 31000, CIS benchmarks, NIST, UAE Information Assurance/ Information Security Regulation frameworks, and IT risk assessment methodologies.
Understanding of secure coding practices, JIRA, Azure Pipelines, and Continuous Integration and Continuous Deployment security integration.
Experience in IT Quality Management, security KPIs, and compliance reporting.