Senior IT Auditor - Technology Assurance Job Snapshot Role: Senior IT Auditor - Technology Assurance Location: Abu Dhabi Emirate, United Arab Emirates Industry: Oil & Energy Function: Accounting / Auditing Experience: Minimum 8 years Job Type: Full-time
Job Details Country: United Arab Emirates City: Abu Dhabi Emirate Industry: Oil & Energy Function: Accounting / Auditing Salary: 25000-38000 Estimated salary range based on similar jobs in the job city; please confirm the final offer with the employer. Gender: Any Candidate Nationality: Any Job Type: Full-time
Role Context
The Senior IT Auditor provides independent assurance over technology environments supporting complex corporate and energy operations. Combining technical IT knowledge with professional auditing practices, the position evaluates whether systems, infrastructure, access controls, technology changes and governance processes adequately manage organizational risks. The role also strengthens audit planning, guides junior auditors and provides management with practical recommendations for improving technology controls and resilience.
Key Responsibilities
- Manage assigned IT audit engagements from pre-planning and risk assessment through fieldwork, reporting, follow-up and closure.
- Contribute to periodic risk assessments with particular attention to information technology and emerging technology risks.
- Support development of the Annual Audit Plan based on identified risk exposure and organizational priorities.
- Review and update the IT audit universe to maintain adequate coverage of significant technology risks.
- Provide information for periodic reporting on IT audit performance, significant exposures and governance or control concerns.
- Lead IT auditors during examination of systems, records, processes and supporting evidence.
- Develop detailed audit programs and Risk and Control Matrices for assigned engagements.
- Define audit objectives, potential risks, key controls, testing procedures and evidence requirements.
- Select appropriate Information Systems Audit Techniques according to the nature and complexity of each review.
- Apply data analytics and statistical sampling techniques where they improve audit coverage or evidence quality.
- Evaluate governance, risk management and technology control processes against applicable requirements.
- Identify high-risk technology areas and critical control points requiring detailed examination.
- Collect and analyze complex system, process and evidentiary data to support audit conclusions.
- Maintain complete working papers and supporting documentation within the automated Audit Management System.
- Ensure audit documentation complies with approved methodologies, templates and quality standards.
- Supervise audits against approved Risk and Control Matrices and professional internal auditing standards.
- Review work completed by junior auditors and confirm that assigned procedures have been performed adequately.
- Verify that audit objectives receive sufficient coverage and conclusions are supported by appropriate evidence.
- Evaluate management responses and corrective measures relating to previous audit recommendations.
- Conduct follow-up reviews and maintain current status information for management action plans.
- Prepare clear audit reports addressing the adequacy and effectiveness of risk management and internal controls.
- Recommend practical improvements for identified technology governance and control deficiencies.
- Follow up on responses to draft and final audit reports and evaluate proposed remediation actions.
- Participate in special reviews and other assurance assignments requested by Internal Audit leadership.
- Support periodic reporting to the Audit Committee and Senior Management on significant IT risks and audit findings.
- Assist with Audit Committee agendas, meeting documentation and minutes when assigned.
- Contribute to Corporate Governance Framework, Enterprise Risk Management, Code of Conduct, ethics and values initiatives.
- Conduct workshops and presentations that increase awareness of Internal Audit and its contribution to organizational performance.
- Escalate significant technology control concerns to Internal Audit management for timely attention.
- Provide professional input regarding Audit Committee Charters, Internal Audit Charters and IT audit methodologies.
- Assist Group Companies with audit governance and Internal Audit function development when required.
- Participate in specialized professional training and knowledge-sharing initiatives across the Group.
- Conduct research and benchmarking to resolve audit issues and identify opportunities to improve audit practices.
- Assess system development processes, technology infrastructure, access rights and change management controls.
- Review operating systems, databases, network infrastructure and ERP environments from an audit and control perspective.
- Evaluate routers, switches, firewalls and other infrastructure components where relevant to audit scope.
- Consider Operational Technology processes and systems when evaluating technology risks affecting industrial operations.
- Coordinate with external auditors and other assurance providers to improve audit coverage and reduce duplicated effort.
- Support engagement with the Abu Dhabi Accountability Authority when required for government audit activities.
- Train and develop assigned personnel in IT audit techniques, risk assessment and professional assurance practices.
- Contribute to continuous improvement of audit tools, methodologies, reporting and operational processes.
Ideal Profile
- Bachelor 's Degree in Computer Science, Information Technology, Finance, Auditing or an equivalent discipline.
- Minimum 8 years of relevant IT internal auditing experience.
- Previous exposure to Oil and Gas operations and associated technology risks.
- CISA certification is mandatory.
- CISSP, CISM, GIAC or related professional certifications are preferred.
- In-depth knowledge of the IT Assurance Framework and relevant professional assurance practices.
- Strong working knowledge of COBIT, ITIL, ISO27000 and NIST frameworks.
- Thorough understanding of risk-based IT auditing and technology governance.
- Experience developing audit programs and Risk and Control Matrices.
- Strong knowledge of system development, infrastructure review, access rights management and change management.
- Advanced understanding of operating systems, databases and network infrastructure.
- Knowledge of routers, switches, firewalls and associated technology controls.
- Experience evaluating ERP systems and related controls.
- Awareness of Operational Technology processes, systems and industrial technology risks.
- Strong capability in collecting and analyzing complex datasets using data analytics tools.
- Ability to evaluate technical evidence and form logical, defensible audit conclusions.
- Experience supervising audit assignments and developing junior auditors.
- Strong planning and project management capability.
- Ability to communicate effectively with senior management, auditors and technical stakeholders.
- Strong professional report writing and presentation skills.
Skills Set
- IT internal auditing
- CISA
- IT Assurance Framework
- COBIT
- ITIL
- ISO27000
- NIST
- Risk-based auditing
- IT risk assessment
- IT governance
- Corporate governance
- Enterprise Risk Management
- Risk and Control Matrix
- Information Systems Audit Techniques
- IT general controls
- Audit planning
- Audit execution
- Control testing
- Data analytics
- Statistical sampling
- Audit Management Systems
- Audit working papers
- Systems development auditing
- Infrastructure auditing
- Access rights management
- Change management
- Operating systems
- Database controls
- Network infrastructure
- Routers
- Switches
- Firewalls
- ERP controls
- Operational Technology
- OT risk
- Cybersecurity controls
- Audit reporting
- Audit Committee reporting
- Management action plans
- Corrective action follow-up
- Internal Audit Charter
- Technology assurance
- Audit benchmarking
- CISM
- CISSP
- GIAC
Why Join Us
This position offers experienced IT audit professionals the opportunity to examine technology risks across both corporate systems and complex operational environments within the Oil & Energy sector. Exposure to enterprise applications, infrastructure, Operational Technology, governance and senior-level assurance reporting creates a strong platform for developing deeper expertise in technology risk while contributing directly to stronger controls and organizational resilience.
About the Company
ADNOC Group is a major integrated energy organization headquartered in Abu Dhabi with operations across exploration, production, processing and the wider energy value chain. Its Internal Audit activities provide independent assurance over governance, risk and control environments, helping strengthen accountability and effective management across corporate, technology and operational functions.