Assistant Manager/Manager, IT Audit

COMMERCE DOT COM SDN. BHD.

Petaling Jaya

On-site

MYR 60,000 - 95,000

Full time

9 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical benefits
Group term life
Meal credits
In-house sports court
Team events
Work‑life balance

Job summary

Commerce Dot Com Sdn. Bhd. in Malaysia is seeking an experienced IT Audit professional to plan, lead and execute comprehensive IT audits across ITGCs, applications, infrastructure and cybersecurity.

You will evaluate control design and operating effectiveness and report findings to management. The role requires 5+ years in IT audit or information security, with certifications such as CISA/CIA/CISSP. You will develop audit programmes, prepare working papers, and support ISO/IEC 27001 ISMS audits,

Qualifications

  • Bachelor's degree in IT, CS, IS or related field.
  • Professional certification such as CISA/CIA/CISSP/CRISC is an added advantage.
  • Knowledge of IT audit methodologies, ITGCs, COBIT and ISO/IEC 27001.
  • Minimum 5 years of IT audit or information security experience.
  • Hands-on experience with IT operations, change management, disaster recovery.
  • Experience in ISMS/internal audits is an added advantage.
  • Ability to lead audits and review team work.

Responsibilities

  • Plan, lead and execute IT audits including scope and programmes.
  • Evaluate design and operating effectiveness of IT controls.
  • Prepare audit working papers and final reports.
  • Follow up on audit actions and obtain management action plans.
  • Conduct ISMS internal audits per ISO/IEC 27001.
  • Support annual IT audit planning and stay updated on tech/regulatory developments.

Skills

IT auditing
ITGC
Information security
Root-cause analysis
Documentation
Stakeholder management
Leadership

Education

Bachelor's Degree in Information Technology/Computer Science/Information Systems

Tools

COBIT
ISO/IEC 27001
ISMS

Job description

  • Plan, lead and execute comprehensive IT audits, including the development of audit scope, objectives and audit programmes, covering IT general controls, application systems, infrastructure, networks, cybersecurity, data centres, system development and change management, IT operations, business continuity and disaster recovery.
  • Evaluate the design and operating effectiveness of IT controls, identify control deficiencies, determine root causes and assess their impact on the organization.
  • Prepare and review audit working papers to ensure audit procedures, evidence, conclusions and findings are adequately documented and comply with Internal Audit methodology, policies and applicable professional standards.
  • Prepare clear, concise and accurate audit reports, communicate significant findings to relevant stakeholders, and obtain appropriate management action plans and target completion dates.
  • Perform follow-up on audit observations, including validation of corrective actions and supporting evidence before recommending closure.
  • Participate in and/or conduct ISMS internal audits in accordance with the organization’s Information Security Management System requirements and applicable standards, including ISO/IEC 27001, and report nonconformities, observations and opportunities for improvement.
  • Support the annual IT audit planning process and keep abreast of developments in technology, cybersecurity, information security and applicable regulatory requirements.
QUALIFICATIONS
  • Bachelor’s Degree in Information Technology, Computer Science, Information Systems or a related discipline.
  • Professional certification such as CISA, CIA, CISSP, CRISC or other relevant certification is an added advantage.
  • Knowledge of IT audit methodologies, internal auditing, IT general controls, COBIT, information security practices and applicable professional standards.
  • Knowledge of ISO/IEC 27001 and ISMS internal audit requirements is an added advantage.
  • Minimum 5 years of relevant working experience in IT audit, internal audit, information security, technology controls or a related field.
  • Hands‑on experience in auditing IT general controls, application systems, infrastructure, networks, cybersecurity, data centres, system development/change management, IT operations, business continuity and disaster recovery.
  • Experience in ISMS and/or ISO/IEC 27001 internal audits is an added advantage.
  • Experience in preparing audit working papers, developing audit findings, preparing audit reports and following up on corrective actions.
  • Experience in leading audit assignments and reviewing the work of audit team members is preferred.
REQUIRED COMPETENCIES & SKILLS
  • Strong knowledge of IT auditing, IT general controls, information security and internal control principles.
  • Good understanding of COBIT, ISO/IEC 27001, ISMS requirements and applicable IT governance and security standards.
  • Strong analytical, problem-solving and root-cause analysis skills.
  • Good audit documentation and report-wiring skills.
  • Strong communication, interpersonal and stakeholder management skills.
  • Ability to lead audit assignments and guide audit team members.
  • Ability to manage multiple assignments and meet established timelines.
  • Good professional judgment, integrity, objectivity and attention to detail.
  • Ability to work independently and collaboratively within the Internal Audit team.
WHY JOIN US
  • Comprehensive medical benefits for you, your spouse, and children, ensuring your well‑being is our top priority.
  • Rest easy with our group term life coverage, providing you with security and assurance.
  • Stay energized with meal credit that keep you fueled throughout the day.
  • An in‑house futsal court and badminton court for post‑work workouts.
  • A variety of fun‑filled events and gatherings to unwind.
  • Achieve a healthy work‑life balance, ensuring you thrive both in and out of the office.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Assistant Manager-Manager, IT Audit
Assistant Manager-Manager, IT Audit

Commerce Dot Com • Selangor

On-site
MYR 120,000 - 180,000
Medical benefits for you and family
Group term life coverage
Meal credit
+3
SENIOR MANAGER, INTERNAL AUDIT
SENIOR MANAGER, INTERNAL AUDIT

KPJ HEALTHCARE BERHAD • Malaysia

On-site
MYR 80,000 - 120,000
Executive - IT Audit
Executive - IT Audit

Sunway Group • Subang Jaya

On-site
MYR 60,000 - 100,000
SENIOR MANAGER, INTERNAL AUDIT
SENIOR MANAGER, INTERNAL AUDIT

KPJ Healthcare Berhad • Kuala Lumpur

On-site
MYR 120,000 - 160,000
Assistant Manager, Internal Audit & Risk Management
Assistant Manager, Internal Audit & Risk Management

Cyberjaya • Cyberjaya

On-site
MYR 110,000 - 170,000
Senior Executive - Audit
Senior Executive - Audit

Sunway Group • Subang Jaya

On-site
MYR 60,000 - 90,000
Assistant Vice President - IT Audit
Assistant Vice President - IT Audit

alrajhi bank Malaysia • Kuala Lumpur

On-site
MYR 112,000 - 201,000
CYBER SECURITY SPECIALIST
CYBER SECURITY SPECIALIST

Commerce Dot Com Sdn Bhd • Cyberjaya

On-site
MYR 60,000 - 120,000
Comprehensive medical benefits
Group term life coverage
Meal allowances
+1
Assistant Manager - IT (Compliance)
Assistant Manager - IT (Compliance)

Genting Energy • Kuala Lumpur

On-site
MYR 180,000 - 260,000
Executive/Senior Executive Internal Audit
Executive/Senior Executive Internal Audit

MR.DIY Group (M) Berhad • Seri Kembangan

On-site
MYR 56,000 - 89,000