Assistant Manager-Manager, IT Audit

Commerce Dot Com

Selangor

On-site

MYR 120,000 - 180,000

Full time

12 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical benefits for you and family
Group term life coverage
Meal credit
In-house sports courts
Events and gatherings
Healthy work-life balance

Job summary

Commerce Dot Com is seeking an experienced IT Audit professional to lead comprehensive audits spanning ITGCs, applications, infrastructure, networks, and cybersecurity. The role covers ISMS audits under ISO/IEC 27001, risk assessment, and reporting with action plans.

You will plan, execute and supervise audits, review working papers, and ensure compliance with Internal Audit standards. The ideal candidate brings 5+ years of IT audit experience and strong communication skills.

Qualifications

  • Bachelor’s Degree in IT/CS/IS or related discipline.
  • Certifications such as CISA/CIA/CISSP/CRISC are advantageous.
  • Knowledge of IT audit methodologies, internal auditing, IT general controls.
  • Familiarity with ISO/IEC 27001 and ISMS internal audit requirements is a plus.
  • Minimum 5 years of relevant IT audit experience.
  • Hands-on auditing ITGCs, app systems, infra, networks, cyber security, DR/BC.
  • Experience leading audits and reviewing team work.

Responsibilities

  • Plan, lead and execute IT audits across ITGC, apps, infrastructure and cyber.
  • Evaluate control design and operating effectiveness and assess root causes.
  • Prepare and review audit working papers per standards.
  • Prepare audit reports and obtain management action plans.
  • Follow up on audit observations and validate corrective actions.
  • Participate in ISMS internal audits (ISO/IEC 27001) and report nonconformities.
  • Support annual IT audit planning and keep up with regulatory requirements.

Skills

IT auditing
IT general controls
Information security
ISMS
COBIT
ISO/IEC 27001
Analytical skills
Report writing
Communication
Leadership
Time management

Education

Bachelor’s degree in IT/CS/IS
CISA
CIA
CISSP
CRISC

Job description

  • Plan, lead and execute comprehensive IT audits, including the development of audit scope, objectives and audit programmes, covering IT general controls, application systems, infrastructure, networks, cybersecurity, data centres, system development and change management, IT operations, business continuity and disaster recovery.
  • Evaluate the design and operating effectiveness of IT controls, identify control deficiencies, determine root causes and assess their impact on the organization.
  • Prepare and review audit working papers to ensure audit procedures, evidence, conclusions and findings are adequately documented and comply with Internal Audit methodology, policies and applicable professional standards.
  • Prepare clear, concise and accurate audit reports, communicate significant findings to relevant stakeholders, and obtain appropriate management action plans and target completion dates.
  • Perform follow-up on audit observations, including validation of corrective actions and supporting evidence before recommending closure.
  • Participate in and/or conduct ISMS internal audits in accordance with the organization’s Information Security Management System requirements and applicable standards, including ISO/IEC 27001, and report nonconformities, observations and opportunities for improvement.
  • Support the annual IT audit planning process and keep abreast of developments in technology, cybersecurity, information security and applicable regulatory requirements.
QUALIFICATIONS
  • Bachelor’s Degree in Information Technology, Computer Science, Information Systems or a related discipline.
  • Professional certification such as CISA, CIA, CISSP, CRISC or other relevant certification is an added advantage.
  • Knowledge of IT audit methodologies, internal auditing, IT general controls, COBIT, information security practices and applicable professional standards.
  • Knowledge of ISO/IEC 27001 and ISMS internal audit requirements is an added advantage.
  • Minimum 5 years of relevant working experience in IT audit, internal audit, information security, technology controls or a related field.
  • Hands-on experience in auditing IT general controls, application systems, infrastructure, networks, cybersecurity, data centres, system development/change management, IT operations, business continuity and disaster recovery.
  • Experience in ISMS and/or ISO/IEC 27001 internal audits is an added advantage.
  • Experience in preparing audit working papers, developing audit findings, preparing audit reports and following up on corrective actions.
  • Experience in leading audit assignments and reviewing the work of audit team members is preferred.
REQUIRED COMPETENCIES & SKILLS
  • Strong knowledge of IT auditing, IT general controls, information security and internal control principles.
  • Good understanding of COBIT, ISO/IEC 27001, ISMS requirements and applicable IT governance and security standards.
  • Strong analytical, problem-solving and root-cause analysis skills.
  • Good audit documentation and report-writing skills.
  • Strong communication, interpersonal and stakeholder management skills.
  • Ability to lead audit assignments and guide audit team members.
  • Ability to manage multiple assignments and meet established timelines.
  • Good professional judgment, integrity, objectivity and attention to detail.
  • Ability to work independently and collaboratively within the Internal Audit team.
WHY JOIN US
  • Comprehensive medical benefits for you, your spouse, and children, ensuring your well-being is our top priority.
  • Rest easy with our group term life coverage, providing you with security and assurance.
  • Stay energized with meal credit that keep you fueled throughout the day.
  • An in-house futsal court and badminton court for post-work workouts.
  • A variety of fun-filled events and gatherings to unwind.
  • Achieve a healthy work-life balance, ensuring you thrive both in and out of the office.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Assistant Manager/Manager, IT Audit
Assistant Manager/Manager, IT Audit

COMMERCE DOT COM SDN. BHD. • Petaling Jaya

On-site
MYR 60,000 - 95,000
Medical benefits
Group term life
Meal credits
+3
SENIOR MANAGER, INTERNAL AUDIT
SENIOR MANAGER, INTERNAL AUDIT

KPJ Healthcare Berhad • Kuala Lumpur

On-site
MYR 120,000 - 160,000
SENIOR MANAGER, INTERNAL AUDIT
SENIOR MANAGER, INTERNAL AUDIT

KPJ HEALTHCARE BERHAD • Malaysia

On-site
MYR 80,000 - 120,000
Assistant Manager, Internal Audit & Risk Management
Assistant Manager, Internal Audit & Risk Management

Cyberjaya • Cyberjaya

On-site
MYR 110,000 - 170,000
Executive - IT Audit
Executive - IT Audit

Sunway Group • Subang Jaya

On-site
MYR 60,000 - 100,000
Assistant Manager, Internal Audit
Assistant Manager, Internal Audit

CGC Malaysia • Petaling Jaya

On-site
MYR 180,000 - 260,000
Assistant Vice President II, Internal Audit Department
Assistant Vice President II, Internal Audit Department

Air Selangor • Kuala Lumpur

On-site
MYR 150,000 - 210,000
CYBER SECURITY SPECIALIST
CYBER SECURITY SPECIALIST

Commerce Dot Com Sdn Bhd • Cyberjaya

On-site
MYR 60,000 - 120,000
Comprehensive medical benefits
Group term life coverage
Meal allowances
+1
IT Internal Auditor
IT Internal Auditor

IJM Corporation Berhad • Petaling Jaya

On-site
MYR 90,000 - 140,000
Senior Executive (Group Internal Audit)
Senior Executive (Group Internal Audit)

SEDC GLOBAL BUSINESS SERVICES SDN. BHD. • Kuching

On-site
MYR 120,000 - 180,000