IT and Information Security Compliance Staff Auditor

ThunderSoft

Penang

On-site

MYR 90,000 - 150,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

ThunderSoft in Malaysia is seeking an experienced IT Audit and Compliance professional to strengthen our ITGC controls and SOX readiness within a SAP-centric environment.

You will lead control assessments, maintain risk matrices, and collaborate with IT and business units to remediate deficiencies while supporting ISO 27001 certification efforts. Strong communication and project management are essential to liaise with auditors and drive improvements.

Qualifications

  • Bachelor’s or Master’s degree in IT, Business or Accounting.
  • 5+ years of IT audit/compliance experience.
  • Experience with IT controls and risk assessment.
  • Big 4 IT Audit background or ERP experience is a plus.

Responsibilities

  • Manage timely performance of control assessments and evidence review.
  • Assist in annual IT Risk Assessment for key financial processes.
  • Maintain IT Risk Control Matrix documenting systems, controls and testing.
  • Ensure proper accounting of ITGC SOX documentation.
  • Identify opportunities to automate ITGC controls.
  • Support testing of IT systems and controls for SOX in SAP environments.
  • Support ISO 27001 certification evidence gathering.
  • Collaborate with IT teams to remediate control deficiencies.
  • Liaise with auditors for ITGC testing and compliance.
  • Review SDLC controls and advise project managers on risks.
  • Audit projects for SDLC compliance.
  • Additional duties as assigned.

Skills

IT Audit
SOX Compliance
GRC
COBIT
SAP ERP
SOC 1/2
Communication
Leadership
Project Management

Education

Bachelor’s or Master’s Degree in IT/Accounting/Business

Tools

SAP ECC
SAP GRC

Job description

Job responsibilities include but not limited to,

  • Manage timely performance of control assessments, review of control supporting evidence as second line of defense
  • Actively assist in annual IT Risk Assessment including the following: identification of all systems supporting key financial processes; assessment of controls (general and application) for key financial systems; assessment and/or development of test procedures, including assessment of control testers.
  • Maintain IT Risk Control Matrix to document all key financial systems, controls and testing procedures.
  • Ensure proper accounting of SOX documentation for ITGC to include IT Risk Control Matrix, ITGC Process Narratives, ITGC testing, issue evaluation and reporting.
  • Identify opportunities and support automation in process and ITGC controls to improve the efficiency.
  • Support coordination and perform testing and evaluation of IT systems and controls for SOX compliance in a predominately SAP environment.
  • Support ISO 27001 certification evidence gathering and audit support.
  • Support efforts for ITGC training and documentation as needed.
  • Work collaboratively with the IT teams and business units in remediating control deficiencies
  • Evaluate third party SSAE 18 (SOC 1) and/or SOC 2 reports for compliance to system control requirements.
  • Make recommendations for enhancement of IT system controls and process improvements.
  • Work on projects to implement IT risk and control / compliance requirements for new systems.
  • Provide timely and complete communications within the IT department, Internal Audit and Compliance including identification of ITGC issues and exceptions.
  • Serve as liaison to internal and external auditors for ITGC testing and other compliance initiatives.
  • Ability to work on multiple projects, balancing a mix of resources, due dates and requirements.
  • Develop and foster effective working relationships within IT at each of the Divisions as well as key Business, Internal Audit and Compliance personnel.
  • Work collaboratively with necessary stakeholders and teams for GDPR compliance and implementation.
  • Work closely with owners of the Access Control, Release Management, Change Management and Vendor ,Management processes to ensure compliance with the ITGC Framework.
  • As assigned, perform a review of assigned SDLC key control deliverables and advise Project Managers on SDLC risks and controls.
  • Audit projects for SDLC and key control compliance.
  • Besides the above responsibilities and duties, this position may require to take up additional responsibilities as assigned.
Skills/Requirements

To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required.

  • Bachelor’s or Master’s Degree from a regionally accredited four-year college or university in Computer Science, Business, Accounting or related field and 5+ years of relevant experience in IT Audit/Compliance; or equivalent combination of education and experience.
  • In-depth knowledge of business processes as well as process controls and risks and an understanding on how this relates to the IT environment and audit procedures.
  • Big 4 IT Audit background or Fortune 100 companies (with SAP ERP) experience is a plus.
  • One or more of the following is desired:
  • Certified Information Systems Auditor (CISA)
  • Certified Internal Auditor (CIA)
  • Understanding of IT control frameworks and standards such as COBIT.
  • Performed and led IT general computing controls risk / SOX / compliance process including updates to the annual testing, test execution, review of test results, recommending solutions to gaps and addressing gaps with control owners.
  • Broad knowledge of IT infrastructure and architecture of computer systems as well as exposure to a variety of platforms such as operating systems, networks, databases and ERP systems.
  • Experience with SAP’s ECC, BW, SCM, PI/PO, TM and BOBJ applications and services.
  • Experience with SAP’s GRC Access Control tool along with Segregation of Duty (SOD) analysis and sensitive administrative T-Codes and privileged user access is a plus.
  • Experience with project management.
  • Proven experience in navigating complex organizations, creative problem solving and effective relationship management.
  • Work collaboratively with cross-functional teams
  • Ability to translate complex technical topics into easy to understand concepts and the ability to manage escalations and communications.
  • Strong verbal and written communication skills with ability to effectively communicate with peers and executive leadership.
  • Strong leadership and time management skills. Specific skills include facilitating change, driving operational excellence, and striving for continuous improvement.
Work Location

Malaysia

Schedule

Full-time on-site

Employee Status

Contract

Job Level

Staff Information Security and IT Compliance

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Compliance Lead: SOX, SAP & Risk Controls
IT Compliance Lead: SOX, SAP & Risk Controls

ThunderSoft • Kuala Lumpur

On-site
MYR 120,000 - 180,000
IT Compliance & SOX Audit Analyst (SAP/GRC)
IT Compliance & SOX Audit Analyst (SAP/GRC)

ThunderSoft • Penang

On-site
MYR 90,000 - 150,000
IT Internal Auditor
IT Internal Auditor

IJM Corporation Berhad • Petaling Jaya

On-site
MYR 90,000 - 140,000
Assistant Manager, IT SOX Financial Controls
Assistant Manager, IT SOX Financial Controls

HFG Insurance Recruitment • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Information Technology Audit Manager
Information Technology Audit Manager

NTT DATA Payment Services • Kuala Lumpur

On-site
MYR 90,000 - 130,000
GRC Analyst Kuala Lumpur, Malaysia GRC Analyst
GRC Analyst Kuala Lumpur, Malaysia GRC Analyst

Sitecore • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Assistant Manager/Manager, IT Internal Audit
Assistant Manager/Manager, IT Internal Audit

Lam Soon Edible Oils Sdn Bhd • Shah Alam

On-site
MYR 120,000 - 180,000
Assistant Manager/Manager, IT Internal Audit
Assistant Manager/Manager, IT Internal Audit

Lam Soon • Selangor

On-site
MYR 120,000 - 180,000
IT Governance, Risk & Compliance Manager
IT Governance, Risk & Compliance Manager

CapBay • Kuala Lumpur

Hybrid
MYR 90,000 - 150,000
Senior Manager/ Manager - IT Audit
Senior Manager/ Manager - IT Audit

Genting Plantations Berhad • Kuala Lumpur

On-site
MYR 120,000 - 180,000