Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.
Prudential plc is seeking a skilled IT auditor to join the GwIA team in Malaysia. The role involves developing risk-based audit plans, leading audits from planning through closure, and collaborating with senior management to address issues.
Candidates should have 3+ years in IT audit within financial services, a technology degree, and relevant certifications. Experience in cybersecurity, data analytics and IAM tools like SailPoint/CyberArk is preferred.
Prudential’s purpose is to be partners for every life and protectors for every future. Our purpose encourages everything we do by creating a culture in which diversity is celebrated and inclusion assured, for our people, customers, and partners. We provide a platform for our people to do their best work and make an impact to the business, and we support our people’s career ambitions. We pledge to make Prudential a place where you can Connect, Grow, and Succeed.
A member of the Global IT audit resource pool, you are responsible for:
Assisting to develop and continuously review the half-yearly risk based audit plan for Prudential, aligned to LBU strategy
Lead or support in delivering the assigned audit which includes entire audit process from planning to issue assurance and closure
Other GwIA driven initiatives
To provide value adding contribution to audit reviews of processes, controls and systems, within Prudential and across the other business units in the Group as required:
Deliver good quality audit assignments in line with GwIA audit methodology, Group requirements and standards, resulting in accurate and complete identification of issues
Execute the audits in the approved audit plan including risk assessment and control management over operations’ effectiveness and compliance with all applicable standards and regulations
Understand the business, risk and controls through information gathered on the audit scope area, involvement in walkthroughs and discussions with management
Review the adequacy and efficiency of the controls in place via review of documented procedures and conducting audit testing
Working papers are documented properly in accordance with GwIA Audit Methodology and approved within the established deadline
Responsible for discussing the audit report and findings with senior management and ensuring that appropriate responses are obtained for each issue raised in the report, including demonstration of good conflict management skill and remaining professional when criticised
Draft internal audit report for discussion with GwIA management and auditee management, including display of good and concise presentation of issues/risks
Monitor progress and adequacy of actions taken to rectify and close out audit issues
Demonstrate the ability to evaluate, synthesise, organise and interpret data and information
Seek opportunities to increase the use of data analytics testing by adding new tests to the data analytics library
Continuous monitoring of emerging risks and key changes to the businesses, and are factored in the risk assessment of the audit planning process
Keeps abreast of new information and developments in the industry or best practices in auditing (e.g., by reading, liaising with organization and business core group contacts, or by attending learning and training events)
Routinely engages and meets business stakeholders as part of GwIA continuous monitoring activities
To promote GwIA and the service it provides by building strong and effective working relationships with senior management, other staff and external auditors
At the request of the GwIA Management, assist in the preparation of internal audit reports and papers for Board and Management committee reporting, on the status of the audit plan, audit results and issues status
Post Qualification - at least 3 years relevant experience in 2nd or 3rd line (will consider 1st line on a case to case basis)
In addition to a technology degree, is CISA certified and / or has other relevant technical certification around Cybersecurity, Cloud, Software Engineering, Technology Risk Management or Project Management.
Financial services (Banking, Insurance etc.)
Experience in auditing controls, security, and management in at least four or more of the following areas:
Added advantage if candidates have experience in auditing and risk assessing controls, security, and management in at least one or more of the following areas:
Artificial intelligence
Data governance
API management
Robotics process automation
Mobile device management
Mobile application development
Familiar with emerging technologies and associated risks (e.g. artificial intelligence, blockchain, internet of things, robotics)
Coding background / data analytics capability (familiar with tools such as Python, SQL) an advantage
Known as an SME in own functional area and is often sought after for advice / consultation
An awareness of current and emerging industry risks within financial services and a clear appreciation of the regulatory environments within the industry
Apart from business-as-usual audit work, have track records of delivering impactful initiatives / products which have helped elevate the function (e.g. helped automate a certain manual process / delivered an automated dashboard for more efficient risk identification etc.) will be advantageous
Good understanding of the local regulations
Possesses good verbal and written communication skills
Demonstrable experience of influencing and challenging senior management and building excellent relationships
Track record of producing value-adding, commercially realistic recommendations in risk, consultancy or internal audit environment
Leading edge risk management knowledge and expertise
Relevant industry experience
High attention to detail and rigorous thinking ability
Good Team player, who can gain the professional respect of the team
Prudential is an equal opportunity employer. We provide equality of opportunity of benefits for all who apply and who perform work for our organisation irrespective of sex, race, age, ethnic origin, educational, social and cultural background, marital status, pregnancy and maternity, religion or belief, disability or part-time / fixed-term work, or any other status protected by applicable law. We encourage the same standards from our recruitment and third-party suppliers taking into account the context of grade, job and location. We also allow for reasonable adjustments to support people with individual physical or mental health requirements.