Get more replies from employers
Send a job-specific resume in minutes.
CPS Asia Pacific is seeking a Senior IT Auditor to evaluate the effectiveness, security, and compliance of the organization’s technology environment. The role will independently assess internal systems, applications, infrastructure, processes, and selected third-party environments throughout the audit lifecycle.
The successful candidate will plan and execute audits, validate evidence, investigate issues, document observations, and monitor remediation.
We are seeking a detail-oriented and experienced Senior IT Auditor to evaluate the effectiveness, security, and compliance of the organization’s technology environment. The role will independently assess internal systems, applications, infrastructure, processes, and selected third-party environments throughout the complete audit lifecycle.
The successful candidate will be involved in audit planning, control testing, evidence validation, issue investigation, documentation, reporting, and remediation monitoring. The position is well suited for professionals with backgrounds in IT Audit, IT Compliance, Quality Assurance, or ISO implementation and certification who are comfortable working with both technical and business stakeholders.
Strong judgment, analytical thinking, confidentiality, and professional independence are essential, particularly when reviewing sensitive systems, security controls, business information, and audit evidence.
Plan and conduct internal and external technology audits based on established audit objectives, standards, and organizational requirements.
Review IT systems, applications, infrastructure, integrations, security practices, ISO management systems, and privacy-related controls.
Perform audit readiness assessments, system reviews, functional testing, and user or identity verification where required.
Evaluate whether technology controls are appropriately designed, implemented, and operating effectively.
Assess IT General Controls (ITGC), application controls, access management, security configurations, and other technology-related controls.
Examine operating systems, networks, databases, APIs, cloud environments, and supporting technology processes.
Identify control deficiencies, unauthorized activities, security exposures, process gaps, and potential compliance issues.
Evaluate the potential impact and risk associated with identified findings.
Review audit evidence to determine its accuracy, completeness, reliability, and relevance.
Trace information to source systems or supporting records when additional validation is required.
Investigate unusual transactions, inconsistencies, control exceptions, and potential misrepresentation.
Apply structured root cause analysis to determine why control or process weaknesses occurred.
Maintain comprehensive audit working papers, testing documentation, evidence, findings, and supporting records.
Prepare clear and objective audit observations, risk assessments, and recommendations.
Communicate audit results to technical and non-technical stakeholders in a professional and understandable manner.
Assist with audit debriefs and the preparation of final reports for management and relevant stakeholders.
Monitor corrective actions and perform follow-up reviews to determine whether identified issues have been adequately addressed.
Escalate significant or high-risk findings to the appropriate stakeholders.
Support improvements to audit procedures, testing approaches, checklists, templates, and documentation standards.
Promote consistent and effective audit practices across engagements.
Maintain objectivity, professional skepticism, and independence throughout audit activities.
Identify and avoid potential conflicts of interest when evaluating systems, processes, or teams.
Protect confidential information, credentials, audit evidence, business records, and other sensitive data encountered during engagements.
Bachelor’s degree in Information Technology, Computer Science, Information Systems, Engineering, or a related discipline. Equivalent relevant experience may be considered.
At least 5 years of relevant professional experience in one or more of the following:
IT Audit
IT Compliance
Quality Assurance
ISO Implementation, Audit, or Certification
Strong understanding of:
IT General Controls (ITGC)
Application and system controls
Access management and security controls
Operating systems and network environments
Databases and APIs
Cloud platforms and services
Log analysis and data analytics
Strong investigative, analytical, and root cause analysis capabilities.
Excellent attention to detail with an evidence-driven approach to problem solving.
Strong written and verbal English communication skills.
Ability to explain technical audit observations and risks to both technical and non-technical stakeholders.
High level of integrity, discretion, and professionalism when handling confidential information.
Comfortable working independently while maintaining audit objectivity and professional judgment.
Experience working in a regulated or highly controlled industry is an advantage.
Candidates with relevant professional certifications are highly preferred, including:
CISA (Certified Information Systems Auditor)
CIA (Certified Internal Auditor)
ISO/IEC 27001
ISO 22301
ISO 9001
ISO 45001
Other recognized certifications in IT audit, information security, risk management, compliance, or ISO standards