JOB SUMMARY
The IT Auditor conducts independent, structured audits across both internal engagements—assessing assigned systems and platforms for compliance with applicable regulatory and internal requirements—and external audits of third-party entities. The role covers the full audit cycle, from preparation and on-site execution through documentation and reporting, and requires a detail-oriented professional who can work independently, communicate findings clearly, and uphold the highest standards of accuracy and confidentiality.
DUTIES AND RESPONSIBILITIES
- Lead and execute internal and external audits across the organization and third-party entities covering system integrations, ISO management systems, security compliance, and data privacy impact assessments.
- Assess infrastructure, configurations, access controls, IT general controls, and application controls against defined audit criteria—with focus on detecting control bypass, unauthorized activity, and non-compliance.
- Validate the integrity, completeness, and reliability of audit evidence; trace data to source systems and investigate anomalies, gaps, or potential misrepresentation through root cause analysis.
- Execute pre-audit preparation, system readiness checks, functional testing, and user/identity verification per audit checklists and regulatory standards.
- Document findings, test outcomes, and audit records with clear, traceable evidence suitable for regulatory and management review.
- Escalate high-risk findings and conduct follow-through investigations to validate remediation and confirm closure with credible evidence.
- Contribute to post-audit debriefs, final report preparation, and continuous improvement of audit processes and documentation standards.
- Maintain auditor independence and ensure no conflict of interest with systems or teams under assessment.
JOB COMPETENCIES/SPECIFICATIONS
- Bachelor’s degree in Computer Science, Information Technology, Information Systems, Engineering, or equivalent practical experience.
- Minimum 5 yearsof relevant experience in IT Audit, Compliance, QA, or ISO Implementation/Audit/Certification.
- Working knowledge of IT general controls, application controls, operating systems, networks, databases, APIs, cloud services, and log/data analytics.
- Forensic, evidence-based mindset with strong analytical and root-cause analysis skills.
- Clear written and verbal English communication for both technical and non-technical audiences.
- High integrity and discretion when handling sensitive systems, credentials, and confidential data.
- Preferred Certifications in IT audit or information security (e.g., ISO 27001, 22301, 9001, 45001; CISA, CIA, or similar).
- Preferred prior exposure to regulated industry audit environments.