Get more replies from employers
Send a job-specific resume in minutes.
MEGA PRIME FOODS INCORPORATED is seeking an IT Auditor to evaluate the effectiveness of IT controls, systems, processes, and security practices in Metro Manila. The role conducts IT audits and assessments to identify risks, control gaps, and improvement opportunities while ensuring compliance with policies and industry standards.
The ideal candidate will have 2–5 years of IT audit/IT risk experience, knowledge of ITGCs, governance, and frameworks such as COBIT, ISO 27001, NIST, and COSO.
Job Summary
The IT Auditor is responsible for evaluating the effectiveness of the organization’s IT controls, systems, processes, and security practices. This role conducts IT audits and assessments to identify risks, control gaps, and opportunities for improvement, while ensuring compliance with internal policies, industry standards, and applicable regulations.
Key Responsibilities
Plan and conduct IT audits, risk assessments, and control reviews covering IT infrastructure, applications, cybersecurity, data, and technology processes.
Evaluate the design and effectiveness of IT general controls (ITGCs), including access management, change management, backup and recovery, and IT operations.
Assess IT processes and controls against company policies, regulatory requirements, and relevant industry standards.
Identify control weaknesses, security risks, compliance gaps, and potential areas of improvement.
Prepare audit working papers, findings, reports, and recommendations for management.
Work with IT and business stakeholders to develop corrective action plans and monitor the implementation of agreed recommendations.
Perform follow-up audits to validate the closure and effectiveness of remediation activities.
Review user access controls, privileged access, segregation of duties, and access provisioning/deprovisioning processes.
Assess IT change management, incident management, problem management, and business continuity/disaster recovery processes.
Support audits related to cybersecurity, data privacy, third-party/vendor risk, and information security.
Maintain awareness of emerging technology risks, cybersecurity threats, and changes in relevant regulations and standards.
Collaborate with Internal Audit, Information Security, Risk Management, Compliance, and other relevant teams.
Provide insights and recommendations that strengthen the organization's IT governance, risk management, and internal control environment.
Qualifications
Bachelor’s degree in Information Technology, Computer Science, Accounting, Internal Audit, Management Information Systems, or a related field.
Typically 2–5 years of experience in IT audit, IT risk, information security, technology controls, internal audit, or a related function.
Knowledge of IT General Controls (ITGC), IT governance, risk management, and internal control frameworks.
Familiarity with standards and frameworks such as COBIT, ISO 27001, NIST, and COSO is an advantage.
Understanding of IT infrastructure, networks, databases, cloud technologies, cybersecurity, and enterprise applications.
Strong analytical, problem-solving, documentation, and report-writing skills.
Good communication and stakeholder management skills.
Ability to work independently and manage multiple audit activities and deadlines.
Preferred Certifications
Certified Information Systems Auditor (CISA)
Certified Internal Auditor (CIA)
Certified Information Systems Security Professional (CISSP)
Certified in Risk and Information Systems Control (CRISC)
ISO 27001 certification is an advantage.
Key Competencies
IT Audit & Controls
IT Risk Management
Information Security
IT Governance
Compliance & Regulatory Awareness
Risk Assessment
Analytical & Critical Thinking
Audit Documentation & Reporting
Stakeholder Management
Attention to Detail