Lead Auditor
Department: Internal Audit
Employment Type: Full Time
Location: KSA
Reporting To: Hatem AlHaidan
Description
As Audit Lead – IT & Cyber Security Audit, you will lead the end-to-end execution
of IT, cybersecurity, and technology audit engagements, supervising
engagement teams and delivering high-quality audit results in line with Tabby's
technology risk-based audit plan.
Key Responsibilities
- Lead the planning and execution of assigned IT general controls,
- application controls, and cybersecurity audit engagements, from
scoping through reporting. - Develop detailed audit programs and risk and control matrices (RCMs)
covering IT and cyber risk areas, aligned with the approved audit plan. - Supervise and review the fieldwork of Senior Auditors, Auditors, and
Interns assigned to the engagement, ensuring quality and adherence to
methodology. - Conduct walkthroughs, technical interviews, and testing of IT general
controls, application controls, network and endpoint security, identity
and access management, and cloud configurations. - Identify control gaps and root causes, and draft clear, actionable audit
findings and recommendations on technology and cyber risk. - Draft audit reports and present engagement results to Engineering and
Information Security process owners. - Engage directly with technology process owners to validate findings,
agree on corrective action plans, and set remediation timelines. - Track and follow up on the implementation of IT and cyber audit
recommendations for assigned engagements. - Contribute to the annual technology and cyber risk assessment for
assigned systems and platforms. - Coach and provide on-the-job guidance to Senior Auditors, Auditors,
and Interns on IT audit techniques. - Support the Audit Manager in preparing quarterly and annual IT/cyber
audit reporting materials. - Stay current on IT auditing standards, cybersecurity frameworks, and
SAMA regulatory requirements (including the SAMA Cyber Security
Skills, Knowledge and Expertise
- 5+ years of experience in IT audit, information security, or technology risk,
including experience leading audit engagements, preferably within
banking, fintech, or corporate environments. - Strong knowledge of IT auditing standards, cybersecurity frameworks,
and SAMA regulatory requirements. - Experience assessing IT general controls, application controls, and
cybersecurity controls. - Strong communication and interpersonal skills to engage with
technology process owners and present audit findings. - Strong analytical and problem-solving skills with a detail-oriented
approach. - Proficiency in IT audit tools and familiarity with cloud platforms
(AWS/Azure/GCP). - Bachelor's degree in Computer Science, Information Systems,
Cybersecurity, or a related field; CISA (obtained or in progress) highly
desirable.