The Senior IT Internal Auditor is responsible for planning, executing, and leading IT audit engagements across the organization to evaluate the effectiveness of IT controls, risk management practices, and governance structures. The role ensures compliance with internal policies, regulatory requirements, and industry standards, while identifying risks and recommending improvements to strengthen IT systems, processes, and data security
Key Activities:
- Lead IT audit engagements based on the approved audit plan
- Develop audit scope, programs, and testing procedures
- Assess IT general controls (ITGCs), application controls, and system configurations
- Evaluate user access management, data integrity, and security controls
- Identify and assess IT risks and their impact on business operations
- Ensure compliance with internal policies and external standards (ISO 27001, COBIT, NIST)
- Evaluate IT governance frameworks and risk management processes
- Assess cybersecurity controls and data protection practices
- Prepare clear and comprehensive audit reports with findings and recommendations
- Present audit results to management and key stakeholders
- Monitor and follow up on remediation actions and closure of audit findings
- Perform data analysis using audit tools (e.g., ACL, IDEA, Excel)
- Review system logs, integrations, and application controls
- Assess ERP systems (Oracle, SAP) for control effectiveness and risks
- Provide advisory support on IT projects and system implementations
- Recommend control enhancements and process improvements
- Stay updated on emerging technology risks and audit best practices
Industry / Domain:
Holding
Necessary Knowledge and Experience:
- 4-7years of experience in IT auditing or IT risk
- Strong experience in IT general controls (ITGC), application controls, and security
- Knowledge of IT governance, cybersecurity, and infrastructure controls
- Experience in risk-based audit methodologies
Education and Certification Minimum Requirements:
- Bachelor’s degree in Information Technology, Computer Science, or related field
- Professional certifications, preferably holding CISA (Certified Information Systems Auditor) as highly preferred, in addition to CIA, CRISC, or CISSP.
Job Specific Technical Skills:
- ERP systems controls (Oracle, SAP)
- Data analysis tools (ACL, IDEA, Excel advanced)
- Understanding of cloud environments (Oracle Cloud, AWS, Azure)
- Knowledge of cybersecurity controls and risk assessment
- Strong analytical, reporting, and documentation skills