Audit Manager

Assurity Trusted Solutions

Singapore

On-site

SGD 70,000 - 100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Family Care Leave
Birthday Leave
Learning culture

Job summary

Assurity Trusted Solutions is looking for an Audit Manager to oversee audit processes and ensure risk coverage. Candidates must possess a degree in IT and professional certifications like CISA. The role demands at least 4 years of experience in the ICT field.

Responsibilities include managing audits, developing threat-informed perspectives, and contributing to policy feedback. A collaborative work environment with growth opportunities is highlighted along with attractive annual leave benefits.

Qualifications

  • Minimum of 4 years experience in ICT, with at least 2 years in ICT audit.
  • Experience conducting audit fieldwork and compliance management.
  • Strong written and verbal communication skills.

Responsibilities

  • Oversee audits and ensure coverage of risk areas.
  • Develop and apply threat-informed thinking across engagements.
  • Contribute to annual audit risk assessment and planning process.

Skills

Problem Framing
Systems Thinking
Threat-Informed Perspective
AI & Experimentation Fluency
Learning Orientation

Education

Degree in IT-related discipline
Professional certifications such as CISA

Job description

Assurity Trusted Solutions (ATS) is a wholly owned subsidiary of the Government Technology Agency (GovTech). As a Trusted Partner over the last decade, ATS offers a comprehensive suite of products and services ranging from infrastructure and operational services, authentication services, governance and assurance services as well as managed processes. In a dynamic digital and cyber landscape, where trust & collaboration are key, ATS continues to drive mutually beneficial business outcomes through collaboration with GovTech, government agencies and commercial partners to mitigate cyber risks and bolster security postures.

Key Responsibilities
PILLAR 1 — AUDIT EXECUTION (The "Engine")
  1. Oversee 4 audits as audit manager within the fiscal year, ensuring:
    • Coverage of critical risk areas informed by threat intelligence and systems criticality
    • Problem framing at the scoping stage: structuring audit objectives as risk hypotheses rather than control checklists — asking "what could go wrong and why" before asking "is this control in place"
    • Clear, concise articulation of findings as risk narratives connecting control gaps to broader exposure and downstream impact
    • Recommendations that address root causes, not just surface deficiencies
    • Timely issuance of reports as per planned timelines
  2. Apply data quality discipline during fieldwork — using standardised taxonomies and structured data capture to ensure findings feed Pillar 2's PRISM engine. Recognise that every audit engagement is simultaneously an intelligence-generation activity.
  3. Develop and apply threat‑informed thinking across audit engagements, building awareness beyond cyber controls to include:
    • Data risk: quality, lineage, and privacy dimensions
    • Resiliency risk: tested versus actual failover capability
    • Platform risk: third‑party and supply chain dependencies
    • Practice risk: how processes actually operate under pressure versus how they are documented
  4. Embrace AI and automation tools as core working methods:
    • Use the Unified Audit Automation Product (AI‑generated work programmes, Automated Control Testing, Generative Reporting, QA automation) as standard practice
    • Provide structured feedback on tool effectiveness to the Technology & Analytics horizontal
    • Adopt an experimentation mindset — willingness to try new approaches, learn from imperfect outputs, and iterate
  5. Score vendor performance on live engagements, contributing to Pillar 3's PRIME framework.
PILLAR 2 — AUDIT ANALYSIS (The "Brain")
  1. Contribute to the annual audit risk assessment and planning process by:
    • Identifying key risk trends across WoG, referencing industry threat intelligence and cybersecurity reports
    • Developing hypothesis‑driven audit objectives aligned with identified risks
    • Creating audit plans with procedures, timelines, and resources
  2. Participate in the systemic analysis of IM8 audits by:
    • Conducting analysis of IM8 audits from the preceding fiscal year, looking for patterns and shared root causes across engagements
    • Contributing to analysis outputs with clear systemic implications
    • Presenting analysis results to GovTech Seniors
  3. Contribute to the Policy Feedback Loop:
    • Provide evidence‑based observations to Policy Developers on IM8 policy effectiveness
    • Frame observations around implementation context and root causes
    • Support policy enhancement for emerging technology domains
  4. Build pattern recognition as a deliberate skill: during every audit engagement, actively ask "Is what I'm seeing here likely to exist elsewhere? What systemic condition would produce this finding?" — and route observations to Pillar 2's analysis function.
PILLAR 3 — IT AUDIT CAPABILITY DEVELOPMENT (The "Enabler")
  1. Contribute to the operationalisation of risk‑based auditing across WoG by:
    • Supporting training delivery to WoG auditors and agencies
    • Contributing to audit methodology maintenance and updates
    • Raising awareness through WoG briefings, newsletters, blogs, and community engagement
  2. Support the relevance of IM8 and audit methodology training, ensuring alignment with current policy and emerging risk themes.
  3. Identify opportunities for technology‑enabled improvement:
    • Assess where AI, automation, and analytics can enhance audit work
    • Support distribution and adoption of CDA's Unified Audit Automation Product
    • Treat technology adoption as an iterative learning process
  4. Stay current with emerging technologies, threat vectors, and trends in the audit and assurance profession — building the practitioner depth that underpins credible, threat‑informed audit work.
Qualifications
  • A degree in an IT‑related discipline or equivalent qualification
  • Professional certifications such as CISA and cloud security certification are essential
  • A minimum of 4 years of experience in the ICT field, with at least 2 years in ICT audit, assurance, and/or compliance management
  • Experience conducting audit fieldwork and understanding of regulatory compliance, governance, and internal controls
  • Experience in cyber security, cloud application development, or commercial public cloud platforms is advantageous
Mindset & Capabilities
  • Problem Framing: Willingness and developing ability to frame audit work around "what could go wrong and why" rather than defaulting to control checklists
  • Systems Thinking: Curiosity about how individual findings connect to broader conditions. Active habit of asking "Is this likely to exist elsewhere? What would cause this?"
  • Threat‑Informed Perspective: Awareness that risk extends beyond traditional IT controls to include data, resiliency, platform, and practice dimensions — and willingness to develop depth across these areas
  • AI & Experimentation Fluency: Comfort using AI and automation tools as standard working methods. Willingness to try new approaches, learn from imperfect outputs, and iterate. Experience with data analytics, audit automation, or generative AI is a valuable addition
  • Learning Orientation: This role is the foundational development point for deeper specialisation — candidates should demonstrate genuine curiosity and a growth mindset
  • Sound understanding of technology, IT management processes, technology risks, and internal controls
  • Strong written and verbal communication skills
  • Ability to deliver high‑quality, thorough work with attention to detail

Join us and discover a meaningful and exciting career with Assurity Trusted Solutions!

The remuneration package will commensurate with your qualifications and experience. Interested applicants, please click Apply Now.

We thank you for your interest and please note that only shortlisted candidates will be notified.

By submitting your application, you agree that your personal data may be collected, used and disclosed by Assurity Trusted Solutions Pte. Ltd. (ATS), GovTech and their service providers and agents in accordance with ATS’s privacy statement which can be found at: https://www.assurity.sg/privacy.html or such other successor site.

  • We promote a learning culture and encourage you to grow and learn.
  • Annual Leave Benefits with additional perks such as Family Care and Birthday Leave.
  • Working in a collaborative environment with helpful team members
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior IT Auditor
Senior IT Auditor

Assurity Trusted Solutions Pte Ltd • Singapore

On-site
SGD 90,000 - 150,000
Learning culture and professional成长
Annual leave and family care perks
Collaborative team environment
Senior IT Auditor
Senior IT Auditor

Jobtailor • Singapore

On-site
SGD 90,000 - 130,000
Threat Risk Cybersecurity Trainer
Threat Risk Cybersecurity Trainer

Assurity Trusted Solutions • Singapore

On-site
SGD 80,000 - 120,000
Encouragement for growth and learning
Engagement with government agencies
Lead Audit Manager
Lead Audit Manager

Assurity Trusted Solutions Pte Ltd • Singapore

On-site
SGD 100,000 - 130,000
Learning culture
Annual leave benefits
Collaborative work environment
Threat Risk Cybersecurity Trainer
Threat Risk Cybersecurity Trainer

Assurity Trusted Solutions Pte Ltd • Singapore

On-site
SGD 90,000 - 120,000
GovTech affiliation
Learning culture
Cybersecurity and AI Software Engineer
Cybersecurity and AI Software Engineer

Assurity Trusted Solutions Pte Ltd • Singapore

On-site
SGD 70,000 - 90,000
Annual performance bonus
Training budget
Benefits comparable to Permanent Employees
Cybersecurity Engineer (Solutioning and Architecture) - Multiple Headcounts
Cybersecurity Engineer (Solutioning and Architecture) - Multiple Headcounts

Assurity Trusted Solutions Pte Ltd • Singapore

Hybrid
SGD 90,000 - 130,000
Cybersecurity Engineer (GRC)
Cybersecurity Engineer (GRC)

Assurity Trusted Solutions Pte Ltd • Singapore

On-site
SGD 42,000 - 72,000
AI Engineer - 2 year contract
AI Engineer - 2 year contract

Assurity Trusted Solutions Pte Ltd • Singapore

Hybrid
SGD 60,000 - 90,000
Flexible work arrangements
Leave benefits
Employee wellness programs
Senior / Lead Offensive Cybersecurity Engineer (VAPT)
Senior / Lead Offensive Cybersecurity Engineer (VAPT)

Assurity Trusted Solutions Pte Ltd • Singapore

On-site
SGD 180,000 - 240,000
GovTech subsidiary
Learning culture