What the role is:
You lead and manage a team of auditors in conducting IT governance, systems, and process audits to evaluate and enhance the effectiveness of IT risk management, controls, and governance within the Ministry of Defence (MINDEF) and the Singapore Armed Forces (SAF). This includes assessing control environments in computer applications and providing management with analysis, appraisals, and recommendations on reviewed IT systems, as well as advising on IT security and controls during the development of new systems.
What you will be working on:
- Plan, direct, organise and manage audits of IT systems and processes
- Establish long-range and short-range audit plans
- Develop and train staff to achieve IT audit professionalism and keep abreast of new technology across various digital platforms
- Determine areas of IT risks and appraise their significance in relation to operational factors of cost, schedule and resources
- Define audit projects according to degree of risk, significance, and frequency of coverageReview and approve audit programmes encompassing the purpose, scope, and audit approach for each audit project
- Ensure that audits adhere to established audit standards and objectives
- Review work done by staff to ensure findings are accurate and objective and that recommendations are constructive and practical
- Implement a monitoring and reporting system to ensure proper and adequate follow-up actions are taken by auditees
- Contribute advisory services with regard to the development of new IT policies, systems and processes in MINDEF/SAF to relevant agencies where necessary
Challenge(s):
- Keeping abreast of emerging trends and changes in auditing techniques, the business and IT environment, and the regulatory framework, while harnessing Data Analytics (DA), Artificial Intelligence (AI) and auditing tools in the course of audit work and integrating governance, risk and compliance as an integral part of the IT audit process and methodology
- Navigating the increasing complexity of audit services brought about by the infusion of DA, AI and RPA into many processes, requiring the ability to understand diverse issues, draw insights from data, and recommend improvements to organisational practices
- Understanding the different AI risks, cybersecurity risks and cyber-attack techniques in order to devise audit strategies that assess and address their implications to the areas under review
What we are looking for:
- Education in Computer Science or a related discipline is preferred
- At least 15 years of relevant experience in IT auditing or IT security
- Sufficient understanding of hardware, software operating systems, computer operations, systems analysis and design, cybersecurity, cloud technology, RPA and AI
- Certified Information Systems Auditor (CISA) certification is required
- Possession of additional certifications such as Certified in Risk and Information Systems Control (CRISC), Cybersecurity Practitioner (CSX) or Certified Information Systems Security Professional (CISSP) is advantageous
- Knowledge of SAP is advantageousOnly shortlisted candidates will be notified.
About MINDEF
The mission of MINDEF and the Singapore Armed Forces is to enhance Singapore's peace and security through deterrence and diplomacy, and should these fail, to secure a swift and decisive victory over the aggressor. The Defence Executive Officer (DXO) scheme is the non-uniformed career scheme of MINDEF that offers myriad opportunities in various job functions, such as corporate communications, cyber security, data analytics and visualisation, defence policy, finance, HR, psychology, and more. Embodying the same level of commitment towards defence, DXOs work together with their military counterparts to contribute to MINDEF/SAF’s mission and ensure Singapore's security and stability. United by this common cause, our lines of defence complement each other to secure the prosperity and progress of our nation.