Management and boards of directors rely heavily on internal audit to provide important proactive assessments and assurance around the effectiveness of controls and company processes, while also providing objective advisory support. In the new digital economy, technology will play an increasingly important role in every company's governance framework.
As an IT internal audit professional, you'll be leading engagements to identify technology control enhancements, IT operational and compliance process improvement and efficiency opportunities, as well as company-wide cost improvements. EY is a global leading service provider in this space, with a reputation for high quality and cost-effective innovative offerings.
Our structured career framework means you'll continue to develop, whatever level you're at. And with a network stretching around the globe, you'll gain valuable insight across industries and geographies.
The opportunity
As part of our IT internal audit team, you'll focus on client opportunities where your expertise can make a substantial impact. You'll apply your knowledge and experience to shape our services and motivate your team. You'll build valuable relationships with clients and develop strong capabilities, through both formal training and working with senior mentors and talented colleagues.
Your key responsibilities
As a Manager within the IT internal audit team, you will provide guidance and share knowledge with team members and participate in performing procedures especially focusing on complex, judgmental and/or specialized issues. You will work with the team and the client to create plans for accomplishing engagement objectives and a strategy that complies with professional standards and addresses the risks inherent in the engagement.
Skills and attributes for success
- Brief the engagement team on the client's IT environment and industry IT trends
- Maintain relationships with client management and stakeholders to manage expectations of service, including work products, timing and deliverables
- Demonstrate a thorough understanding of complex information systems and apply it to client situations
- Use extensive knowledge of the client's business/industry to identify technological developments and evaluate impacts on the client's business
- Demonstrate excellent project management skills, inspire teamwork and responsibility with engagement team members
- Lead and manage end-to-end IT internal audit and advisory engagements, including planning, fieldwork, reporting, and follow-up activities
- Develop risk-based IT internal audit plans aligned to client's organizational objectives, emerging risks, and regulatory requirements
- Evaluate the design and operating effectiveness of IT and cybersecurity controls across key technology domains, including cybersecurity, cloud computing, ERP systems, data governance, and third-party risk management
- Manage engagement budget, timeline and quality of deliverables
- Write clear, concise and objective audit reports, incorporating key aspects such as engagement objectives, scope, findings, risk implications, root causes and recommendations
- Review and challenge audit findings, root cause analyses, and management action plans to ensure practical and sustainable remediation
- Present audit observations, risk implications, and recommendations to senior management, Internal Audit leadership, Audit Committees, and Boards where required
- Monitor engagement quality and ensure compliance with EY methodology, IIA Standards, and client internal audit frameworks
- Understand EY and its service lines and actively assess what the firm can deliver to serve clients
To qualify for the role, you must have
- A university degree or equivalent professional qualification in accounting, business, information technology, or a related discipline
- At least 6 years of relevant experience, including a minimum of 4 years in IT audit or IT risk consulting within a public accounting firm, professional services firm, or industry environment.
- Ability to travel up to 20% of the time
- Significant experience in applying relevant technical knowledge in several of the following areas:
- (a) IT general controls review
- (b) Infrastructure review
- (c) Application controls review
- (d) Cybersecurity review
- (e) Digital transformation governance review
- (f) Artificial Intelligence (AI) governance and controls assessment
- (g) ERP security and control review (e.g., SAP, Oracle, Workday)
- (h) Cyber incident response and recovery readiness assessment
- (i) Third-party technology and outsourcing risk review
- (j) IT project and system implementation assurance review
- (k) DevSecOps and secure software development lifecycle review
- (l) Identity and Access Management (IAM) assessment
- (m) Privileged Access Management (PAM) review
- (n) Cloud security review
- (o) Data protection and data privacy review
- (p) Business continuity and IT disaster recovery review
- (q) IT /