Assurity Trusted Solutions (ATS) is a wholly owned subsidiary of the Government Technology Agency (GovTech). As a Trusted Partner over the last decade, ATS offers a comprehensive suite of products and services ranging from infrastructure and operational services, authentication services, governance and assurance services as well as managed processes. In a dynamic digital and cyber landscape, where trust & collaboration are key, ATS continues to drive mutually beneficial business outcomes through collaboration with GovTech, government agencies and commercial partners to mitigate cyber risks and bolster security postures.
Key Responsibilities
- Develop and tailor audit programmes, security audit checklists, and assessment methodologies to evaluate the design and operating effectiveness of internal controls in mitigating ICT risks.
- Plan, design, and execute policy risk‑based audits, process audits, and technical audits of systems, applications, and supporting infrastructure.
- Manage stakeholder engagements with agencies throughout the audit lifecycle, including audit planning, briefings, fieldwork, management discussions, response reviews, and follow‑up activities, to ensure timely and effective delivery of audit plans.
- Review and evaluate audit observations to assess the overall state of ICT governance, risk management, and control practices across agencies and the Whole‑of‑Government environment.
- Develop practical and risk‑based recommendations and mitigation measures to strengthen ICT governance, security, and control effectiveness.
- Collaborate with stakeholders at both operational and managerial levels to assess issues, identify root causes, and formulate recommendations to address identified gaps.
- Monitor and validate the implementation of corrective actions to ensure audit findings have been effectively remediated and underlying root causes adequately addressed.
- Plan, procure, and actively manage outsourced audit resources and augmentation services to ensure the successful delivery of committed audit outcomes and deliverables.
- Conduct ICT&SS audits of Government agencies as assigned by GovTech’s Internal Audit Division (IAD). Perform in‑depth reviews of Government agencies’ ICT&SS processes, applications, systems, and supporting infrastructure.
- Facilitate the reporting and maintenance of audit findings in the designated central audit repository.
- Manage end‑to‑end audit engagements, engage effectively with stakeholders across multiple agencies, and provide assurance over the adequacy and effectiveness of ICT governance, risk management, and control frameworks.
Qualifications
- At least 6 years of relevant experience in IT audit, with a proven track record of delivering audit engagements.
- Proven experience leading end‑to‑end IT audit engagements, including planning, fieldwork, reporting and follow‑up.
- Strong understanding of cybersecurity principles, risk assessment, regulatory requirements, threats, vulnerabilities and security governance.
- Experience assessing IT governance, controls and processes against recognised frameworks and standards such as COBIT, ITIL, NIST and ISO/IEC 27001.
- Familiarity with IM8 and/or equivalent ICT governance and security policies would be advantageous.
- Experience in cloud computing (AWS, Azure, GCC), SaaS environments, application security or application development would be advantageous.
- Strong communication, stakeholder management, influencing and project planning skills.
- Possession of professional certifications such as CISA, CISSP, CISM, CRISC or equivalent would be advantageous.
Benefits
- We promote a learning culture and encourage you to grow and learn.
- Annual Leave Benefits with additional perks such as Family Care and Birthday Leave.
- Working in a collaborative environment with helpful team members.
Join us and discover a meaningful and exciting career with Assurity Trusted Solutions!
The remuneration package will commensurate with your qualifications and experience.