Job Search and Career Advice Platform

Enable job alerts via email!

IT Audit Associate 3

Ernst & Young Advisory Services Sdn Bhd

Johannesburg

On-site

ZAR 500 000 - 700 000

Full time

Yesterday
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A global leader in advisory services seeks an IT Audit Associate 3 in Johannesburg, South Africa. The role focuses on executing IT audit services, with a significant emphasis on cybersecurity audits. Candidates should possess a minimum of three years of IT audit experience and a bachelor's degree in a relevant field. Strong analytical and communication skills are essential, alongside knowledge of cybersecurity tools and regulatory frameworks. The position offers competitive career development within a structured framework.

Qualifications

  • Minimum 3 years of IT audit experience, with exposure to cybersecurity audits.
  • Certifications: CISA preferred, CEH, CISSP or ISO 27001 Lead Auditor advantageous.

Responsibilities

  • Plan and execute audits of IT systems, networks, and applications.
  • Review and assess cybersecurity frameworks adherence.
  • Conduct penetration testing and vulnerability assessments.
  • Evaluate user access management and change management processes.
  • Prepare audit reports with actionable recommendations.

Skills

Strong analytical and problem-solving skills
Excellent communication and report-writing skills
Ability to work independently and manage multiple audits
High ethical standards and attention to detail

Education

Bachelor’s degree in Information Technology or related field

Tools

Cybersecurity tools (Firewalls, IDS/IPS, VPN, DLP)
IT audit methodologies and frameworks (COBIT, ITIL)
Data analytics for audit testing
Job description
Technology Consulting, IT Audit Associate 3

Our national practice assists clients in providing IT audit services in support of our financial audits. We also provide IT governance and IT risk related services to a variety of clients and particularly in the Financial Services, Oil & Gas, Retail and government sectors.

The opportunity

Our structured career framework means you’ll continue to develop, whatever level you’re at. So, whenever you join, however long you stay, the exceptional EY experience lasts a lifetime.

Key Responsibilities
  • Cybersecurity Audits
  • Plan and execute audits of IT systems, networks, and applications to identify vulnerabilities and compliance gaps.
  • Review cybersecurity frameworks (e.g., NIST CSF, ISO 27001) and assess adherence.
  • Conduct penetration testing and vulnerability assessments where applicable.
  • IT General Controls (ITGC)
  • Evaluate user access management, authentication, and privilege controls.
  • Review change management, backup, and disaster recovery processes.
  • Perform risk-based audits aligned with regulatory requirements (e.g., DORA, NIS2, PCI DSS).
  • Prepare audit reports with actionable recommendations for remediation.
  • Participate in cyber incident simulations and wargaming exercises.
  • Advise on IT governance, cyber risk management, and business continuity planning.
  • Stakeholder Engagement
  • Collaborate with IT, security, and business teams to implement audit findings.
  • Communicate technical risks in clear, business-friendly language.
Core Skills & Attributes
  • Strong analytical and problem-solving skills.
  • Ability to work independently and manage multiple audits simultaneously.
  • Excellent communication and report-writing skills.
  • High ethical standards and attention to detail.
Technical Skills
  • Knowledge of cybersecurity tools and technologies (Firewalls, IDS/IPS, VPN, DLP).
  • Familiarity with IT audit methodologies and frameworks (COBIT, ITIL).
  • Proficiency in data analytics for audit testing.
  • Understanding of cloud security and emerging cyber threats.
Qualifications
  • Minimum 3 years of IT audit experience, with exposure to cybersecurity audits.
  • Bachelor’s degree in Information Technology, Computer Science, or related field.
  • Certifications: CISA (Certified Information Systems Auditor) preferred, CEH, CISSP or ISO 27001 Lead Auditor advantageous.
Additional Specialised Skills
  • Experience in regulatory compliance audits (SOX, ISAE 3402).
  • Knowledge of cyber risk assessment and governance frameworks.
  • Sound knowledge of cybersecurity frameworks and practices, with the ability to apply standards such as ISO 27001 and ethical hacking principles.
  • Excellent analytical, interpersonal, communication, writing, and presentation skills.
About EY

About EY
As a global leader in assurance, tax, transaction and advisory services, we hire and develop the most passionate people in their field to help build a better working world. This starts with a culture that believes in giving you the training, opportunities and creative freedom to make things better. So that whenever you join, however long you stay, the exceptional EY experience lasts a lifetime

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.