KEY RESPONSIBILITIES
- Plan, lead and execute comprehensive IT audits, including the development of audit scope, objectives and audit programmes, covering IT general controls, application systems, infrastructure, networks, cybersecurity, data centres, system development and change management, IT operations, business continuity and disaster recovery.
- Evaluate the design and operating effectiveness of IT controls, identify control deficiencies, determine root causes and assess their impact on the organization.
- Prepare and review audit working papers to ensure audit procedures, evidence, conclusions and findings are adequately documented and comply with Internal Audit methodology, policies and applicable professional standards.
- Prepare clear, concise and accurate audit reports, communicate significant findings to relevant stakeholders, and obtain appropriate management action plans and target completion dates.
- Perform follow-up on audit observations, including validation of corrective actions and supporting evidence before recommending closure.
- Participate in and/or conduct ISMS internal audits in accordance with the organization's Information Security Management System requirements and applicable standards, including ISO/IEC 27001, and report nonconformities, observations and opportunities for improvement.
- Support the annual IT audit planning process and keep abreast of developments in technology, cybersecurity, information security and applicable regulatory requirements.
QUALIFICATIONS
- Bachelor's Degree in Information Technology, Computer Science, Information Systems or a related discipline.
- Professional certification such as CISA, CIA, CISSP, CRISC or other relevant certification is an added advantage.
- Knowledge of IT audit methodologies, internal auditing, IT general controls, COBIT, information security practices and applicable professional standards.
- Knowledge of ISO/IEC 27001 and ISMS internal audit requirements is an added advantage.
- Minimum 5 years of relevant working experience in IT audit, internal audit, information security, technology controls or a related field.
- Hands-on experience in auditing IT general controls, application systems, infrastructure, networks, cybersecurity, data centres, system development/change management, IT operations, business continuity and disaster recovery.
- Experience in ISMS and/or ISO/IEC 27001 internal audits is an added advantage.
- Experience in preparing audit working papers, developing audit findings, preparing audit reports and following up on corrective actions.
- Experience in leading audit assignments and reviewing the work of audit team members is preferred.
REQUIRED COMPETENCIES & SKILLS
- Strong knowledge of IT auditing, IT general controls, information security and internal control principles.
- Good understanding of COBIT, ISO/IEC 27001, ISMS requirements and applicable IT governance and security standards.
- Strong analytical, problem-solving and root-cause analysis skills.
- Good audit documentation and report-writing skills.
- Strong communication, interpersonal and stakeholder management skills.
- Ability to lead audit assignments and guide audit team members.
- Ability to manage multiple assignments and meet established timelines.
- Good professional judgment, integrity, objectivity and attention to detail.
- Ability to work independently and collaboratively within the Internal Audit team.
WHY JOIN US
- Comprehensive medical benefits for you, your spouse, and children, ensuring your well-being is our top priority.
- Rest easy with our group term life coverage, providing you with security and assurance.
- Stay energized with meal credit that keep you fueled throughout the day.
- An in-house futsal court and badminton court for post-work workouts.
- A variety of fun-filled events and gatherings to unwind.
- Achieve a healthy work-life balance, ensuring you thrive both in and out of the office.