Search by job, company or skills

IT Audit Manager

Early Applicant
  • Posted 20 days ago
  • Be among the first 10 applicants

Job Description

About the job

Join Our Family Today.

Together, We'll Make Travel Better.

We are seeking a highly capable IT Audit professional to lead and execute risk-based IT audit activities across the Group. This role operates in a dynamic, multicultural environment and partners closely with global business and technology stakeholders to assess risk, strengthen internal controls, and support continuous improvement. Reporting to the Global Director, Internal Audit & Corporate Governance, the successful candidate will work independently across assigned business areas while contributing to the broader internal audit agenda.

What You'll Be Doing:

  • Develop, maintain, and continuously enhance the Group's IT audit framework in alignment with the organisation's technology landscape, risk profile, and control environment.
  • Plan, scope, and execute risk-based IT audits covering IT general controls, applications, system implementations, change management, cybersecurity, data security, and related technology processes.
  • Assess the design and operating effectiveness of IT controls, identify control gaps and emerging risks, and provide practical recommendations to improve governance, efficiency, and control effectiveness.
  • Lead or support internal audit engagements and IT advisory reviews, including audit planning, fieldwork, testing, documentation, reporting, and stakeholder discussions.
  • Prepare clear, concise, and actionable audit reports for management, and monitor the timely implementation of agreed corrective actions through follow-up reviews.
  • Collaborate with business and functional teams across the Group to promote strong control awareness, support change initiatives, and drive process improvements.
  • Keep abreast of evolving technology risks, regulatory requirements, and industry best practices to strengthen audit coverage and provide relevant insights to stakeholders.

What You'll Need:

  • Bachelor's degree in Information Technology, Information Systems, Accounting, Finance, Computer Science, or a related discipline.
  • At least 6 years of relevant experience in internal audit, external audit, IT audit, IT risk, or a related assurance function.
  • Professional certifications such as CISA, CIA, CPA, CISM, CISSP, or equivalent are preferred.
  • ISO/IEC 27001 Lead Auditor certification is strongly preferred.
  • Strong knowledge of IT general controls, cybersecurity risk, system implementation reviews, change management, data protection, and risk-based audit methodologies.
  • Practical experience with relevant governance, risk, and compliance standards or frameworks such as GDPR, ISO 27001, COBIT, NIST, or equivalent is an advantage.
  • Practical experience in cloud security audit and assessment across AWS, Azure, and Alibaba Cloud is a definite advantage.
  • Solid experience on PCI DSS, ISO/IEC 27001:2022 and SOC Type 2 security audit assessment with internal stakeholders, bank, airline and external audit firms. Able to recommend Corrective Action request and remediation plan.
  • Strong analytical, report-writing, and stakeholder management skills, with the ability to communicate effectively across business and technology teams.
  • Fluency in English is required; proficiency in both spoken and written Chinese (Putonghua and Cantonese) is highly advantageous.
  • Able to work independently in a fast-paced, multicultural environment and manage multiple priorities effectively.

More Info

Job Type:
Industry:
Function:
Employment Type:

About Company

Job ID: 150799285

Similar Jobs

Malaysia, Kuala Lumpur

Skills:

SpotfireData AnalyticsTableauACLSqlSOX integrated auditsproject managementERP security and controls reviewsIt AuditISAE 3402 engagementsIdealfinancial statement auditsinternal or operational audits

Kuala Lumpur

Skills:

it auditor information technology audit information security management system Iso 27001Iso27001IsmsCybersecurityInformation SecurityCloud SecurityNetwork SecurityIt AuditInternal IT AuditBankingInsuranceBfsi

Malaysia, Kuala Lumpur

Skills:

it controls It InfrastructureCismInformation SecurityCybersecurityCloud ComputingCisspIt AuditCisa

Malaysia, Kuala Lumpur

Skills:

containerization CybersecurityAgile DevelopmentData PrivacyIdentity And Access ManagementRpaApi ManagementIt InfrastructureIt OperationsData GovernanceAI governanceIT governance and risk managementResilienceData analytics capabilityTransformation and programme project managementApplication development and changeCloud PaaS IaaS and SaaSThird party management