Search Jobs

Search by job, company or skills

Senior Manager, Information Technology (IT) Audit

Senior Manager, Information Technology (IT) Audit

Tranglo
  • Posted 12 hours ago
  • Be among the first 10 applicants

Job Description

Tranglo's business and operations are highly dependent on technology to support secure and reliable payment and remittance services. We are looking for an experienced Senior Manager, IT Audit to lead and oversee IT audits across the Group. The role will be primarily responsible for IT Audit and will also provide oversight of Operations Audit, which is led and managed by the Internal Audit Manager.

Roles and Responsibilities:

  • Maintain and enhance the IT audit universe by keeping abreast of changes in Tranglo's systems, technology infrastructure, cybersecurity environment and IT operations.
  • Develop and propose the annual IT audit plan and audit scopes based on key technology risks, business developments, regulatory requirements and emerging risks.
  • Lead, supervise and coach the IT audit team in planning and conducting audits covering areas such as IT governance, cybersecurity, system development and change management, user access management, infrastructure and network security, vulnerability management, data centre operations, business continuity and disaster recovery.
  • Assess the design and effectiveness of IT controls against applicable regulatory requirements, internal policies and recognised frameworks and standards, including COBIT, ITIL and ISO/IEC 27001.
  • Review audit work and reports to ensure that findings are adequately supported, risks are clearly articulated and recommendations are practical and appropriate to Tranglo's operations.
  • Lead audit exit meetings and discuss key findings, risks and recommendations with relevant management and auditees.
  • Monitor the remediation of IT audit findings and ensure that outstanding issues are appropriately followed up and escalated where necessary.
  • Provide oversight of Operations Audit, which is led by the Internal Audit Manager, including reviewing key audit scopes, significant findings and audit reports.
  • Present significant audit findings, key technology risks and the status of remediation actions to the Board Audit Committee and Board, where required.
  • Support other Internal Audit activities and perform ad-hoc reviews or assignments as required.

Requirements:

  • Minimum 10 years of relevant experience in either IT Audit, Information Security, Cybersecurity, IT Risk or IT Governance, preferably with significant internal audit experience.
  • At least one (1) relevant professional certification, such as CISA, CISSP, ISO/IEC 27001 Lead Auditor, CRISC, CompTIA, CREST, GPEN or equivalent. ISO/IEC 27001 Lead Auditor certification is preferred.
  • Good working knowledge of recognised IT governance, risk and control frameworks and standards, such as COBIT, ISO/IEC 27001 and ITIL.
  • Demonstrated experience in a supervisory or managerial role, including leading and developing teams conducting IT audits.
  • Good understanding of technology risks and controls relating to payment/remittance systems, cybersecurity, IT infrastructure, application systems and technology operations.
  • Knowledge of applicable Malaysian regulatory requirements, particularly Bank Negara Malaysia requirements relating to Money Services Business and Risk Management in Technology (RMiT), would be an advantage.
  • Strong analytical skills with the ability to identify key risks, assess control weaknesses and recommend practical improvements.
  • Strong written and verbal communication skills in English, with the ability to communicate audit matters effectively to senior management, the Board Audit Committee and the Board.
  • Experience in the financial services, payments, remittance or fintech is preferred.

More Info

Job Type:
Industry:
Function:
Employment Type:

Key Skills

About Company

Similar Jobs

10-12 yrs
Malaysia, Kuala Lumpur
Skills:
Enterprise Risk Management (ERM) frameworks and methodologies, policy development , Data Analysis, Preparing risk reports for senior management and regulators, Market conduct risk, Privacy impact analysis, Fraud risk, Digital risk and cybersecurity implications
8-10 yrs
Malaysia, Kuala Lumpur
Skills:
security automation , Cloud Infrastructure, Orchestration, Python, AI augmentation, DevOps toolsets, Security Architecture, security engineering, Cybersecurity domains
8-10 yrs
Malaysia, Kuala Lumpur
Skills:
Cism, Security Operations Incident Response, Cissp, Cisa, GICSP, Security Architecture Transformation, Threat Vulnerability Management, Data Protection Privacy
8-10 yrs
Malaysia, Kuala Lumpur
Skills:
Dlp, Siem, Iam, Pci Dss, BNM MCIPD, CIS Critical Security Controls, ISO IEC 27001, NIST Cybersecurity Framework, BNM RMiT, EDR
8-10 yrs
Malaysia, Kuala Lumpur
Skills:
Iso27001, Microsoft Power Bi, Automation Tools, DAX Functions, Cobit, Risk Analysis Methodologies, nist, Technology Risk Assessment