Company logo hidden

IT Audit Specialist

Unlock employer Dubai, United Arab Emirates Direct to Company 1 hour ago · 09 Oct 2026

Financial

  • Estimate: $60k - $100k*
  • Zero income tax location

Accessibility

  • Office Only
  • Visa Provided

Requirements

  • Experience: Intermediate
  • English: Professional

Position

About the Job
At the company, you’ll deliver independent, evidence-led IT audit work that helps strengthen the security, reliability, and governance of the technology supporting our international business.
This is a hands-on individual contributor role focused on technology and cybersecurity assurance. You’ll examine technical controls, analyze system evidence, investigate weaknesses, and develop clear findings that explain their business impact.
Working with IT audit managers and colleagues, you’ll take ownership of assigned audit work across infrastructure, cloud environments, applications, engineering processes, and operational resilience. You’ll also support integrated reviews with regulatory and operational auditors.

Ready to apply for roles like this?

Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.

Unlock employer & apply directly

Why This Matters
The company's mission is Trading for Anyone, Anywhere, Anytime. Millions of traders, around the clock, across regulatory regimes. Real money, real regulations, real consequences. The technology behind that has to be secure, resilient, and provably well controlled.
Auditing it means going to the evidence, not the policy document. We are building audit that is proactive, not annual.

Why the company
We're in production, not planning.

  • 65%+ of customer enquiries resolved by AI, with genuine judgment, not decision trees
  • Automated security review on every pull request
  • 400+ users on our internal workflow orchestration platform
    You'll audit a technology estate that is already running AI in production, and you'll help shape how it gets assured. We share what we learn at the company (derivai.substack.com).

What You’ll Do

  • Plan IT audit work, support technology risk assessments, system and process walkthroughs, and develop audit scope, objectives, and testing programmes.
  • Test technology and cybersecurity controls, assessing identity and privileged access management, infrastructure and network security, vulnerability management, security monitoring, incident response, and third-party technology controls.
  • Review cloud and engineering practices, performing assigned tests of cloud configurations, secure development, CI/CD pipelines, change management, application security, and secrets management.
  • Assess application and data controls, testing automated business controls, interfaces, data integrity and protection, and relevant governance and controls for AI-enabled systems.
  • Evaluate technology resilience by reviewing backup and recovery, disaster recovery testing, service availability, and technology dependencies supporting business continuity.
  • Analyze technical evidence by examining configurations, access records, logs, change histories, and test results; investigate exceptions and assess their risk, root cause, and any compensating controls.
  • Document and communicate findings by maintaining clear, reproducible working papers and drafting findings that explain the evidence, business impact, and practical recommendations.
  • Validate remediation by reviewing closure evidence and retesting controls where appropriate, escalating inadequate fixes, delays, or unresolved issues to the audit manager.
  • Work constructively with stakeholders; discuss systems and observations with engineering, security, and technology teams while maintaining independence, confidentiality, and professional skepticism.
  • Improve audit delivery and build expertise using analytics, scripts, automation, and responsibly governed AI tools to improve testing. Stay current with technology risks and audit standards. Senior specialists will lead defined workstreams and support less-experienced auditors.

Who You Are

  • Relevant IT audit or technology assurance experience, ideally in regulated financial services, fintech, or another technology-intensive environment.
  • Practical experience testing IT controls, assessing technical evidence, and documenting audit conclusions. Experience in cybersecurity, cloud, or engineering assurance is an advantage.
  • A working understanding of cloud environments, infrastructure, cybersecurity, identity and access management, software development, application controls, and technology resilience, with deeper capability in one or more areas.
  • The ability to examine system evidence directly and distinguish an effectively operating control from a documented policy or an unsupported explanation.
  • Knowledge of risk-based auditing, the IIA Global Internal Audit Standards, and ISACA IT audit guidance, with familiarity with relevant frameworks such as COBIT, NIST, and ISO/IEC 27001.
  • The ability to translate technology risks and applicable regulatory requirements into practical audit tests and explain technical weaknesses in business terms.
  • Strong analytical skills, attention to detail, and curiosity to investigate inconsistencies and understand root causes.
  • The ability to manage assigned work and meet deadlines. Senior specialists should be able to deliver defined IT audits or complex workstreams with limited supervision, subject to managerial review.
  • Excellent written and spoken English, including the ability to produce clear working papers and discuss findings with technical and non-technical stakeholders.
  • A relevant degree in information systems, computer science, cybersecurity, or a related discipline. CISA, CIA, or an equivalent relevant audit qualification is preferred.
  • Demonstrable interest in and practical use of data analysis, scripting, automation, or AI to improve work, supported by confidentiality safeguards and validation of outputs.

What Success Looks Like
Thorough technical testing delivered on time, reliable evidence supporting every conclusion, clear findings that identify meaningful technology risks, and remediation validated through evidence rather than assurances alone.

The Honest Reality
This is demanding work. You'll deliver findings that engineering and security teams won't always welcome, and you'll defend them with evidence. You'll balance thoroughness with relationships, and make calls on risk with incomplete data.
But you'll audit real systems handling real transactions, and your conclusions will carry weight. If you want to check policies against checklists, this isn't it. If you want to test what actually runs, it might be.

Apply Direct

Jobs you might like   View all jobs

About Financial Services Company

Company details are hidden. Subscribe to view full company profile.

Ready to apply for this role?

Apply Direct