About the Role
Lead and manage the delivery of risk-based IT audits and special projects, aligning with policies, procedures, global internal audit standards, and regulatory requirements. Your role will include providing assurance and identifying technology risks, while building effective relationships across teams. Key competencies involve assessing and providing insights on Risk Management over IT and Cybersecurity controls, Resilience and Business Continuity controls, and Emerging Technologies like Blockchain and AI.
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
Responsibilities
Pre-Audit Planning:
- Develop and oversee the execution of the annual technology audit plan, ensuring alignment with IT governance, cybersecurity, and organizational risk strategies.
- Conduct IT risk assessments to identify key areas for review and develop comprehensive audit programs tailored to technology and digital risks.
- Lead opening meetings with executive IT management to discuss audit scope, objectives, and timelines for each technology audit engagement.
Audit Execution:
- Supervise and guide the technology audit team during the execution of IT audit assignments, ensuring compliance with IT audit standards, frameworks, and methodologies.
- Review and approve IT audit workpapers, ensuring they provide sufficient factual, reliable, relevant, and useful information to support audit findings.
- Evaluate the effectiveness of IT controls, IT infrastructure, Cloud environments, cybersecurity measures, data privacy compliance, and IT governance, providing recommendations for improvement.
- Oversee the documentation of IT-related issues raised, management responses, and ensure accurate reflection in audit reports.
Post-Audit Activities:
- Lead the drafting of comprehensive IT audit reports, summarizing key findings, technology risks, and recommendations for senior management and the Audit and Risk Committee.
- Ensure timely follow-up on IT audit recommendations and validate the implementation of corrective actions by management.
Communication and Coordination:
- Develop and manage relationships with senior management, colleagues, and relevant external parties to discuss current and future issues, ensuring their requirements and concerns are addressed.
- Coordinate with IT risk management, cybersecurity teams, and other risk assurance functions for a cohesive approach to IT governance, risk, and compliance.
- Communicate IT audit progress, results, and insights to key stakeholders, ensuring transparency and alignment with technology risk management objectives.
Compliance and Professional Standards:
- Ensure compliance with the group’s policies, procedures, and guidelines along with all relevant regulatory and statutory requirements to protect the organization’s interests at all times.
Requirements
- Bachelor’s or master’s degree in computer science, Information Systems Management, or other related fields.
Professional Certificates
- One or more industry-recognized audit, security, cloud, or emerging technology professional certifications (e.g., CISA, CISSP, CRISC, CIA, CCSSP, CISM).
Experience
- At least 10-12 years of experience in internal or external audit (IT Audit).
- Good understanding of fintech/banking concepts, products, and procedures.
- Solid understanding of AI, with practical experience in a fintech/banking environment.
- Strong grasp of local laws, regulations, international frameworks, and best practices.
Technical Skills & Competencies
- Technical: Specialist knowledge of IT infrastructure, Networking, Information Security, Cybersecurity, Cloud Security, Data Privacy, Data Security, Blockchain/Cryptocurrency, Artificial Intelligence, and Risk Management.
- Management & Leadership: Skills in negotiation & influencing, thought leadership, project management, team management, skills gap identification, and junior staff motivation and development.
- Interpersonal: Proficient in oral & written communication, relationship development & management, organization & time-management, adaptability & multi-tasking.