IT Audit

Emdad By Elm
الرياض, الرياض دوام كامل
نشر: 1448/1/22 | 2026/07/07 ينتهي: 1448/2/23 | 2026/08/06 ✨ وصف بالذكاء الاصطناعي
تقدم للوظيفة الآن

الوصف الوظيفي

About the Role

The Associate Principal – IT & Cyber Audit plays a pivotal role in strengthening the organization’s internal audit function by delivering independent and objective assurance over IT systems, cybersecurity controls, and digital transformation initiatives. This position is instrumental in evaluating the robustness of IT governance frameworks, information security protocols, cyber resilience strategies, and technology-driven processes to ensure full compliance with regulatory mandates, internal policies, and strategic business objectives. By identifying control gaps and mitigating technology-related risks, the role enhances stakeholder confidence in the integrity and security of digital services and platforms, fostering a resilient and trustworthy operational environment.

Core Responsibilities

  • Audit Planning and Execution: Develop and implement comprehensive IT and cybersecurity audit plans in alignment with the approved internal audit strategy and established methodologies. Ensure audits are conducted efficiently, systematically, and in accordance with professional standards.
  • Control Assessment and Evaluation: Conduct thorough evaluations of general IT controls (ITGCs), application-level controls, and cybersecurity frameworks across diverse systems, platforms, and IT infrastructure. Assess the effectiveness of controls in mitigating risks and safeguarding organizational assets.
  • Regulatory and Framework Compliance: Perform assessments against recognized frameworks and standards, including NCA, ISO 27001, and COBIT, to verify adherence to industry best practices and regulatory requirements.
  • Reporting and Recommendations: Prepare meticulously documented audit reports that clearly articulate observations, root causes, associated risks, and actionable recommendations. Ensure findings are communicated in a manner that is both accessible and impactful to stakeholders at all levels.
  • Issue Tracking and Follow-Up: Monitor the implementation of management action plans to ensure timely and effective resolution of audit issues. Conduct follow-up reviews to validate the sustainability of remediation efforts and the closure of identified gaps.
  • Stakeholder Engagement: Collaborate closely with IT, cybersecurity, and business teams to gain deep insights into system architectures, operational processes, and emerging risk exposures. Serve as a trusted advisor during the design and implementation of new systems, digital initiatives, and large-scale IT projects.
  • Knowledge Management and Innovation: Stay abreast of evolving technology trends, emerging cyber threats, regulatory updates, and advancements in audit methodologies. Contribute to the continuous improvement of IT audit tools, techniques, and frameworks to enhance audit quality and efficiency.

Qualifications and Competencies

To excel in this role, candidates must possess the following qualifications and professional attributes:

  • Education: A bachelor’s degree in Information Technology, Computer Science, Information Systems, Cybersecurity, or a closely related discipline.
  • Professional Experience: Demonstrated experience in IT audit, cybersecurity, risk management, or technology assurance within complex organizational environments. Prior exposure to government, regulated industries, or large-scale enterprises is highly advantageous.
  • Technical Proficiency: In-depth knowledge of IT General Controls (ITGCs), cybersecurity frameworks, cloud and digital platforms, Identity and Access Management (IAM), data protection and privacy controls, Governance, Risk, and Compliance (GRC) tools, and audit analytics.
  • Soft Skills: Exceptional analytical and critical thinking capabilities, coupled with the ability to articulate complex technical concepts in clear, concise written and verbal communications. Strong stakeholder management skills and a collaborative approach are essential for building consensus and driving meaningful change.
  • Professional Certifications: While not mandatory, possession of one or more of the following certifications is considered a significant advantage: CISA (Certified Information Systems Auditor), CISM (Certified Information Security Manager), CRISC (Certified in Risk and Information Systems Control), or ISO 27001 Lead Auditor/Implementer.

يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.

المصدر: لينكد إن ↗ • 12 مشاهدة

وظائف مشابهة

تقدم للوظيفة الآن