Senior Information Technology Auditor
الوصف الوظيفي
About the Role
We are seeking a highly skilled and experienced Senior Information Technology Auditor to join our team. In this critical role, you will play a pivotal part in safeguarding our organization’s digital assets by conducting comprehensive technology and cybersecurity audits. Your expertise will be instrumental in evaluating the effectiveness of IT governance frameworks, information security controls, cyber resilience strategies, infrastructure, applications, cloud environments, and technology operations. As an independent assurance professional, you will ensure that technology risks are proactively managed and that all regulatory requirements are fully met, thereby reinforcing the integrity and security of our IT ecosystem.
Key Responsibilities
The Senior Information Technology Auditor will be responsible for the following core functions:
- Audit Planning and Execution: Develop and execute technology and cybersecurity audit plans in alignment with the approved annual audit schedule, ensuring comprehensive coverage of critical IT domains.
- Control Assessment: Evaluate the design and operational effectiveness of IT General Controls (ITGCs) and application-specific controls to identify vulnerabilities and ensure robust security postures.
- Cybersecurity Governance Review: Assess cybersecurity governance frameworks, including identity and access management, network security, endpoint security, cloud security, vulnerability management, incident response protocols, and security monitoring mechanisms.
- Infrastructure and Platform Evaluation: Conduct thorough assessments of IT infrastructure components, including databases, operating systems, cloud platforms, and disaster recovery/business continuity controls to ensure resilience and compliance.
- Regulatory Compliance: Verify adherence to regulatory requirements, internal policies, and industry-recognized standards such as the SAMA Cyber Security Framework, NCA ECC, ISO 27001, and NIST guidelines.
- Risk Identification and Mitigation: Perform detailed risk assessments to identify control gaps, recommend actionable improvements, and enhance the overall security posture of the organization.
- Reporting and Communication: Prepare clear, concise, and actionable audit working papers, reports, and presentations for senior management, ensuring transparency and accountability in risk management efforts.
- Follow-Up and Validation: Monitor the implementation of audit findings and validate the effectiveness of agreed-upon action plans to ensure sustained improvements.
- Specialized Support: Provide expert guidance and support for investigations, special reviews, and advisory engagements related to technology and cybersecurity, addressing emerging challenges and evolving threats.
- Continuous Learning: Stay abreast of the latest cyber threats, technological advancements, and leading audit methodologies to maintain a cutting-edge approach to IT risk management.
Requirements and Qualifications
To excel in this role, candidates must meet the following criteria:
- Educational Background: A Bachelor’s degree in Computer Science, Information Technology, Cyber Security, Information Systems, or a closely related discipline is required.
- Professional Certifications: Relevant certifications such as CISA, CISSP, CRISC, or CISM are highly desirable and will be considered a significant advantage.
- Professional Experience: A minimum of 7 to 10 years of hands-on experience in IT Audit, Cyber Security Audit, Information Security, or Technology Risk management is essential. Experience within the banking, financial services, or a regulated environment is particularly valued.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.