Job Vacancy: IT Audit Specialist
We are seeking an experienced IT Audit Specialist to deliver risk-based technology audits and advisory reviews across the Group, assessing governance, applications, infrastructure, and key controls, and providing practical recommendations that strengthen compliance, resilience, and performance.
Key Responsibilities
- Plan and execute IT audit engagements (IT governance, project reviews, and pre/post implementation assessments).
- Test IT General Controls (and IT application controls where applicable), including access, change, operations, backup/recovery, and incident management.
- Perform walkthroughs and business process testing where technology controls impact financial reporting, compliance, and operations.
- Develop risk assessments, audit programs, and workpapers in line with internal audit standards; identify control gaps, fraud indicators, and emerging risks.
- Draft clear reports, present results to stakeholders, and agree practical recommendations.
- Track management action plans to closure, validating remediation evidence.
- Contribute to annual IT risk assessment activities and provide ongoing guidance to business units/subsidiaries on IT risk and control improvements.
Required Qualifications & Experience
- Bachelor’s degree in information systems, Computer Science, Accounting or related field.
- A minimum of three (3) years’ IT audit or IT Risk Management experience (internal and/or external), including ITGC testing and risk-based audit delivery.
- Proficiency in assessing enterprise applications/ERPs and documenting key technology risks and controls.
- Strong grasp of IT governance, risk, and controls, with the ability to translate technical issues into business impact.
- Strong communication, documentation, organization, and stakeholder management skills.
Preferred / Advantageous
- Certified Information Systems Auditor (CISA) is highly preferred; CRISC, CISM or CISSP are advantageous.
- Technical background (Windows Server and/or Linux) and familiarity with core infrastructure components.
- Working knowledge of frameworks/standards such as COBIT and NIST.
- Experience with implementation reviews and business continuity/disaster recovery.
- Basic scripting/web knowledge (e.g., HTML/CSS, JavaScript, PHP, Visual Basic) to support audit analytics or evidence review.