We’re Hiring: IT Audit Manager
Kuching, Sarawak
Cahya Mata Professionals Sdn Bhd
We're looking for an experienced IT Audit Manager to join our Group Internal Audit team. In this role, you'll play a key part in safeguarding the Group's technology landscape by evaluating IT governance, cybersecurity, SAP environments, and digital controls across our diverse businesses.
If you're passionate about technology, risk management, cybersecurity, and driving continuous improvement, this is an opportunity to make a meaningful impact while working closely with senior management and business leaders.
Key Responsibilities:
- Support the Senior Audit Manager in planning, leading and executing risk-based IT and SAP audits across the Group, covering infrastructure, enterprise applications, databases, cybersecurity, network security and emerging technologies.
- Assess the effectiveness of IT governance, technology risks and internal controls in accordance with the Institute of Internal Auditors' Global Internal Audit Standards, the Internal Audit Manual, applicable regulations, Group policies and recognised IT governance frameworks such as COBIT, ISO 27001 and NIST.
- Evaluate the efficiency, reliability and security of IT operations and technology-enabled business processes.
- Partner with IT, Risk, Compliance and other second-line functions to strengthen governance, cybersecurity and technology risk management practices.
- Review audit working papers and prepare high-quality audit reports with practical, risk-based recommendations for the Chief Internal Auditor and Group Audit Committee.
- Provide independent advisory support to Management on IT risks, governance, cybersecurity and control enhancements.
- Keep abreast of emerging technologies, cybersecurity trends and evolving regulatory requirements to strengthen audit effectiveness.
- Undertake other audit assignments, including non-IT audits, as required.
Requirements / Qualifications:
- Bachelor's Degree in Information Technology, Computer Science, Information Systems, Cybersecurity or a related discipline.
- Minimum 7 years of experience in IT Audit, Technology Risk, Cybersecurity, Technology Assurance, System Administration or related IT disciplines.
- Hands-on experience as an IT professional (e.g. System Administrator, IT Analyst, SAP Consultant, SAP Basis Administrator or Software Developer) will be highly valued.
- Experience auditing, implementing or supporting SAP environments, including SAP implementation projects, SAP operations or SAP Basis administration.
- Strong understanding of IT audit methodologies, IT governance, cybersecurity principles and technology risk management.
- Working knowledge of recognised frameworks such as COBIT, ISO 27001, NIST and other relevant standards.
- Industry exposure in manufacturing, cement, property, construction, oil & gas, trading or supply chain environments is an advantage.
- Professional certifications such as CISA, CISSP, CISM, CRISC, ISO 27001 Lead Auditor or equivalent are highly desirable.
- Experience with Audit Management Systems, ERP platforms and data analytics tools is an added advantage.