Lead the execution of approved audit plans, conducting thorough risk assessments and evaluating control mechanisms to ensure operational effectiveness and regulatory compliance.
Gain an in-depth understanding of the business environment and its associated risks. Conduct comprehensive walkthroughs and engage in detailed discussions with management to evaluate the adequacy and effectiveness of existing controls.
Assess the effectiveness of IT controls, including access controls, change management, data security, and disaster recovery. Recommend improvements where necessary to strengthen the control environment.
Prepare clear and concise audit reports that summarize findings, risks, and recommendations. Communicate these findings to senior management and other stakeholders in a professional and constructive manner.
Engage with senior management to discuss audit findings and ensure appropriate responses are provided for all identified issues. Manage conflicts professionally and maintain a constructive dialogue.
Track the progress and adequacy of actions taken to address audit issues, ensuring that they are resolved in a timely manner.
Explore opportunities to enhance audit processes by incorporating data analytics, adding new tests to improve the depth and accuracy of audit assessments.
Continuously monitor emerging risks and significant changes within the business, integrating them into the audit planning and risk assessment processes.
Foster strong, effective working relationships with senior management, other departments, and external auditors to promote the value of the internal audit function.
Assist in the preparation of reports and documentation for Board and Management committees, providing insights into audit outcomes and the status of ongoing issues.
Qualifications and Skills:
Strong background in IT auditing, with a solid understanding of IT systems, controls, and risk management.
Excellent communication skills, capable of conveying complex technical issues to non-technical stakeholders.
Proven ability to manage multiple projects and deadlines in a fast-paced environment.
Proficiency in using audit management software and data analytics tools.
Experience in leading audit teams and fostering professional growth among team members.
In-depth knowledge of relevant IT regulations and standards, such as GDPR, SOX, and ISO 27001.
Possession of one or more relevant certifications such as Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified Internal Auditor (CIA), or Certified Information Systems Security Professional (CISSP) is an added advantage.