Industry - Cloud computing & Data Center
Senior IT Audit Manager
Job Summary
We are seeking a Senior IT Audit Manager to join our Risk Management – Internal Audit team. This role is responsible for executing end-to-end IT audit engagements and supporting US SOX testing, ISO 27001 compliance, and SOC 1 and SOC 2 audit activities. You will play a key role in evaluating IT systems, internal controls, and business processes to strengthen the control environment, ensure regulatory compliance, and mitigate operational risks.
Key Responsibilities
- Conduct IT risk assessments across multiple domains, including IT infrastructure, cloud environments, data governance, cybersecurity, and application systems.
- Evaluate IT General Controls (ITGCs) and IT Application Controls (ITACs), assessing their effectiveness and impact on business processes, automation, and compliance requirements.
- Collaborate with IT teams on system-related changes, ensuring clear ownership and accountability between IT infrastructure, business processes, and control design.
- Support US SOX testing, ISO 27001 compliance, SOC 1 and SOC 2 audits, and other relevant assurance activities.
- Identify and assess risks arising from process changes, system integrations, and automation initiatives, recommending appropriate control enhancements.
- Drive continuous improvement of the organization's internal control environment, governance framework, and risk management practices.
- Support governance forums by providing insights and recommendations on process optimization, control effectiveness, and risk mitigation.
- Prepare clear and comprehensive audit documentation, reports, and recommendations for stakeholders across technical and business functions.
Requirements
- Bachelor's degree in Information Technology, Computer Science, Accounting, Finance, or a related discipline.
- 4–6 years of relevant experience in IT audit, cybersecurity, technology risk, consulting, or Governance, Risk and Compliance (GRC), preferably within an internal audit, external audit, or US-listed company environment.
- Strong hands-on experience conducting ITGC and ITAC audits.
- Experience working in a Big Four auditing firm is strongly preferred.
- Solid knowledge of cybersecurity risk management frameworks and standards, including NIST SP 800-53, ISO 27002, and ITIL. Familiarity with industry guidelines from organizations such as ITU, GSMA, and 3GPP is advantageous.
- Strong understanding of cybersecurity best practices, including risk management, vulnerability management, incident response, cloud security controls, and assurance practices.
- Experience with US SOX, ISO 27001, SOC audits, and Segregation of Duties (SoD) reviews is an advantage.
- Relevant professional certifications such as CIA, CISA, CISSP, or equivalent are preferred.
- Strong analytical, critical-thinking, documentation, and problem-solving skills, with the ability to leverage data, dashboards, and spreadsheets to generate actionable insights.
- Good business acumen, with the ability to understand business workflows, identify operational pain points, and define meaningful success metrics.
- Ability to translate technical IT concepts into business implications and communicate complex audit findings clearly to diverse audiences.
- Strong stakeholder management, interpersonal, and communication skills, with the ability to collaborate effectively across functions and manage competing priorities under pressure.
- Strong project coordination and organizational skills, with the ability to manage multiple engagements, deadlines, deliverables, and follow-ups in a fast-paced environment.
- A proactive and accountable mindset, with an innovative approach to continuous improvement and cross-functional collaboration.
- Basic understanding of AI products and concepts, including the capabilities and limitations of large language models (LLMs) and common business applications.
What We Offer
- An inclusive and collaborative working environment that values authenticity, diversity of thought, and different professional backgrounds.
- Opportunities to work in a dynamic, fast-growing organization with exposure to industry developments and emerging technologies.
- The opportunity to contribute to meaningful projects and have a direct impact on business operations and the development of internal governance and control frameworks.
- Exposure to new initiatives involving the development and enhancement of business processes, systems, and controls.
- A culture that encourages personal accountability, autonomy, continuous learning, and professional growth.
- Attractive employee benefits, alongside training, mentoring, and professional development opportunities.
EA Licence No: 19C9807