Job Roles and Responsibilities:
The IT Auditor will be responsible for conducting IT audits across multiple clients and industries, assessing the adequacy and effectiveness of IT controls, identifying technology-related risks, and ensuring compliance with applicable standards, regulations and internal policies.
The ideal candidate will have a good understanding of IT systems, information security, business processes and audit procedures. Job responsibilities include:
IT Audit
- Evaluate the effectiveness of clients IT controls across different industries, business processes, systems and technology environments.
- Conduct IT audits to assess compliance with applicable regulatory requirements, industry standards, internal policies and procedures.
- Identify and assess IT risks and control weaknesses, and recommend appropriate improvements or mitigating measures.
- Assist in developing IT audit scopes, audit programmes, risk assessments and audit procedures.
- Evaluate IT General Controls, application controls and other technology-related controls, and recommend improvements where appropriate.
- Review areas including user access management, change management, IT operations, backup and recovery, system development, cybersecurity, business continuity and third-party IT services, where applicable.
- Assess whether application systems and related controls adequately support business processes and transaction processing.
- Review relevant IT governance, cybersecurity and information security practices against applicable standards and frameworks.
- Perform walkthroughs, interviews, document reviews and control testing to obtain sufficient audit evidence.
- Prepare audit working papers and reports documenting audit procedures performed, findings identified and recommendations for improvement.
- Discuss audit findings and recommendations with client personnel and management.
- Perform follow-up reviews to assess the implementation status of agreed corrective actions.
- Prepare and present reports that reflect audit results and document the proposed process.
- Engage in continuous knowledge development regarding sector's rules, regulations, best practices, tools, techniques, performance standards, relevant regulations, industry practices, technology risks, emerging technologies and audit methodologies.
- Collaborate with internal audit, cybersecurity and other engagement team members where necessary.
- Perform other ad-hoc duties and assignments as assigned.
Job Requirement:
- Bachelor's degree in Information Technology, Information Systems, Computer Science, Cybersecurity or a related field.
- Qualifications or academic background in Accounting, Auditing or related disciplines would be an added advantage.
- CISA (Certified Information Systems Auditor) certification is a minimum professional certification requirement for candidates who do not possess other relevant professional certifications.
- Candidates possessing other relevant professional certifications such as CIA, CISM, CISSP, CRISC, ISO/IEC 27001 Lead Auditor or equivalent will also be considered.
- Relevant experience in IT audit, technology risk, IT governance, IT compliance, internal audit or a similar role is preferred.
- Prior experience in performing IMDA SSIR audits, Cyber Trust Mark assessments, Cyber Essentials Mark assessments and/or Data Protection Essentials (DPE) assessments would be an added advantage.
- Good knowledge and understanding of IT systems, IT controls, information security and IT risk management.
- Familiarity with IT standards and frameworks such as COBIT, ISO/IEC 27001, NIST or other relevant frameworks.
- Able to appreciate business process issues and understand business transaction scenarios and how application systems support business operations.
- Strong analytical and problem-solving skills.
- Good audit documentation and report-writing skills.
- Excellent communication skills in both oral and written English.
- Resourceful and able to work independently with appropriate supervision.
- Logical thinking, good attitude, fast learner and good team player.
- Able to handle multiple tasks and assignments.
- Able to work under pressure and meet deadlines.
- Willing to travel to client premises where required.