Exhibit subject matter expertise across a wide range of Technology areas, including Technology Infrastructure, Applications, Information Security / Cyber, Technology Resilience, Governance, and Regulatory Compliance, demonstrated through high-quality risk assessments, regular business monitoring, audit delivery, and risk-based or regulatory issue validations.
Lead and execute audit processes and ensure audit reports are completed within planned timelines, conduct issue validations, business monitoring, and offer governance insights.
Engage in key business initiatives, proactively providing advice and support on change initiatives within the business.
Contribute to management action plans by identifying solutions to complex and unique control challenges, using professional judgment, expertise, and experience.
Review report findings and recommend actions where necessary, presenting innovative and practical solutions for risk and control issues.
Effectively assess risks when making business decisions by ensuring compliance with relevant laws, regulations, and policies.
Exercise ethical judgment in personal conduct and business practices, addressing, managing, and transparently reporting control issues as required.
Requirements:
Bachelor's or University degree, or equivalent professional experience, ideally in Technology or related fields.
Holding certifications such as CISA (Certified Information Systems Auditor), CISSP (Certified Information Systems Security Professional), CRISC (Certified in Risk and Information Systems Control), CEH (Certified Ethical Hacker), or CGEIT (Certified in the Governance of Enterprise IT) is advantageous.
Familiarity with ISO Standards a plus (e.g. ISO27001, ISO9001)
3 5 years in IT audit experience, specifically in auditing IT systems, infrastructure, and processes.
Demonstrated expertise in areas including data governance, technology infrastructure security, change, application development and production management, including auditing cloud environments.
Comprehensive knowledge of cybersecurity controls, covering areas such as vulnerability and patch management, virus/malware protection, data loss prevention, intrusion detection, crisis management, and incident response.
Practical experience in data analytics and a strong understanding of source code is beneficial.
Flexible and willing to take on additional assignments as needed.