OptiClaim

IT Application Auditor

OptiClaim

Riyadh, Riyadh Province, Saudi Arabia · Full Time

Be the first to apply

Experience
10–12 yrs
Salary
—
Openings
1
Posted
1 week ago
Work mode
In office
Education
Bachelor's in Computer Science or related field
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About the Role

OptiClaim Business Solutions seeks an experienced IT Application Auditor to join a client in Riyadh, Saudi Arabia. This full-time position involves evaluating controls and risks related to IT applications within enterprise and critical business systems. The ideal candidate will analyze application controls, IT general controls (ITGC), and business process controls to ensure security and compliance of systems such as ERP platforms and other enterprise software.

Primary Responsibilities

  • Conduct comprehensive risk-based IT audits across ERP and significant business applications.
  • Examine IT General Controls including user and privileged access management, password policies, change management, backup and recovery procedures, as well as logging and monitoring mechanisms.
  • Assess application security measures such as authentication methods, role-based access control (RBAC), segregation of duties (SoD), workflow approvals, and audit trails.
  • Review system interfaces, integrations, APIs, and data flow controls to verify integrity and security.
  • Perform user access assessments including provisioning, de-provisioning, and recertification processes.
  • Evaluate change and release management practices and deployment workflows.
  • Inspect database security configurations and controls.
  • Identify control weaknesses, risks, and recommend remedial actions.
  • Prepare detailed audit documentation, reports, and executive summaries for stakeholders.
  • Follow up on remediation efforts to ensure closure and compliance.

Required Expertise

  • 10 to 12 years of experience in IT Audit, Application Audit, Information Security, Technology Risk, or Internal Audit.
  • Preferably experienced within a consulting environment, especially with one of the Big 4 accounting firms.
  • Proficient in IT audit methodologies and risk-based auditing techniques.
  • Knowledgeable in User Access Management (UAM), Identity Access Management (IAM), Segregation of Duties (SoD), RBAC, and application configuration control practices.
  • Experienced in change and release management, interface and integration control assessment.
  • Skilled in database security, audit logs, backup and recovery controls.
  • Familiar with enterprise platforms including SAP, Oracle EBS, Oracle Fusion Cloud, Microsoft Dynamics 365, Workday, Salesforce, and ServiceNow.

Frameworks and Standards

  • COBIT
  • ISO/IEC 27001
  • NIST Cybersecurity Framework (CSF)
  • CIS Controls
  • PCI DSS
  • NCA Essential Cyber Controls (ECC)
  • NCA Digital Controls Catalogue (DCC)
  • SAMA Cybersecurity Framework (CSF)
  • Personal Data Protection Law (PDPL)

Educational and Certification Requirements

  • Bachelor's degree in Computer Science, IT, Information Systems, Cybersecurity, or a related discipline.
  • CISA certification is highly preferred.
  • Additional certifications such as CISM, CRISC, CISSP, or ISO/IEC 27001 Lead Auditor would be advantageous.

Minimum education

Bachelor's Degree

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer