Senior IT Internal Auditor
ADIV Human Resources Consultancies, L.L.C
Dubai, United Arab Emirates · Full Time
Be the first to apply
- Experience
- 4–7 yrs
- Salary
- —
- Openings
- 1
- Posted
- 2 weeks ago
- Work mode
- In office
- Education
- Bachelor's degree in IT or related field
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Overview
A client is looking for an experienced Senior IT Internal Auditor to aid the Head of Internal Audit in enhancing IT governance, managing risks, ensuring compliance, and overseeing internal control measures. This position primarily involves conducting IT audits and ensuring conformity with ISO 27001 and DESC ISR standards, managing IT risks, assessing third-party risks, coordinating VAPT efforts, and maintaining audit preparedness.
Key Responsibilities
- Execute risk-based IT audits focusing on IT General Controls, application controls, IT operations, ERP/Zoho platforms, backup systems, disaster recovery, and business continuity.
- Create, assess, and keep up-to-date the IT policies, standards, procedures, and governance documents aligned with ISO 27001:2022, DESC ISR, BCM, and relevant regulatory mandates.
- Oversee the IT risk register, including conducting risk assessments, treatment strategies, monitoring residual risks, and tracking remedial actions.
- Assist in risk evaluations for newly introduced systems, projects, and engagements involving third parties.
- Manage coordination of ISO 27001, DESC ISR, internal and external audits—collecting evidence, interacting with auditors, addressing findings, and monitoring corrective measures.
- Supervise and document Vulnerability Assessment and Penetration Testing activities, including overseeing remediation and retesting processes.
- Conduct risk assessments of vendors and third parties by reviewing SOC reports, certifications, service level agreements, and security documentation.
- Maintain repositories for compliance evidence, audit documentation, dashboards, and management reporting.
- Support the upkeep and testing of Business Continuity and Disaster Recovery plans.
- Participate in programs promoting information security awareness and compliance training.
- Prepare detailed and comprehensible audit, risk, and compliance reports suitable for management and board review.
Qualifications & Experience
- Bachelor's degree in IT, Computer Science, Cybersecurity, Information Security, or a related discipline.
- Between 4 to 7 years of professional experience in IT audit, governance, risk management, and compliance, ideally within regulated, government-affiliated, or free zone organizations.
- Hands-on familiarity with ISO/IEC 27001:2022 standards and DESC ISR compliance requirements.
- Practical involvement with IT General Controls, IT risk management, Vulnerability Assessment and Penetration Testing, third-party risk evaluation, business continuity, and audit oversight.
- Extensive experience in developing and reviewing IT governance documents such as policies, standard operating procedures, controls, and process guidelines.
- Strong analytical and documentation capabilities paired with effective report writing and stakeholder communication skills.
- Proficient user of Microsoft 365 applications, especially Excel, Word, and SharePoint.
Preferred Certifications
- CISA (Certified Information Systems Auditor)
- CIA (Certified Internal Auditor)
- ISO 27001 Lead Auditor or Lead Implementer
- CRISC (Certified in Risk and Information Systems Control)
- COBIT Foundation
Minimum education
Bachelor's Degree