Group Senior IT Auditor
AIR (Advanced Inhalation Rituals) · Dubai, United Arab Emirates
Apply & track with Apply EdgeA hands-on internal audit position performing IT internal audit assignments based on the annual audit plan and conducting special assignments or investigations based on special requests from management or stakeholders. The role includes auditing IT systems and integrations across global locations, focusing on Microsoft D365 and Microsoft Azure environments.
Key Responsibilities
Execute risk-based IT audit assignments across global operations in accordance with the approved audit plan and professional standards.Develop, maintain, and execute comprehensive IT audit programs, procedures, and testing methodologies.Contribute to the annual IT audit risk assessment and audit planning process by identifying emerging technology risks and control priorities.Conduct interviews, walkthroughs, and workshops with stakeholders to assess business processes, technology controls, and system risks.Prepare clear, concise, and value-added audit reports, including practical recommendations.Evaluate the design and operating effectiveness of IT General Controls (ITGCs), automated controls, and application controls across business systems.Audit enterprise applications, cloud environments, and system integrations, including Microsoft D365, Microsoft Azure, Power Platform, and related technologies.Assess cybersecurity governance, and compliance frameworks against internal policies, regulatory requirements, and industry standards such as ISO 27001, NIST, COBIT, ITIL, GDPR, and applicable local regulations.Perform continuous controls monitoring (CCM), and technology-enabled audit testing using audit tools.Leverage Artificial Intelligence, automation tools, and advanced data analytics to improve audit coverage, testing efficiency, risk identification, and reporting quality.Conduct follow-up reviews to assess the timely and effective implementation of agreed audit actions.Perform special investigations and management-requested assignments as required.Support in developing dashboards, audit metrics, management reporting, and assist in the preparation of Audit & Risk Committee materials, and executive presentations.Deliver awareness sessions and training programs to promote strong IT control practices, cybersecurity awareness, and risk management culture across the organization.Collaborate with business, technology, cybersecurity, and data teams across multiple geographies to support organizational objectives.Qualification:Bachelor’s degree in computer science / engineering / accounting / business / finance.Mandatory minimum certifications: CISA and ISO 27001 Lead Auditor.Familiarity with recognized IT governance, cybersecurity, data protection, and regulatory frameworks, including COBIT, NESA, NIST, ITIL, SWIFT CSCF, UAE PDPL, and GDPR.Additional certifications such as CIA, CISSP, CRISC, or equivalent would be an advantage.Experience & Skils:3 to 7 years of experience in IT auditing, IT security, IT risk management, or related IT roles.Practical experience with IT systems and infrastructure, preferably in a global context.Knowledge of Microsoft D365 and Microsoft Azure environments.Experience in auditing e-Commerce platforms, SWIFT compliance & PCI compliance.Strong understanding of IT systems, integrations, and related audit procedures.Understanding of cybersecurity principles and practices.Ability to assess compliance with IT policies, regulatory requirements, and industry best practices.Experience in Data Analytics using tools such as Excel, Power BI etc. will be a great advantage.Have a “can do” attitude with a positive drive and willingness to go above & beyond.Strong time management, project management, good verbal communication, and interpersonal skills.Can write good audit reports and have a good command of English.Ability to manage multiple priorities under tight deadlines.Proficient in computer skills and adept with technology, with a strong willingness to learn and adopt new advancements.Ability to work effectively in a global environment and audit global IT integrations. Flexibility to adapt to multiple global time zones as required for the engagement.Willingness to travel to other geographical locations outside of UAE for IT Audit purposes.