Information Technology Auditor
ECOVIS Saudi Arabia (ECOVIS AL SABTI) · Riyadh, Saudi Arabia
قدّم وتابع مع أبلاي إيدجCompany Description ECOVIS Al Sabti in the Kingdom of Saudi Arabia is a member firm of the ECOVIS International network, a leading global consulting group rooted in Continental Europe. ECOVIS operates in more than 95 countries with a team of around 11,000 professionals, serving clients across diverse industries. The firm offers services in Audit and Assurance, Financial Advisory, Enterprise Risk Management, Cybersecurity, Business Continuity, Data Management, Technology, Tax Consulting, and Accounting. ECOVIS focuses on delivering high-quality, tailored solutions by combining global expertise with local market insights. The firm is recognized for its innovative client service approach, dedication to excellence, and its ability to provide personalized local advice backed by a strong international network.Key Requirements:Bachelor’s degree in Information Technology, Computer Science, Information Systems, Cybersecurity, or a related field.Minimum 3–5 years of professional experience in IT Audit, Information Systems Audit, Technology Risk, Cybersecurity Audit, IT Governance, Risk & Compliance (GRC), or a related consulting role.Strong understanding of IT audit methodologies, IT General Controls (ITGCs), application controls, technology risk management, information security controls, and cybersecurity governance.Good knowledge of relevant frameworks, standards, and regulatory requirements such as COBIT, ISO 27001, NIST Cybersecurity Framework, NCA Cybersecurity Controls, and other applicable local and international IT governance and cybersecurity standards.Hands-on experience in assessing key IT controls, including user access management, change management, IT operations, backup and disaster recovery, system development, information security, and third-party/vendor controls.Ability to identify control weaknesses, technology risks, and compliance gaps, assess their impact, and provide practical and risk-based recommendations for remediation.Experience in preparing audit workpapers, audit findings, reports, and executive summaries, as well as following up on remediation and closure of audit observations.Relevant professional certifications such as CISA (Certified Information Systems Auditor), CISM (Certified Information Security Manager), or equivalent IT Audit / Information Security certifications will be preferred.Proven ability to manage audit assignments/client engagements, coordinate with IT, cybersecurity, compliance, and business stakeholders, and deliver projects within established timelines and quality standards.Excellent verbal and written communication skills, with the ability to communicate technical audit findings effectively to both technical and non-technical stakeholders.