IT Auditor
OMNIYAT · Dubai, United Arab Emirates
قدّم وتابع مع أبلاي إيدجThe IT Auditor provides independent and objective assurance over the design and operating effectiveness of the Group's IT governance framework, cybersecurity controls and technology systems. The role safeguards the confidentiality, integrity and availability of OMNIYAT's data and digital assets by evaluating IT general controls, application controls and cyber risk management practices across the organization. Working closely with the Director – Internal Audit, Enterprise Technology and IT & Digital Security, the IT Auditor identifies control gaps and emerging technology risks and supports the Group's digital transformation agenda by embedding assurance early in system implementations, upgrades and third-party engagements.Day-to-day Tasks:Plan, scope and perform IT general control (ITGC) audits covering logical access, change management, IT operations and backup/disaster recovery across critical systemsAssess the organization’s cyber security posture against recognized frameworks such as NIST CSF and ISO 27001, incorporating UAE PDPL data protection considerationsReview and test ERP and business application controls, including automated controls, interfaces and system-generated reports, across key finance and operational systemsConduct pre-implementation and post-go-live reviews for new system implementations, upgrades and major configuration changes to confirm controls are designed and operating effectivelyPerform integrated audits combining financial, operational and IT risk perspectives, and assess IT third-party/vendor risk including data security and service continuity arrangementsAccess, extract and analyses data from enterprise systems in coordination with the Audit Analytics & AI Auditor to support risk-based and data-driven audit proceduresTrack and follow up on the remediation of IT audit findings and recommendations in coordination with Enterprise Technology and IT & Digital SecuritySupport the planning, scoping and execution of the annual risk-based IT audit plan in coordination with the Director – Internal AuditEvaluate the design and operating effectiveness of key IT general controls and application controls, and recommend practical enhancements where deficiencies are identifiedCoordinate with external IT auditors, forensic specialists or subject-matter experts on co-sourced or specialized engagements where additional expertise is requiredPrepare clear, well-supported and risk-rated IT audit reports that communicate findings, root causes and practical remediation recommendations to managementMonitor emerging cyber security threats, regulatory developments and technology trends relevant to the Group's digital roadmap and assess their impact on the control environmentParticipate in the review of information security policies, procedures and standards to confirm alignment with leading practice and regulatory requirementsProvide advisory input on IT control design during the early stages of digital transformation projects and technology change initiatives.Long Term ProjectsBuild a structured IT and cyber assurance programme aligned to the Group's digital roadmap.Expand integrated audit coverage as new systems and digital initiatives are rolled out.Experience & QualificationsBachelor's degree in Information Technology, Computer Science or a related field. CISA is required; CISSP or ISO 27001 Lead Auditor is an advantage.6+ years of IT audit or cybersecurity assurance experience in the industry and/or with Big 4 consulting firmITGC audits: access, change, operations and backup/disaster recoveryCyber posture assessment against NIST CSF / ISO 27001, incl. PDPL considerationsERP and application controls (Salesforce, Oracle Fusion, Primavera Unifier etc.) reviewPre- and post-go-live system reviewsIntegrated audits and IT third-party/vendor risk assessmentCoordination with Enterprise Technology and IT & Digital Security on remediation