Apply Edge Start your job search

Senior IT Internal Auditor

ADIV Human Resources Consultancies, L.L.C · Dubai, United Arab Emirates

Apply & track with Apply Edge
My client, is seeking a Senior IT Internal Auditor to support the Head of Internal Audit in strengthening IT governance, risk, compliance, and internal controls. The role will focus on IT audits, ISO 27001 and DESC ISR compliance, IT risk management, third-party risk, VAPT coordination, and audit readiness.Key ResponsibilitiesConduct risk-based IT audits covering IT General Controls (ITGCs), application controls, IT operations, ERP/Zoho systems, backup, disaster recovery, and business continuity.Develop, review, and maintain IT policies, standards, procedures, and governance documentation aligned with ISO 27001:2022, DESC ISR, BCM, and applicable regulatory requirements.Maintain the IT risk register, including risk assessments, treatment plans, residual risks, and remediation tracking.Support risk assessments for new systems, projects, and third-party engagements.Coordinate ISO 27001, DESC ISR, internal, and external audits, including evidence collection, auditor liaison, findings, and corrective action tracking.Coordinate and track Vulnerability Assessment and Penetration Testing (VAPT) activities, remediation, and retesting.Support vendor and third-party risk assessments, including review of SOC reports, certifications, SLAs, and security documentation.Maintain compliance evidence repositories, audit documentation, dashboards, and management reports.Support the maintenance and testing of Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP).Assist with information security awareness initiatives and compliance training.Prepare clear, management- and board-ready audit, risk, and compliance reports.Qualifications & ExperienceBachelor’s degree in IT, Computer Science, Cybersecurity, Information Security, or a related field.4–7 years’ experience in IT audit, IT governance, risk, and compliance, preferably within a regulated, government-linked, or free-zone environment.Practical knowledge of ISO/IEC 27001:2022 and DESC ISR.Experience with ITGCs, IT risk management, VAPT, third-party risk, business continuity, and audit management.Strong experience in developing and reviewing IT policies, SOPs, controls, and process documentation.Excellent analytical, documentation, report-writing, and stakeholder management skills.Proficiency in Microsoft 365, including Excel, Word, and SharePoint.Preferred CertificationsCISACIAISO 27001 Lead Auditor / Lead ImplementerCRISCCOBIT Foundation