The Function Purpose
The IT Auditor contributes to the execution of risk-based IT audits and advisory engagements by evaluating technology risks, internal controls, and regulatory compliance. The role performs audit testing, documents results, and prepares working papers in coordination with the IT audit team.
Main Responsibilities
- Contribute to the planning and execution of IT audit engagements in accordance with approved audit methodologies and audit programs.
- Participate in walkthroughs of technology processes and assist in documenting process flows, risks, and controls.
- Perform audit testing across technology risk areas, including user access management, change management, IT operations, information security, applications and databases, infrastructure and cloud services, business continuity and disaster recovery, and third-party technology services.
- Collect, analyze, and validate supporting evidence to assess compliance with internal policies, procedures, and regulatory requirements.
- Prepare complete and accurate audit working papers and maintain supporting documentation in accordance with Internal Audit standards.
- Identify control deficiencies, exceptions, and areas for improvement, and contribute to the development of clear, evidence-based audit observations.
- Support the preparation of audit reports, presentations, and management communications.
- Participate in follow-up reviews to verify the implementation of agreed management action plans.
- Contribute to advisory reviews and special assignments related to technology projects, system implementations, and process improvements, while maintaining Internal Audit’s independence and objectivity.
- Utilize data analytics tools and technology-enabled audit techniques to support audit testing and analysis.
- Maintain awareness of emerging technology, cybersecurity, and IT risk developments through continuous learning and professional development.
Background
- Bachelor’s degree in computer science, Information Systems, Cybersecurity, Information Technology, Computer Engineering, or a related field.
- Up to 3 years of relevant experience in IT Audit, Information Security, Technology Risk, IT Operations, Data Analytics, or a related field is preferred.
- Exposure to banking, financial services, internal audit, external audit, consulting, information security, or technology operations is desirable.
- Progress toward obtaining a relevant professional certification, such as CISA, CIA, CISM, or another recognized IT audit, cybersecurity, or information systems qualification, is preferred.