Plan and execute risk-based IT audit engagements, including IT General Controls (ITGC), cybersecurity, cloud computing, digital platforms, data governance, business continuity management (BCM), disaster recovery (DR), third-party risk, and technology-enabled business processes.
Perform audit planning activities, including risk assessments, audit scoping, control identification, and development of audit programs and testing procedures.
Evaluate the design and operating effectiveness of IT controls, identify technology risks and control deficiencies, and provide practical recommendations to strengthen governance, security, resilience, and operational effectiveness.
Assess compliance with applicable regulatory requirements, internal policies, and recognized industry frameworks and standards, including SAMA Cybersecurity Framework (CSF), SAMA BCM Framework, PCI DSS, ISO/IEC 27001, COBIT, NIST Cybersecurity Framework, SWIFT CSCF (where applicable), and other relevant technology risk and security standards.
Conduct interviews and walkthroughs with business and technology stakeholders to obtain an understanding of IT processes, systems, applications, infrastructure, and associated controls.
Prepare clear, concise, and evidence-based audit reports, working papers, and executive presentations that effectively communicate audit observations, risk implications, and actionable recommendations.
Present audit findings and recommendations to senior management and facilitate discussions to obtain agreement on corrective action plans.
Monitor and validate the implementation of agreed management actions through periodic follow-up reviews and provide independent assurance over the effectiveness of remediation activities, including validation of regulatory observations where required.
Build and maintain effective working relationships with business units, technology teams, risk management, compliance, and external stakeholders while preserving audit independence and objectivity.
Stay abreast of emerging technology risks, cybersecurity threats, evolving regulatory requirements, and changes to applicable auditing, governance, and security standards.
Provide advisory and consulting services on technology initiatives, digital transformation projects, system implementations, and other ad hoc reviews, while maintaining the independence of the Internal Audit function.
Contribute to the continuous enhancement of the Internal Audit methodology, including the adoption of data analytics, continuous auditing techniques, and technology-enabled audit tools.