✨ AI Summary
The Assistant Manager – Internal Audit (IT) will be responsible for planning and executing IT audit fieldwork, assessing business risks, and evaluating internal controls. This role involves drafting audit reports, discussing findings with stakeholders, and tracking the implementation of recommendations. The position requires applying ERP systems like SAP and data analytics tools for audit testing, ensuring independence and professionalism, and staying updated on industry best practices and regulatory changes.
Key requirements include 1-3 years of experience in IT audit, with a focus on IT General Controls, Incident Management, IT Risk Assessment, and Vendor Risk Management. Familiarity with COBIT, ITIL, and NIST frameworks is expected. A Bachelor's degree in Engineering (Computers) is mandatory. Certifications such as CISA or Lead Auditor ISO 27001 are a plus. The ideal candidate will possess strong technical skills in audit methodologies and regulatory frameworks, alongside excellent soft skills in communication, problem-solving, and stakeholder management.
Plan and perform field audit work in line with approved audit programs.Assess business risks and evaluate the effectiveness of internal controls.Prepare detailed working papers documenting audit procedures, findings, and evidenceDraft audit observations, recommendations, and reports based on audit findings.Discuss audit findings with process owners and management to obtain responses.Ensure audit reports are accurate, clear, and submitted within the stipulated timelines.Follow up with process own
Requirements
Minimum 1-3 years of relevant experience
Certifications (good to have) : CISA, Lead Auditor ISO 27001 or equivalent
Perform IT General Controls (ITGC) reviews covering:
User Access Management
Privileged Access Management
Password Controls
Segregation of Duties
Change Management
Backup and Recovery
Incident Management
IT Operations
Conduct application control reviews for SAP and non-SAP applications.
Review cybersecurity controls and information security governance.
Assess third-party/vendor risk management and cloud service controls.
Evaluate disaster recovery and business continuity preparedness.
Conduct infrastructure, network, database, and endpoint security reviews.
Work experience should include Big 4 or equivalent background
Thorough understanding of the industry and its segments
Key Competencies and Skills
Technical Skills
Internal audit methodologies and standards (IIA)
Risk assessment and internal control evaluation
ERP systems (e.g., SAP) and data analytics tools
COBIT, ITIL, NIST cybersecurity framework knowledge
Financial, operational, IT and compliance audits
Audit documentation and report preparation
Understanding of regulatory frameworks (VAT, Corporate
Tax, AML/CFT etc.,– as applicable)
Soft Skills
Effective communication (verbal and written)
Problem-solving and critical thinking
Collaboration and cross functional coordination
Stakeholder management and relationship building
Behavioural
Professional integrity and ethical conduct
Objectivity and independence in audit work
Attention to detail and accuracy
Adaptability to multi-location audits and changing priorities
Professional skepticism
Continuous learning orientation.
Description
Plan and perform field audit work in line with approved audit programs.Assess business risks and evaluate the effectiveness of internal controls.Prepare detailed working papers documenting audit procedures, findings, and evidenceDraft audit observations, recommendations, and reports based on audit findings.Discuss audit findings with process owners and management to obtain responses.Ensure audit reports are accurate, clear, and submitted within the stipulated timelines.Follow up with process owners to track the implementation of audit recommendations.Coordinate with business units to gather necessary information and documentation.Support the preparation of quarterly updates for senior management.Identify process gaps and suggest improvements to strengthen internal controls.Maintain proper documentation and evidence to support audit conclusions.Apply ERP systems (e.g., SAP) and data analytics tools to enhance audit testing.Ensure independence, objectivity, and professionalism in all audit activities.Stay updated on regulatory changes, audit best practices, and industry standards.