Senior Auditor, IT (Digital Infrastructure)
Job purpose
Perform assigned audit engagements in the domain of digital infrastructure, from start to finish, inclusive of preplanning and wrap-up activities ensuring application of risk and control concepts to scenarios encountered, and identify any potential issues within ADNOC and group companies. Contribute in the capacity of SME in the periodic risk assessments and development of the risk-based work plans focusing on infrastructure security (network, cloud, systems, databases etc.) including vulnerability assessments and penetration testing at infrastructure and network layers within ADNOC and group companies.
Key accountabilities
Job specific accountabilities
Internal audit plan
- Develop the audit universe to ensure it covers digital infrastructure and cybersecurity risks in line with other D&T risk areas like digital governance, OT, process, applications, technology interface, and emerging technologies that could affect the ADNOC business operations.
- Review and update the D&T audit universe specifically for digital infrastructure and network.
- Develop and implement strategic initiatives (e.g., infrastructure assurance plan) that impact the group-wide audit plans and oversee the execution to ensure it fulfills the objectives.
Audit execution
- Perform audits, advisory engagements, and other influencing activities in highly technical areas of current and emerging technologies within ADNOC and group companies.
- Develop a detailed audit program / risk and control matrix (RCM) for the assigned audit, including the objectives, potential risk, key controls, audit procedures, and the use of audit techniques and tools to evaluate governance, risks, and control processes, and submit audit program to the management for review and approval.
- Ensure that adequate working papers and all relevant information are continuously documented and updated in the automated audit management system in accordance with predefined templates and audit procedures.
- Ensure that approved audit objectives have been met with adequate coverage of all relevant areas and sufficient audit evidence is obtained to support the conclusion and recommendations in accordance with professional audit standards.
Audit reports
- Prepare an audit report with a conclusion, expressing professional opinions on the adequacy and effectiveness of risk management, control systems, and the efficiency with which activities are carried out.
- Recommend improvement options to rectify reported deficiencies for department manager’s review.
- Recommend practical enhancements in digital and technology governance, risks, and control processes to assist in the achievement of the company's business objectives.
Coordination
Assist in the periodic reporting to the audit committee and senior management on technology audit activities, performance, significant risk exposures, controls/governance issues, and other related matters within ADNOC and group companies.
Minimum qualification
Bachelor's degree in computer science or related technology discipline, or equivalent discipline.
Minimum experience, knowledge & skills
- 8-10 years of relevant experience in D&T or IT internal auditing, and a minimum of 5+ years of work experience in digital infrastructure and cybersecurity domain.
- Advanced technical knowledge of core infrastructure, network components (routers, switches, firewalls etc.), cloud security, different operating systems, databases, virtualization technologies and security operations.
- Sound knowledge coupled with extensive experience in technology-related risks in emerging areas such as cloud, Internet of Things (IoT), zero-trust / defense in-depth architecture, identity and access management, digitalization, automation etc.
- Strong hands-on experience in conducting vulnerability assessments and penetration testing at infrastructure, network, and system layers. Bug bounty hunting would be an added advantage.
- Exposure in reviewing infrastructure platforms hosting AI/ML solutions to assess related risks, security controls, and governance aspects across the AI technology stack would be an advantage.
- In-depth knowledge of digital processes, including but not limited to business continuity and disaster recovery, enterprise architecture, infrastructure review (on-prem and cloud), access-right management, change management and DevOps etc.
- In-depth knowledge of International Professional Practices Framework for IT Assurance / IT Assurance Framework (ITAF) and other related frameworks/standards (e.g. COBIT, ITIL, ISO27000, ISO22301, NIST) and their interpretation/application to IS/IT auditing practice.
- Experience in managing and tracking time for different internal audit-related activities.
- Expertise in collecting and analyzing complex data using data analytics tools, evaluating information and systems, and drawing logical conclusions.
- Extensive knowledge of planning and project management areas.
- Awareness/knowledge of ERP and operational technology (OT) processes and systems (preferred).
Professional certifications
IT audit certification, CISA, is mandatory or willing to obtain within one year of joining. Other related certifications (GIAC, CISSP, OSCP, CISM, etc.) are preferred. Technical certifications (CCNA, CCIE, Azure, CCSK / CCSP, GPEN etc.) are desirable.