Senior Manager, Information & Communication Technology Audit
· Perform end-to-end audits in IT, Information Security, and Cloud Security .
· Identify potential risks in AD, DC, DNS, hypervisors, virtualisation platforms, container-based technologies and databases.
· Design and run data analytics scripts and queries for full-population testing.
· Write and execute SQL queries independently against production databases, including Oracle, SQL Server, MySQL and PostgreSQL.
· Review and perform manual and automated testing to identify functional and operational issues, inconsistencies and security vulnerabilities.
· Identify potential risks related to data security, IT processes, and compliance with regulatory requirements and industry standards.
· Plan and design audit procedures and strategies based on the organization's specific needs and objectives.
· Conduct audits of IT systems, applications, and processes to assess their effectiveness, security, and compliance.
· Maintain detailed records of audit findings, including vulnerabilities, weaknesses, and recommendations.
· Ensure that the organization's Technology practices adhere to relevant laws, regulations, and industry standards (e.g., Bangladesh Bank Guidelines, ISO, PCI DSS, SWIFT, NIST).
· Provide recommendations to address identified vulnerabilities and improve IT security and efficiency.
· Stay updated on emerging threats, technologies, and industry best practices to enhance the organization's cybersecurity posture continually.
· Adequately analyse, assess and evaluate risks associated with IT and information security systems and applications.
· Conduct data analysis using appropriate Computer-Assisted Audit Techniques (CAATs).