Group IT Audit Senior
CHA, TT

GROUP IT AUDIT SENIOR
JOB SUMMARY
The Group IT Audit Senior plays a key role in evaluating the effectiveness of technology controls, cybersecurity practices, and IT governance processes across the Group. The incumbent leads IT audit fieldwork, performs risk assessments, evaluates IT general controls and application controls, and assesses technology-related risks spanning access management, system development, change management, operations, cloud environments, and third-party service providers. Working in accordance with established audit methodologies and professional standards, the role delivers well-supported findings, performs root cause analysis, and provides meaningful recommendations that improve technology risk management and control effectiveness.
Beyond audit execution, the Group IT Audit Senior serves as a trusted partner to business and technology stakeholders by helping identify recurring issues, emerging IT risks, and opportunities for process improvement. The role leverages data analytics and automation tools to generate deeper insights, improve audit efficiency, and support continuous monitoring activities. Through coaching junior auditors, maintaining strong stakeholder relationships, and ensuring timely follow-up of audit recommendations, the incumbent contributes significantly to strengthening the organization’s technology control environment, cybersecurity posture, and operational resilience.
DUTIES & RESPONSIBILITIES
- Assesses IT risks and develops risk-based audit scopes across key IT processes.
- Leads ITGC testing and identifies control weaknesses.
- Evaluates application controls and data integrity risks.
- Assesses security controls, including identity, network and endpoint security.
- Assesses IT governance effectiveness and control oversight.
- Utilizes analytics to identify anomalies, trends and emerging risks.
- Manages IT audit fieldwork and validates audit evidence.
- Assesses incident, change and operational control processes.
- Assesses vendor controls, service performance and assurance reports.
- Evaluates compliance with policies, standards and regulatory obligations.
- Develops effective working relationships with IT stakeholders.
- Identifies recurring IT issues and emerging risk themes.
- Coaches junior auditors and reviews audit work.
- Validates corrective actions and tracks implementation progress.
COMPETENCIES
Audit & Assurance Expertise
· Independently evaluates IT controls, identifies risks and assesses control effectiveness.
Analytical & Critical Thinking
· Applies root cause analysis and data interpretation to assess risks and control weaknesses.
Communication Skills
· Communicates findings, risks and recommendations clearly and confidently to management.
Leadership & Team Development
· Coaches junior staff, review work quality and provides constructive guidance.
Strategic Perspective
· Connects audit findings to business risks, operational impact and control objectives.
Attention to Detail
· Maintains accurate, complete and well-supported audit workpapers and deliverables.
Quality Management
· Applies quality standards and review procedures throughout engagements.
Technological Proficiency
· Integrates data analytics and automated tools into audit testing and risk assessment.
QUALIFICATIONS & EXPERIENCE
- Minimum of three (3) to six (6) years of progressive Internal/ External Audit experience.
- Holding or progressing toward Certified Information Systems Auditor (CISA) certification is required.
- Holding Certified Internal Auditor (CIA), Certified Information Security Manager (CISM) Certified Information Systems Security Professional (CISSP), Certified in Risk and Information Systems Control (CRISC) is an additional asset.