Overview
Job Description
Job Title
Associate Principal
Job Code
722443
Grade
I4
Group
Division
Internal Audit
Department
IT Audit
Unit
Information Technology and Security Audit
ROLE PURPOSE
The aim is to state the overall significance of the job from the organization’s perspective.
Responsible for the day-to-day internal auditing of Elm’s Information Technology audits controls and systems. Also to ensures successful completion of assigned audit engagements, from start to finish, inclusive of preplanning and wrap up activities, according to the policies and procedures followed within ELM
Key Accountabilities & Activities
This section describes the principal outputs required from the job.
Key Accountabilities
Key Activities
Daily Operations
- Follow the day-to-day operations related to own job to ensure continuity of work
- Contribute to the identification of opportunities for continuous improvement of processes and practices taking into account ‘international best practice’
- Improvement of business processes, cost reduction, and productivity improvement
- Assist in the preparation of timely and accurate reports of the Internal Audit department to meet company and department requirements, policies and standards
Auditing procedures
- Ensure that risk & control concepts are applied and internal audit standards to scenarios encountered and identify any potential issues.
- Communicates identified issues with IT Audit department manager to ensure any potential concerns are addressed in a timely and effective manner.
- Planning for the annual audit engagements and measuring estimated timelines for completion.
- Prepare process mapping, conduct risk assessment and develop audit program.
- Perform audit fieldwork, prepare audit reports and conduct a discussion with the process owners as per the recommended IIA standards.
- Review and assesses ELM's processes, technologies (applications, network, database, operating system, etc.) and practices, as well as related procedures according to the annual audit plan.
- Perform management, information systems and technologies, IT and information security audits in all locations of the Company to review and evaluate the effectiveness of operations, confidentiality, integrity and availability of information and compliance with applicable laws and regulations.
Policies, Processes & Procedures
- Follow all relevant departmental policies, processes, standard operating procedures and instructions so that work is carried out in a controlled and consistent manner
- Comply with all relevant safety, quality and environmental management policies, procedures and controls to ensure a healthy and safe work environment
Information Security
- Comply with all relevant information Security practices and standards to ensure data integrity and confidentiality
JOB SPECIFICATIONS
Academic And Professional Qualifications
- Bachelor degree a Computer Science and/or Master Degree in Business, Finance, IT.
- Successfully IT audit related certifications such as CISA, CRISC, CGEIT, CISM.
Years And Nature Of Experience
- 6 -8 years of relevant experience in a related industry
نظرة عامة
الوصف الوظيفي
المسمى الوظيفي
مدير مشارك
رمز الوظيفة
722443
الدرجة الوظيفية
I4
المجموعة
القطاع
التدقيق الداخلي
الإدارة
تدقيق تكنولوجيا المعلومات
الوحدة
تدقيق تكنولوجيا المعلومات والأمن
الهدف من الوظيفة
الهدف هو بيان الأهمية الإجمالية للوظيفة من منظور المنظمة.
مسؤول عن أعمال التدقيق الداخلي اليومية لضوابط وأنظمة تكنولوجيا المعلومات في شركة علم. بالإضافة إلى ضمان الإتمام الناجح لمهام التدقيق الموكلة، من البداية إلى النهاية، بما في ذلك أنشطة التخطيط المسبق والإنهاء، وفقاً للسياسات والإجراءات المتبعة داخل علم.
المسؤوليات والأنشطة الرئيسية
يصف هذا القسم المخرجات الرئيسية المطلوبة من الوظيفة.
المسؤوليات الرئيسية
الأنشطة الرئيسية
العمليات اليومية
- متابعة العمليات اليومية المتعلقة بالوظيفة لضمان استمرارية العمل
- المساهمة في تحديد فرص التحسين المستمر للعمليات والممارسات مع أخذ "أفضل الممارسات الدولية" بعين الاعتبار
- تحسين العمليات التجارية، وخفض التكاليف، وتحسين الإنتاجية
- المساعدة في إعداد تقارير إدارة التدقيق الداخلي بدقة وفي الوقت المحدد لتلبية متطلبات وسياسات ومعايير الشركة والإدارة
إجراءات التدقيق
- ضمان تطبيق مفاهيم المخاطر والضوابط ومعايير التدقيق الداخلي على السيناريوهات المواجهة وتحديد أي مشكلات محتملة.
- التواصل بشأن المشكلات المحددة مع مدير إدارة تدقيق تكنولوجيا المعلومات لضمان معالجة أي مخاوف محتملة في الوقت المناسب وبطريقة فعالة.
- التخطيط لمهام التدقيق السنوية وقياس الجداول الزمنية التقديرية للإنجاز.
- إعداد مخطط العمليات، وإجراء تقييم المخاطر، وتطوير برنامج التدقيق.
- تنفيذ العمل الميداني للتدقيق، وإعداد تقارير التدقيق، ومناقشة أصحاب العمليات وفقاً لمعايير معهد المدققين الداخليين (IIA) الموصى بها.
- مراجعة وتقييم عمليات علم، والتقنيات (التطبيقات، الشبكة، قاعدة البيانات، نظام التشغيل، إلخ)، والممارسات، بالإضافة إلى الإجراءات ذات الصلة وفقاً لخطة التدقيق السنوية.
- إجراء تدقيق الإدارة، ونظم ومعلومات التكنولوجيا، وتكنولوجيا المعلومات وأمن المعلومات في جميع مواقع الشركة لمراجعة وتقييم فعالية العمليات، والسرية، والنزاهة، وتوافر المعلومات، والامتثال للقوانين واللوائح المعمول بها.
السياسات والعمليات والإجراءات
- اتباع جميع السياسات والعمليات وإجراءات التشغيل القياسية والتعليمات ذات الصلة بالإدارة لضمان أداء العمل بطريقة منضبطة ومستمرة
- الالتزام بجميع سياسات وإجراءات وضوابط السلامة والجودة والإدارة البيئية ذات الصلة لضمان بيئة عمل صحية وآمنة
أمن المعلومات
- الالتزام بجميع ممارسات ومعايير أمن المعلومات ذات الصلة لضمان سلامة البيانات وسريتها
المواصفات الوظيفية
المؤهلات الأكاديمية والمهنية
- درجة البكالوريوس في علوم الحاسب و/أو درجة الماجستير في إدارة الأعمال، أو المالية، أو تكنولوجيا المعلومات.
- الحصول بنجاح على شهادات متعلقة بتدقيق تكنولوجيا المعلومات مثل CISA، CRISC، CGEIT، CISM.
عدد وطبيعة الخبرة
- خبرة ذات صلة تتراوح بين 6 إلى 8 سنوات في مجال عمل مرتبط