Manager - IT Audits
Listed on 2026-08-21
-
IT/Tech
Cybersecurity, IT Consultant, IT Business Analyst, Information Security & Data Protection
Emirates Global Aluminium is the world’s biggest ‘premium aluminium’ producer and the largest industrial company in the United Arab Emirates outside the oil and gas industry. EGA is an integrated aluminium producer, with operations on four continents from bauxite mining to the production of cast primary aluminium and recycling. EGA employs over 7,000 of these people including more than 1,200 UAE Nationals.
EGA operates aluminium smelters in Jebel Ali and Al Taweelah in the United Arab Emirates, an alumina refinery in Al Taweelah, a bauxite mine and associated export facilities in the Republic of Guinea, a speciality foundry in high strength recycled aluminium in Germany, and a recycling plant in the United States.
Manager - IT Audits (UAE Nationals)
Internal Audit
JOB PURPOSE:
An IT Audit Manager plays a crucial role in ensuring that an organization’s information technology systems and processes align with its objectives while meeting regulatory compliance and safeguarding against risks. The key responsibilities include:
- Planning and Designing Audits: Develop comprehensive audit plans that outline the scope, objectives, and methodologies for evaluating the effectiveness, efficiency, and security of IT systems and processes.
- Risk Assessment: Conduct risk assessments to identify vulnerabilities in the IT infrastructure, including cybersecurity threats, data integrity issues, and system availability risks. Based on these assessments, prioritize areas for auditing.
- Performing Audits: Execute audits according to the planned scope, including reviewing and testing IT controls, systems, and processes to assess their effectiveness. This often involves evaluating IT governance practices, security policies, access controls, disaster recovery planning, and operational procedures.
- Reporting Findings: Document audit results, including identified weaknesses or non-compliance issues. Provide clear, actionable recommendations for addressing these issues.
- Follow-up and Verification: Follow up on audit findings to ensure that corrective actions have been implemented effectively. Verify that recommendations are carried out and that the desired outcomes are achieved.
- Advisory Role: Act as an advisor to management on IT risk management, control, and governance processes. Offer guidance on enhancing IT frameworks, policies, and procedures.
- Regulatory Compliance: Evaluate the organization’s compliance with relevant industry standards and regulatory requirements related to IT, such as GDPR, ISO
27001, ISR, SOX, HIPAA. - Collaboration and Communication: Work closely with IT teams, external auditors, and other stakeholders. Effectively communicating audit findings, risks, and recommendations to both technical and non-technical audiences.
The above is to be carried out across all EGA sites (JA, AT, GAC, ATA and EGA Subsidiaries) in the following IT functions:
- EGA SAP and other Corporate & Mobile Applications.
- IT Governance.
- Information Security (including cyber security).
- GRC Access and Process Control systems.
- Industry 4.0.
KEY ACCOUNTABILITIES
Mandatory ethical and audit standards prescribed by the IIA
- Embeds the ethical standards and the mandatory standards prescribed by The Institute of Internal Auditors (IIA) in the day-to-day operations. To that effect, he/she shall instruct/supervise/coach his team members about the aforesaid requirement
- For deviations brought to his/her attention, the job holder would take steps to resolve the issue. It shall be the responsibility of the position holder to keep the Director of Corporate & IT and Chief Internal Auditor (CIA) informed of the deviations reported and the steps undertaken to resolve the issue. Should it not be possible for the job holder to resolve the issue, he/she shall seek the guidance of the Director of Corporate and IT and CIA in this regard
- Responsible for implementing departmental policies, processes, and procedures in all audits/risk assessments / day-to-day work conducted. To that effect, he/she shall instruct/supervise/coach his/her team members with regard to requirements of the departmental policies and procedures as well as monitor adherence to such policy/procedure.…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).