Senior Lead Auditor - IT
Listed on 2026-10-08
-
IT/Tech
Cybersecurity, IT Business Analyst, Information Security & Data Protection
Job Summary
The Senior Lead Auditor - IT executes technology-focused internal audit engagements across Power International Holding and its business groups, providing independent assurance over the design and operating effectiveness of technology, cybersecurity, data protection, and system-control environments.
Reporting to the IT Audit Manager within the Group Internal Audit function, the role evaluates IT general controls, ERP application controls, SAP security and authorizations, segregation of duties, cybersecurity, access management, change management, business continuity, and data governance. The position applies risk-based audit methodologies, data analytics, and professional standards to identify control weaknesses, determine root causes, and communicate practical recommendations to technical and non-technical stakeholders.
The role works independently across technical and business-process environments while supporting audit planning, scoping, fieldwork, reporting, remediation tracking, and continuous improvement of the Group IT audit plan.
Job Responsibilities 1 IT Audit Planning & Execution- Execute risk-based IT audit engagements covering IT general controls, application controls, cybersecurity, access management, change management, IT operations, business continuity, disaster recovery, and related technology risks across the Group.
- Support the IT Audit Manager in defining audit scope, objectives, testing strategies, resource requirements, and engagement timelines in alignment with the approved IT audit plan.
- Perform fieldwork, obtain and evaluate audit evidence, document procedures and conclusions, and maintain complete work papers in accordance with IIA IPPF and relevant ISACA standards.
- Perform ERP-focused audit work covering SAP access controls, role design, authorizations, segregation of duties, master data governance, system configuration, interfaces, workflows, and key automated controls.
- Assess business-process and application-control dependencies across SAP S/4
HANA and other critical enterprise systems. - Evaluate SAP GRC Process Control and access-risk-management arrangements, including mitigating controls and remediation of SoD conflicts.
- Develop and execute IT-specific Risk Control Matrices, clearly distinguishing design effectiveness from operating effectiveness.
- Assess control objectives, risks, control ownership, evidence requirements, testing frequency, sample selection, exceptions, and residual exposure.
- Identify control gaps, recurring issues, root causes, and risk concentrations requiring management attention.
- Extract, reconcile, and analyze data from key business systems to identify anomalies, unauthorized activity, control exceptions, and compliance breaches.
- Use appropriate analytics tools and repeatable audit scripts to strengthen testing coverage, evidence quality, and insight generation.
- Validate the completeness and accuracy of data used for audit testing and document analytical procedures and results.
- Draft clear, evidence-based IT audit findings and contribute to audit reports by translating technical issues into concise risk, impact, root-cause, and control language for business stakeholders.
- Engage with IT, Information Security, data owners, system owners, and business-process owners to validate findings and agree practical corrective action plans, owners, and target dates.
- Present audit observations professionally and respond constructively to technical challenge while maintaining independence and objectivity.
- Track open findings through remediation closure, assess supporting evidence, and elevate overdue or inadequately addressed actions through the established audit governance process.
- Support quality assurance activities, methodology improvements, risk assessments, audit-universe updates, and development of reusable IT audit programs.
- Maintain current knowledge of technology risk, cybersecurity, privacy, SAP controls, regulatory expectations, and emerging audit practices.
Strong understanding of IT general controls, application controls, cybersecurity, data protection, privacy, business continuity, and technology governance.
Audit Methodology & Professional Standards:Working knowledge of risk-based auditing, Risk Control Matrices, design and operating…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).