Independently perform Risk Based Information Systems/Technology (IS/IT) audit reviews of companywide systems by following latest IS Audit Standards, guidelines & best practices.
Review the reliability of accounting, operating, compliance & other data produced by the IS/IT systems to check its relevance with the policy & standards requirements.
Perform IS/IT risk assessment based on a standard/methodology identifying the potential threats, vulnerabilities, likelihood of occurrence and impact on business.
Develop IS/IT audit procedures, prepare audit programs, questionnaires and information requirements to verify controls and recommendations to mitigate such risks for audit management?s review.
Conduct IS/IT audit review of Oracle cloud-based business application systems, databases, including reviews of access controls, the information technology infrastructure i.e. networks, operating systems, firewalls etc., IT organization, IT Projects, SDLC, IT/IS services & security mechanisms to evaluate and report on system security, integrity, confidentiality, availability, efficiency, effectiveness and compliance with relevant policies and procedures.
Prepare system flowchart, use specialized software tools, prepare electronic audit working papers in accordance with auditing standards i.e. sufficient, reliable, relevant and useful evidence to support findings and recommendations.
Ensure IS/IT audit working papers are adequately referenced and electronically stored in a secure manner.
Adequately construct the IS/IT audit related observations and recommendations by relating technology controls to achieve business objectives of IS/IT systems and prepare draft audit reports for review by Audit management.
High Proficiency in use specialized audit tools (software, CAATs), techniques, implementation of audit management systems, data analytics, robotics process automation tools, and technology to perform IT/IS audits using best practices in highly digitalized environment.
Keeps proper back-ups and ensures all relevant data bases, files and records are updated promptly after completion of tasks.
Collaborate with team members and assists in the development of a culture of knowledge/information sharing and effective relationships throughout the Internal Audit Department.
Perform other internal audit related duties, conduct/support in investigations/special reviews that might arise as a result of audit reviews or as directed by Audit management within given deadlines.
Interact with Company management and key personnel to build / maintain ongoing business relationships by utilizing interpersonal and communication skills.
Knowledge, Skills And Abilities Required (demonstrated By Work Experience)
In-depth understanding of the latest IT/ IS systems and its linkages to the accounting, internal controls, auditing principles, regulatory laws and legal framework.
Knowledge of IT/ IS auditing standards, procedures and best practices.
Understanding of systems & process, risk identification/assessment, and internal control evaluation skills (using RCMs).
Ability to work efficiently & effectively with complex cloud-based systems environment.
Ability to collaborate with employees, to include organizing, prioritizing, and scheduling work assignments.
Ability to articulate IT/IS systems information in business terms and communicate effectively, both orally and in writing.
Expert level understanding of IT control environment, Oracle-Cloud, MS Office 365 cloud, MS Office applications (Excel, Word, PowerPoint, Teammate, and use of specialized audit tools, software, CAATs, ACL etc.
Knowledge of COSO, COBIT, IIA Standards and Generally Accepted Accounting Principles (GAAP).
Skill in examining & re-engineering systems controls, procedures and implementing new strategies in highly digitalized environment.
Ability to develop, plan, and implement short- and long-range IT/IS audit goals.
Ability to foster a cooperative work environment.
Ability to provide technical guidance and training to audit team.
Continuous self-development and performance management skills.