Apply now »

Senior Auditor - IT & Security Audit Job

Date:  5 Aug 2026
Custom Field 1:  675389
Location: 

Riyadh, SA

Facility:  Audit

 

Job Description

OVERVIEW

Job Title

Senior Auditor

Job Code

675389

Grade

I3

Group

-

Division

Internal Audit

Department

IT & Security Audit

Unit

Information Technology & Security Audit

 

ROLE PURPOSE

The aim is to state the overall significance of the job from the organization’s perspective.

The role is responsible for executing information technology and security audit engagements to provide independent assurance on the effectiveness of governance, risk management, cybersecurity, and internal controls. The role supports the delivery of the approved internal audit plan by conducting risk-based reviews, identifying control weaknesses, evaluating compliance with applicable standards and regulations, and recommending practical improvements that enhance the organization's control environment and operational resilience.

 

KEY ACCOUNTABILITIES & ACTIVITIES

This section describes the principal outputs required from the job.

Key Accountabilities

Key Activities

  1. IT & Security Audit Execution
  •  Execute IT and cybersecurity audit engagements in accordance with the approved audit plan.
  •  Perform audit testing and evaluate the effectiveness of technology controls.
  •  Document findings and supporting evidence.
  1. Technology Risk Assessment
  • Assess risks related to information systems, infrastructure, applications, and cybersecurity.
  •  Identify control gaps and recommend improvement opportunities.
  •  Evaluate risk mitigation measures.
  1. Control & Compliance Reviews
  •  Review compliance with internal policies, regulatory requirements, and technology standards.
  •  Assess IT General Controls (ITGCs) and automated controls.
  •  Evaluate governance and security control effectiveness.
  1. Audit Reporting
  • Prepare audit observations and reports.
  •  Communicate findings and recommendations to stakeholders.
  •  Support closure and resolution of audit issues.
  1. Follow-Up Activities
  • Track corrective action plans.
  •  Validate implementation of agreed actions.
  •  Report status of outstanding audit observations.
  1. Specialized Technology Audits
  •  Participate in reviews covering cybersecurity, system access, change management, and data protection controls.
  •  Support audits of digital products, applications, and technology initiatives.
  1. Stakeholder Collaboration
  • Coordinate with business and technology teams during audit engagements.
  •  Maintain effective working relationships with stakeholders.
  •  Facilitate information gathering and discussions.
  1. Continuous Improvement
  • Contribute to the enhancement of audit methodologies and practices.
  •  Support the use of data analytics and technology-enabled auditing techniques.
  1. Policies, Processes & Procedures
  •  Follow all relevant departmental policies, processes, standard operating procedures, and instructions so that work is carried out in a controlled and consistent manner.
  •  Comply with all relevant safety, quality, and environmental management policies, procedures, and controls to ensure a healthy and safe work environment.
  1. Information Security
  • Comply with all relevant information security practices and standards to ensure data integrity and confidentiality.

 

 

JOB SPECIFICATIONS

Academic and professional qualifications

  • Bachelor's degree in Information Technology, Computer Science, Information Systems, Cybersecurity, Software Engineering, or a related discipline.
  •  Professional certifications are preferred, such as CISA, CISSP, ISO 27001 Lead Auditor, CRISC, CIA, or equivalent.

Years and Nature of Experience

  • 4–6 years of relevant experience in IT Audit, Information Security Audit, Technology Risk, Cybersecurity, product development , AI developer, networking or Internal Audit.
  • Knowledge of IT governance, cybersecurity, risk management, and audit methodologies

 

 

VERSION TRACKING

Prepared by:

 

First review by:

 

Approved by:

Name

 

Signature

 

Date

 

 

 

 

 


Job Segment: Audit, Test Engineer, Information Security, Internal Audit, Risk Management, Finance, Engineering, Technology

Apply now »