Job Purpose: To provide independent assurance over IT governance, cybersecurity, application controls, and IT general controls, ensuring alignment with organizational objectives, risk appetite, and Nama Electricity Supply Company / OIA governance and assurance standards. Description: Conduct IT audits covering ITGC, cybersecurity, applications, and infrastructure, as per the approved Internal Audit Plan, analyzing data to assess. Develop and implement audit programs, including risk assessments, control matrix, and procedures based on guidance from Senior IT Auditor/Section Head. Collect and maintain proper audit evidence, ensuring accurate working papers, conclusions, and files are maintained in accordance with the division's policies. Perform data analysis within assigned audit areas to identify trends, anomalies, and control weaknesses. Ensure adherence to set IT Audit KPIs, reporting high-risk observations, and tracking implementation progress for observations, risk severity, cost saving, and revenue/loss optimization opportunities. Conduct audits effectively and within the allocated man-days budgeted as per the approved annual audit plan. Maintain complete and accurate engagement workpapers/files in accordance with quality standards and the approved Internal Audit Manual or International Standards for the Professional Practices of Internal Auditing. Produce high-quality IT Audit Findings and reports adhering to communication criteria and quality standards outlined in the approved Internal Audit Manual or International Standards for the Professional Practices of Internal Auditing. Ensure timely follow-up of findings in assigned areas, following the approved IA Follow-Up process. Assist in developing audit reports, findings, and recommendations for discussions with the Senior IT Auditor. Communicate audit findings and recommendations effectively to process owners, division heads, and Senior Management. Collaborate with the Internal Audit team, providing support for timely follow-up of corrective action items and implementation of the Personal Development Plan (PDP). Contribute to the effectiveness of the Internal Audit function through thorough audit execution and identification of areas for process improvement. Deliver high-quality audit reports and maintain positive client/auditee relationships, enhancing organizational risk management and operational excellence. Enhance skills and knowledge related to Business Acumen, Ethics, Governance, Risk, and Control through continuous learning and alignment with the International Professional Practices Framework. Adhere to company policies, procedures, guidelines, and Nama/OIA applicable standards. Minimum Qualifications: Bachelor’s Degree in IT, Computer Science, IS, or related field. Professional-related certificates, such as CIA and CISA, are preferable. Experience working in an audit or risk management function is preferred. Experience in the power/ water sector is preferred. Professional Experience: Minimum 3 years in IT/ IT audit / IT risk with a Bachelor’s Degree. الغرض الوظيفي: تقديم تأكيد مستقل على حوكمة تقنية المعلومات، والأمن السيبراني، وضوابط التطبيقات، والضوابط العامة لتقنية المعلومات، بما يضمن التوافق مع أهداف المؤسسة ومستوى المخاطر المقبول، ومعايير الحوكمة والرقابة المعتمدة لدى شركة نماء لتزويد الكهرباء / جهاز الاستثمار العُماني. الوصف الوظيفي: تنفيذ مهام تدقيق تقنية المعلومات بما يشمل الضوابط العامة (ITGC)، والأمن السيبراني، والتطبيقات، والبنية التحتية، وذلك وفقًا لخطة التدقيق الداخلي المعتمدة، مع تحليل البيانات لتقييم الضوابط. إعداد وتنفيذ برامج التدقيق، بما في ذلك تقييم المخاطر، ومصفوفات الضوابط، وإجراءات التدقيق، بناءً على توجيهات مدقق تقنية المعلومات الأول / رئيس القسم. جمع وحفظ أدلة التدقيق بشكل سليم، وضمان توثيق أوراق العمل والاستنتاجات والملفات بدقة وفق سياسات الإدارة. إجراء تحليلات بيانات ضمن نطاق التدقيق لتحديد الاتجاهات، والفجوات، ونقاط الضعف في الضوابط. الالتزام بمؤشرات الأداء الرئيسية للتدقيق، والإبلاغ عن الملاحظات عالية المخاطر، ومتابعة تنفيذ التوصيات، ومستوى المخاطر، وفرص تقليل التكاليف وتعظيم الإيرادات/تقليل الخسائر. تنفيذ مهام التدقيق بكفاءة وضمن عدد الأيام المعتمدة (Man-days) في خطة التدقيق السنوية. الحفاظ على ملفات وأوراق عمل التدقيق بشكل كامل ودقيق وفق معايير الجودة ودليل التدقيق الداخلي أو المعايير الدولية للممارسة المهنية للتدقيق الداخلي. إعداد تقارير تدقيق عالية الجودة وفق معايير التواصل والجودة المعتمدة. متابعة تنفيذ الملاحظات ضمن النطاق المحدد وفق آلية المتابعة المعتمدة. المساهمة في إعداد تقارير التدقيق والملاحظات والتوصيات بالتعاون مع مدقق تقنية المعلومات الأول. التواصل الفعّال لنتائج التدقيق والتوصيات مع مالكي العمليات ورؤساء الأقسام والإدارة العليا. التعاون مع فريق التدقيق الداخلي ودعم متابعة الإجراءات التصحيحية وخطط التطوير الفردية (PDP). الإسهام في تعزيز فعالية وظيفة التدقيق الداخلي من خلال تنفيذ تدقيق شامل وتحديد فرص تحسين العمليات. إعداد تقارير تدقيق عالية الجودة وبناء علاقات إيجابية مع الجهات محل التدقيق لتعزيز إدارة المخاطر والتميز التشغيلي. تطوير المهارات والمعرفة في مجالات الفهم التجاري، والأخلاقيات، والحوكمة، وإدارة المخاطر والرقابة، من خلال التعلم المستمر والالتزام بإطار الممارسات المهنية الدولية. الالتزام بسياسات وإجراءات الشركة ومعايير نماء / جهاز الاستثمار العُماني. المؤهلات العلمية: درجة البكالوريوس في تقنية المعلومات أو علوم الحاسب أو نظم المعلومات أو أي تخصص ذي صلة. يفضل الحصول على شهادات مهنية مثل CIA و CISA. يفضل وجود خبرة في مجال التدقيق أو إدارة المخاطر. يفضل وجود خبرة في قطاع الكهرباء أو المياه. الخبرة المهنية: خبرة لا تقل عن 3 سنوات في مجال تقنية المعلومات أو تدقيق تقنية المعلومات أو مخاطر تقنية المعلومات مع درجة البكالوريوس.
Subscribe for free, choose your specializations, and we'll send matching jobs directly to your WhatsApp
Subscribe via WhatsApp, free