Job Purpose
To execute on the internal audit methodology and a risk-based audit approach when performing start to end internal audit duties across all Hollard functions and partners both nationally and internationally with a high focus on technical IT audit and cyber security
Key Objectives
Business Development
• Build rapport with process owners and stakeholders.
• Practice effective communication skills.
Financial
• Manage time in line with the allocated budget and communicate any potential delays or overruns.
Process
• Conduct audits in accordance with approved Internal Audit methodology.
• Manage client interaction for allocated areas of scope.
• Attend audit team kick-off and close-out meetings.
• Prepare process analysis documentation (low complexity processes).
• Read business understanding documents and flow charts.
• Conduct penetration tests and vulnerability assessments on computerised networks and systems.
• Develop and utilise a sound understanding of business processes, risks and controls including relevant regulatory and accounting issues.
• Identification of process, information and control gaps and seek additional information if necessary.
• Ensure that information generated is accurate, valid and comprehensive prior to review and/or reporting.
• Documenting findings and discussion with client in terms of factual correctness – asks for support where necessary.
• Draft and discuss own findings for inclusion in audit reports.
• Take responsibility to clear and finalise all own reported findings/reporting points.
• Review own working papers for quality and completeness before sending to Senior Auditor for review.
• Ensure all review queries are cleared within a reasonable timeframe (expectation 48 hours).
• Focus on problem solving/high risk areas during the audit.
• Communicate any delays or difficulties experienced for corrective action.
• Track audit process status for allocated areas of responsibility and effectively communicate any anticipated challenges, delays, etc.
• Communicates knowledge gained throughout the audit engagement and/or otherwise with the team members.
HUMAN RESOURCES
• Attend scheduled training
• Take responsibility for own career and performance management.
• Contribute to training ideas and/or potential training deficiencies.
• Contribute to the social committee and attend social activities.
Qualifications Required:
• Bcom IT /BSc IT degree as a minimum, as well as one or more of the following:
• Certified Information Systems Auditor (CISA).
• Certified Information Security Manager (CISM).
• Certified Ethical Hacker (CEH).
• Offensive Security Certified Professional (OSCP)
Knowledge
• Risk based audit methodology.
• Knowledge of COBIT and/or ITIL frameworks.
• Knowledge of COSO framework.
• IIA standards.
• Computer infrastructure, networks and security.
• Disaster recovery and business continuity management.
• Basic business and financial understanding.
• Basic insurance knowledge (an advantage).
• Intermediate understanding of IT, data and privacy related legislation/regulation.
Knowledge
• Risk based audit methodology
• Knowledge of COBIT and/or ITIL frameworks
• Knowledge of COSO framework
• IIA standards
• Computer infrastructure, networks and security
• Disaster recovery and business continuity management
• Basic business and financial understanding
• Basic insurance knowledge (an advantage)
• Intermediate understanding of IT, data and privacy related legislation/regulation.
Skills
• Stakeholder engagement (client interviewing)
• Effective written and verbal communication skills (business acumen)
• Risk management (intermediate)
• Drafting findings
• Issue identification
• Audit planning (intermediate)
• Documentation skills
• Time management
• Root cause analysis (intermediate)
• Basic programming and ability to interpret source code
• Intermediate Excel
• Basic Linux
Technical Knowledge:
• IT General Controls (advanced)
• Vulnerability scanning (intermediate)
• Computer networks (intermediate)
• Server administration (intermediate)
• Infrastructure and architecture (intermediate)
• Database structures (intermediate)
• Cloud (intermediate)
• Cyber security (intermediate)
Skills
• A good knowledge of the business and the ability to evaluate risks
• Ability to take a holistic view of the organization in determining and positioning internal audit’s role
• Ability to identify strategic issues through critical reasoning
• Ability to effectively influence across all relevant levels within the business unit, including senior and middle business management
• Ability to effectively plan and set priorities for self and engagement team
• Strong leadership skills
• Strong communicator
• Strong project management skills
• Results oriented with a strong deadline focus
• Ability to build strong relationships and to work with others towards shared goals
• Team player able to collaborate and support colleagues and peers across the organization, while still being able to work independently when needed
• Flexible and open to change and innovation
• Good conflict management skills
• Good negotiation and problem-solving skills
• Strong attention to detail
• Good report writing and presentation skills.
• Strong analytical skills
• Ability to use Nessus, Kali, NMap and other security tools (basic)
For more information, please contact Pheliswa 011 234 0404, alternatively email your updated CV to pheliswa@esmartgroup.co.za
