وصف الوظيفة
وصف الوظيفة
نحن نسعى للحصول على مدير تدقيق ذكي ومتفكر نحو المستقبل - تكنولوجيا للانضمام إلى قسم التدقيق الداخلي لدينا، متخصص في منصات رقمية وDevOps وبيئات تقنية الخدمات المصرفية للأعمال. بالإبلاغ إلى مدير التدقيق الداخلي الأول / رئيس التدقيق في البلد، ستقوم بتقييم مستقل لفعالية ضوابط تكنولوجيا المعلومات والأطر الرقمية والعمليات المعتمدة على التكنولوجيا عبر البنك.
ستوفر ضماناً بأن مخاطر التكنولوجيا مُدارة بشكل مناسب، والأنظمة آمنة، والعمليات ممتثلة للسياسات الداخلية والمتطلبات التنظيمية ومعايير الأمن السيبراني/مكافحة غسل الأموال. تتطلب هذه الوظيفة خبرة قوية في مشهد تكنولوجيا البنوك الحديثة، بما في ذلك القنوات الرقمية، والتسليم الرشيق، وممارسات DevOps.
- التخطيط والقيادة وتنفيذ التدقيقات التكنولوجية التي تغطي المنصات الرقمية، خطوط أنابيب DevOps، وأنظمة الخدمات المصرفية للأعمال.
- تقييم كفاية وفعالية ضوابط تكنولوجيا المعلومات العامة (ITGCs)، وضوابط التطبيقات، وأطر الأمن السيبراني.
- تطوير خطط تدقيق شاملة، مع تحديد مخاطر التكنولوجيا الرئيسية ونقاط التحكم والأنظمة الحيوية.
- تقييم المخاطر المرتبطة بمبادرات التحول الرقمي وبيئات السحابة وواجهات برمجة التطبيقات والتكامل النظامي.
- مراجعة عمليات DevOps بما في ذلك خطوط CI/CD، إدارة الإصدارات، ضوابط التغيير، وممارسات الأتمتة.
- تحديد ثغرات التحكم والفجوات الأمنية وعدم الكفاءات التشغيلية، مع التوصية بإجراءات ترميم عملية.
- إعداد تقارير تدقيق تفصيلية مع تصنيفات مخاطر واضحة وخطط تحسين قابلة للتنفيذ.
- مراجعة وتأكيد إغلاق نتائج التدقيق، والتأكد من فاعلية إجراءات الإصلاح واستدامتها.
- المشاركة في مشاريع تكنولوجيا المعلومات وتنفيذ الأنظمة وإطلاق المنتجات الرقمية لتقديم دعم استشاري للمخاطر.
- الت engaging مع أصحاب المصلحة في IT والرقمية والخدمات المصرفية للأعمال، وتقديم الرؤى والمساهمة في تطوير خطة التدقيق السنوية وعالم تدقيق التكنولوجيا.
- درجة البكالوريوس في تكنولوجيا المعلومات، علوم الحاسوب، الهندسة، أو مجال ذو صلة (يفضل الماجستير).
- شهادات مهنية مثل CISA، CISSP، CIA، أو ما يعادلها.
- خبرة 7-10 سنوات كحد أدنى في تدقيق IT/التكنولوجيا ضمن البنوك أو الخدمات المالية.
- معرفة قوية بمنصات الخدمات المصرفية الرقمية، القنوات عبر الإنترنت/الموبايل، وأنظمة الخدمات المصرفية للأعمال.
- خبرة عملية مع بيئات DevOps، بما في ذلك أدوات CI/CD، المنهجيات الرشيقة، وضوابط آلية.
- فهم راسخ لمبادئ الأمن السيبراني، ITGCs، الحوسبة السحابية، وأمن واجهات برمجة التطبيقات.
- الألفة مع الأطر التنظيمية وحوكمة تكنولوجيا المعلومات ومعايير حماية البيانات (مثلاً ISO 27001، NIST).
- إثبات القدرة على قيادة التدقيق والتواصل مع أصحاب المصلحة في التكنولوجيا والأعمال على المستويات العليا.
- مهارات تحليلية وحل مشكلات قوية، ومهارات كتابة تقارير فنية.
- معرفة بمعايير IIA ومنهجيات تدقيق التكنولوجيا، مع القدرة على تطبيقها في بيئات رقمية معقدة.
المسؤوليات - إدارة وتقييم مخاطر البنوك غير التقليدية: بناء وصيانة عالم تدقيق، استخدام تقييمات المخاطر لتحديد أولويات المجالات المعقدة مثل FinTech والتقنيات الجديدة والقنوات المبتكرة.
- القيادة في التخطيط التدقيقي بناءً على المخاطر: تحديد وتحليل المخاطر الناشئة، تقديم المدخلات لخطط التدقيق السنوية، والمساهمة في تطوير تدقيقات منتظمة ومشروعات بناءً على تقييمات مخاطر شاملة.
- تنفيذ عمليات تدقيق شاملة: المشاركة بنشاط في أنواع تدقيق مختلفة، بما في ذلك التدقيقات القطرية، التكنولوجية، الشاملة للمجموعة والتدقيقات الموضوعية، تقييم تصميم الضوابط، الكفاءة التشغيلية، والامتثال التنظيمي. تحديد الثغرات واقتراح التحسينات للحد من المخاطر وحماية الأصول.
- تقديم تنفيذ تدقيق عالي الجودة: ضمان الالتزام بالنطاقات المتفق عليها والمنهجيات القياسية، تقييم فاعلية الضوابط مقابل سياسات وإجراءات البنك.
- التعاون وبناء التوافق: مناقشة نتائج التدقيق مع الإدارة طوال العملية، وضمان الاتفاق على الإجراءات لمعالجة المخاطر المحددة. تطوير وتقديم خطط العمل لأصحاب المصلحة، وتثبيت الالتزام بتنفيذ الإجراءات التصحيحية والمتابعة حتى الإغلاق.
- تقديم استشارات داخلية: إجراء المراجعات والمشاركة في مهمات خاصة مثل مشاريع تطوير النظام. تحديد ثغرات الضبط وتوصية بتحسينات أفضل الممارسات.
- دعم المبادرات الكبرى: المشاركة بنشاط في مشاريع رئيسية، واختبار ضوابط النظام أثناء التطوير وبعد التنفيذ لضمان الفاعلية.
- الالتزام الصارم بجميع الأنظمة والإجراءات ومعايير المراجعة المعتمدة.
ضمان إتمام المهام في الوقت المحدد مع الحفاظ على الاحترافية والالتزام بمعايير التدقيق الداخلي (الميثاق/الدليل) والمعايير الدولية للممارسة المهنية للمراجعين الداخليين.
المؤهلات - التخرج من جامعة كمبيوتر/هندسة محترمة مع اطلاع على مبادئ الأعمال والمحاسبة.
- حيازة شهادات ذات صلة مثل CISA، CISSP (أو مكافئات ISACA) أو شهادات تحليل بيانات ذات صلة مع مزايا إضافية من CIA، CFA.
- 5+ سنوات من الخبرة في تدقيق تكنولوجيا المعلومات أو العمل في مشاريع رقمية، ويفضل ضمن Big 4، البنوك، أو شركات FinTech، مع خبرة في تقييم المخاطر، اختبار الضوابط، والتقنيات الناشئة مثل السحابة، DevOps، و Agile.
- الطلاقة في العربية والإنجليزية، مع امتلاك مهارات تحليلية، تواصل وتقديم عرض قوية لإدارة المشاريع والتعاون الفعّال.
- خبرة في تقديم مراجعات ضمان المشروع للتغييرات التنظيمية الحيوية.
Job description
Job Description
We are seeking a highly skilled and forward-thinking Audit Manager - Technology to join our Internal Audit function, specializing in Digital Platforms, DevOps, and Business Banking technology environments. Reporting to the Senior Internal Audit Manager / Country Head of Audit, you will independently evaluate the effectiveness of IT controls, digital frameworks, and technology-enabled processes across the Bank.
You will provide assurance that technology risks are appropriately managed, systems are secure, and operations comply with internal policies, regulatory requirements, and cybersecurity/AML standards. This role requires strong expertise in modern banking technology landscapes, including digital channels, agile delivery, and DevOps practices.
- Plan, lead, and execute technology audits covering digital platforms, DevOps pipelines, and business banking systems.
- Assess the adequacy and effectiveness of IT general controls (ITGCs), application controls, and cybersecurity frameworks.
- Develop comprehensive audit plans, identifying key technology risks, control points, and critical systems.
- Evaluate risks related to digital transformation initiatives, cloud environments, APIs, and system integrations.
- Review DevOps processes including CI/CD pipelines, release management, change controls, and automation practices.
- Identify control weaknesses, security gaps, and operational inefficiencies, recommending practical remediation actions.
- Prepare detailed audit reports with clear risk ratings and actionable improvement plans.
- Review and validate closure of audit findings, ensuring remediation actions are effective and sustainable.
- Participate in technology-related projects, system implementations, and digital product launches to provide risk advisory support.
- Engage with IT, Digital, and Business Banking stakeholders, providing insights and contributing to the development of the annual audit plan and technology audit universe.
- Bachelor's degree in Information Technology, Computer Science, Engineering, or related field (Master's preferred).
- Professional certifications such as CISA, CISSP, CIA, or equivalent.
- Minimum 7-10 years of experience in IT/Technology Audit within banking or financial services.
- Strong knowledge of digital banking platforms, online/mobile channels, and business banking systems.
- Hands-on experience with DevOps environments, including CI/CD tools, agile methodologies, and automated controls.
- Solid understanding of cybersecurity principles, ITGCs, cloud computing, and API security.
- Familiarity with regulatory frameworks, IT governance, and data protection standards (e.g., ISO 27001, NIST).
- Proven ability to lead audits and engage with technology and business stakeholders at senior levels.
- Strong analytical, problem-solving, and technical report-writing skills.
- Knowledge of IIA standards and technology audit methodologies, with the ability to apply them in complex digital environments.
Responsibilities - Manage & assess non-conventional banking risks: Build and maintain an audit universe, utilize risk assessments to prioritize complex areas like FinTech, new technologies, and innovative channels.
- Drive risk-based audit planning: Identify and analyze emerging risks, provide input for annual audit plans, and contribute to developing regular and project-based audits based on comprehensive risk assessments.
- Execute comprehensive audits: Actively participate in various audit types, including country, technology, group-wide, and thematic audits, evaluating control design, operational efficiency, and regulatory compliance. Identify weaknesses and propose improvements to mitigate risk and safeguard assets.
- Deliver high-quality audit execution: Ensure adherence to agreed scopes and standard methodologies, assessing control effectiveness against bank policies and procedures.
- Collaborate and build consensus: Discuss audit findings with management throughout the process, ensuring agreement on actions to address identified risks. Develop and present action plans to stakeholders, securing commitment to implement corrective measures and prevent future issues, and ensure timely follow-up till closure.
- Provide in-house consulting: Conduct reviews and participate in special assignments like system development projects. Identify control gaps and recommend best-practice improvements.
- Support major initiatives: Actively engage in key projects, testing system controls during development and post-implementation to ensure effectiveness.
- Rigorously adhere to all established systems, procedures, and review criteria.
Ensure timely completion of tasks while maintaining professionalism and adherence to internal audit standards (Charter/Manual) and International Standards for the Professional Practice of Internal Auditing.
Qualifications - Graduate from a reputable computer science/engineering university with exposure to business and accounting principles.
- Hold relevant certifications like CISA, CISSP (or ISACA equivalents) or relevant data analytics credentials with additional advantages from CIA, CFA.
- 5+ years' experience in IT audit or worked in digital projects, ideally within Big 4, banking, or FinTechs, demonstrating expertise in risk assessment, control testing, and emerging technologies like cloud, DevOps, and Agile.
- Fluent in Arabic and English, possessing strong analytical, communication, and presentation skills for effective project management and collaboration.
- Experience in providing project assurance reviews for critical organizational changes.