Job description
About Bosta:
Launched in 2017, Bosta is an overnight delivery provider for E-commerce companies in Egypt. Leveraging technology to empower businesses is what we do best. Our goal is to disrupt the logistics industry by bringing technology and experience all together to provide a one-stop-shop for delivery solutions.
We rely on advanced technology to deliver orders to our customers in a fast way. Businesses can track and connect with couriers and follow up on their orders - all in one system.
Job Code: I2026FPA-063
Job Responsibilities:
- • Design and implement an enterprise-wide internal control framework aligned with COSO principles and tailored to Bosta's operating model across Egypt, and future markets.
• Map all critical business processes end-to-end, identify control gaps, and build a prioritized remediation roadmap with clear owners and timelines.
• Develop and maintain the Risk-Control Matrix (RCM) covering financial reporting, operations, and compliance risks.
• Prepare management representation letters, process narratives, and flowcharts for auditor review.
• Support the Audit Committee (once established) with reporting, risk assessments, and control testing results.
• Serve as the primary liaison with external auditors during annual audits and due diligence.
• Coordinate internal audit activities — planning, fieldwork, reporting, and remediation tracking.
• Monitor regulatory compliance requirements across operating jurisdictions and ensure Finance processes meet local and international standards (IFRS, tax, labor law, social insurance).
• Own the external vendors compliance framework for outsourced labor providers — ensuring payments accuracy verification, contract adherence.
• Design preventive controls to detect policy violations before they reach Finance.
• Identify manual processes that create control risk and champion automation or system-based controls.
• Work with IT and Operations to embed controls into existing systems (ERP, HRIS, payment platforms) rather than relying solely on detective controls.
• Establish KPIs for control effectiveness and report quarterly to the Head of FP&A and CFO.
Job Qualifications:
Must-Have Qualifications• 7–10 years of experience in internal audit, internal controls, or risk & compliance, with at least 3 years in a senior/lead role.
• Experience in a Big 4 firm or equivalent (Deloitte, PwC, EY, KPMG), ideally in their risk advisory or audit practice.
• Direct involvement in at least one major control transformation project.
• Strong understanding of IFRS, COSO, and control testing methodologies.
• Professional certification: CIA strongly preferred.
Preferred Qualifications• Industry experience in logistics, e-commerce, or high-growth technology companies.
• Multi-country experience is a plus
• Familiarity with ERP systems (SAP, Oracle, NetSuite) and data analytics tools for continuous monitoring.
Behavioral Competencies• Structured thinker: Can take a chaotic, undocumented process and turn it into a clear flowchart with controls, owners, and exception-handling procedures.
• Diplomatically relentless: Pushes for compliance without creating adversarial relationships with Operations and HR. Understands that controls must work with the business, not against it.
• Comfortable with ambiguity: need to be energized, not paralyzed, by embracing ambiguity.
• Communication range: Can write a board-ready risk report and also explain to a hub manager why a new approval step matters.
• Ownership mentality: Doesn't wait for the auditor to find the problem. Finds it first, fixes it, and
documents the fix.
وصف الوظيفة
حول بوستا:
أُطلق في 2017، بوستا هي مزود توصيل ليلي لشركات التجارة الإلكترونية في مصر. الاستفادة من التكنولوجيا لتمكين الأعمال هي ما نقوم به أفضل ما في العالم. هدفنا هو تعطيل صناعة الخدمات اللوجستية من خلال جمع التكنولوجيا والخبرة معًا لتوفير متجر واحد لحلول التوصيل.
نعتمد على التكنولوجيا المتقدمة لتوصيل الطلبات لعملائنا بسرعة. يمكن للشركات تتبع والتواصل مع المرسلين ومتابعة طلباتهم - كل ذلك في نظام واحد.
رمز الوظيفة: I2026FPA-063
المهام الوظيفية:
- • تصميم وتنفيذ إطار تحكم داخلي على مستوى المؤسسة متوافق مع مبادئ COSO ومُخصص لنموذج تشغيل بوستا عبر مصر والأسواق المستقبلية.
• رسم خريطة لجميع العمليات التجارية الحرجة من البداية للنهاية، وتحديد فجوات الرقابة، وبناء خارطة إصلاح ذات أولوية مع مالكين وجداول زمنية واضحة.
• تطوير والحفاظ على مصفوفة المخاطر-التحكم (RCM) التي تغطي مخاطر الإبلاغ المالي، والعمليات، والامتثال.
• إعداد رسائل تمثيل الإدارة، ووصف العمليات، ومخططات التدفق لمراجعة المدقق.
• دعم لجنة التدقيق (حال تأسيسها) بالتقارير وتقييمات المخاطر ونتائج اختبارات الرقابة.
• العمل كحلقة وصل أساسية مع المدققين الخارجيين خلال التدقيقات السنوية والدراسات المستندية.
• تنسيق أنشطة التدقيق الداخلي — التخطيط والعمل الميداني والتقارير وتتبع الإصلاحات.
• مراقبة متطلبات الامتثال التنظيمي عبر الاختصاصات التشغيلية والتأكد من تلبية عمليات المالية المعايير المحلية والدولية (IFRS، الضرائب، قانون العمل، التأمينات الاجتماعية).
• امتلاك إطار عمل امتثال للموردين الخارجيين لمزودي العمالة المستعان بهم — ضمان دقة المدفوعات والتحقق من الالتزام بالعقد.
• تصميم ضوابط وقائية لاكتشاف انتهاكات السياسات قبل وصولها إلى قسم المالية.
• تحديد العمليات اليدوية التي تخلق مخاطر رقابة والدفع نحو الأتمتة أو الضوابط المعتمدة على النظام.
• العمل مع تكنولوجيا المعلومات والعمليات لدمج الضوابط في الأنظمة القائمة (ERP، HRIS، منصات الدفع) بدلاً من الاعتماد فقط على الضوابط الاستدلالية.
• وضع مقاييس أداء للرقابة وتقديم تقارير ربع سنوية لرئيس FP&A والمدير المالي.
المؤهلات المطلوبة:
المؤهلات الأساسية• 7–10 سنوات خبرة في التدقيق الداخلي، الضوابط الداخلية، أو المخاطر والامتثال، مع ثلاث سنوات على الأقل في دور رفيع/قيادي.
• خبرة في شركة من الأربعة الكبرى أو ما يعادلها (Deloitte، PwC، EY، KPMG)، ويفضل في مجال الاستشارات المخاطرية أو التدقيق.
• مشاركة مباشرة في مشروع واحد رئيسي لتحويل الرقابة على الأقل.
• فهم قوي لـ IFRS، COSO، ومنهجيات اختبار الرقابة.
• شهادة مهنية: CIA مفضلة بشدة.
المؤهلات المفضلة• خبرة صناعية في الخدمات اللوجستية، التجارة الإلكترونية، أو شركات التكنولوجيا عالية النمو.
• خبرة متعددة البلدان تعتبر إضافة
• الإلمام بأنظمة ERP (SAP، Oracle، NetSuite) وأدوات تحليل البيانات للمراقبة المستمرة.
الكفاءات السلوكية• مفكر منظم: يستطيع تحويل عملية فوضوية وغير موثقة إلى مخطط تدفق واضح مع ضوابط، مالكين، وإجراءات معالجة الاستثناءات.
• دبلوماسي في الأسلوب، يضغط للامتثال دون إحداث علاقات عدائية مع العمليات والموارد البشرية. يفهم أن الضوابط يجب أن تتعمل مع العمل وليس ضده.
• مرتاح في الغموض: يجب أن يكون متحمسًا وليس متوقفًا عند استيعاب الغموض.
• مدى التواصل: يستطيع كتابة تقرير مخاطر جاهز للعرض على المجلس ثم شرح لمدير المحور سبب أهمية خطوة موافقة جديدة.
• عقلية الملكية: لا ينتظر حتى يعثر المدقق على المشكلة. يجداها أولاً، يصلحها، ويسجل الإصلاح.