img
نوع العقددوام كامل
طبيعة الوظيفةبالموقع
الموقعالرياض

وصف الوظيفة

About the Role

OptiClaim Business Solutions is seeking an IT Application Auditor on behalf of a client in Riyadh, Saudi Arabia. This full-time role focuses on supporting IT application audit engagements across enterprise applications and business-critical systems. The position requires a professional with over 10 years of experience in IT audit or related fields.

Key Responsibilities

The IT Application Auditor will evaluate and assess controls and risks within various enterprise systems. This includes reviewing application controls, IT General Controls (ITGC), business process controls, application security, and technology risks across ERP and other critical enterprise applications.

  • Conduct risk-based IT application audits across ERP and business applications.
  • Review ITGCs, including user access, privileged access, password management, change management, backup/recovery, and logging & monitoring.
  • Evaluate application security controls such as authentication, Role-Based Access Control (RBAC), Segregation of Duties (SoD), workflow approvals, and audit trails.
  • Assess interfaces, integrations, APIs, and data flow controls.
  • Perform user access reviews, covering provisioning, de-provisioning, and recertification processes.
  • Assess change/release management and deployment processes.
  • Review database security controls.
  • Identify risks, control gaps, and propose remediation measures.
  • Prepare audit documentation, reports, and executive summaries.
  • Track remediation actions through to closure.

Qualifications and Experience

Candidates should possess a strong background in IT audit and related disciplines, with a preference for those with consulting experience.

  • 10–12 years of experience in IT Audit, Application Audit, Information Security, Technology Risk, or Internal Audit.
  • Consulting background preferred, ideally with a Big 4 firm.
  • Knowledge of IT audit methodologies and risk-based auditing.
  • Experience with User Access Management (UAM), Identity and Access Management (IAM), Segregation of Duties (SoD), Role-Based Access Control (RBAC), and application configuration controls.
  • Familiarity with change/release management, interface & integration controls.
  • Knowledge of database security, logging/audit trails, and backup & recovery.
  • Experience with Enterprise applications such as SAP, Oracle EBS, Oracle Fusion Cloud, MS Dynamics 365, Workday, Salesforce, and ServiceNow.

Relevant Frameworks

The role requires familiarity with various industry frameworks and standards, including:

  • COBIT
  • ISO/IEC 27001
  • NIST CSF
  • CIS Controls
  • PCI DSS
  • NCA ECC
  • NCA DCC
  • SAMA CSF
  • PDPL

Work Type and Location

This is a full-time position based in Riyadh, Saudi Arabia.


متطلبات الوظيفة

  • تتطلب ٥-١٠ سنوات خبرة

وظائف مشابهة