img
نوع العقددوام كامل
طبيعة الوظيفةبالموقع
الموقعالرياض

وصف الوظيفة

About Hala

Hala is a leading fintech company in the MENAP region, established in 2017. The company aims to redefine financial services and build the future bank for SMEs by providing cutting-edge financial and technological tools. Licensed by the Saudi Arabian Central Bank, Hala operates multiple entities in the UAE, Saudi Arabia, and Egypt, including Hala Payments and Hala Logistics, offering solutions that enable merchants to digitize payments and manage sales and operations.

The Opportunity: IT Audit Manager

Hala is seeking an IT Audit Manager to join its team in Riyadh. This full-time role involves leading audits across Information Technology, Cybersecurity, Business Continuity Management (BCM), and other technology-enabled business processes. The manager will plan and execute risk-based audits, evaluating the design and operating effectiveness of IT general controls (ITGCs), cybersecurity controls, technology governance, cloud environments, business continuity and disaster recovery capabilities, and regulatory compliance. This position requires identifying technology risks and control deficiencies, assessing their impact, and providing practical recommendations to strengthen governance, enhance cyber resilience, improve operational effectiveness, and support compliance with applicable regulatory requirements and industry standards.

Key Responsibilities

  • Plan and execute risk-based IT audit engagements, covering IT General Controls (ITGC), cybersecurity, cloud computing, digital platforms, data governance, business continuity management (BCM), disaster recovery (DR), third-party risk, and technology-enabled business processes.
  • Perform audit planning activities, including risk assessments, audit scoping, control identification, and the development of audit programs and testing procedures.
  • Evaluate the design and operating effectiveness of IT controls, identify technology risks and control deficiencies, and provide practical recommendations to strengthen governance, security, resilience, and operational effectiveness.
  • Assess compliance with applicable regulatory requirements, internal policies, and recognized industry frameworks and standards, such as SAMA Cybersecurity Framework (CSF), SAMA BCM Framework, PCI DSS, ISO/IEC 27001, COBIT, NIST Cybersecurity Framework, and SWIFT CSCF (where applicable).
  • Conduct interviews and walkthroughs with business and technology stakeholders to understand IT processes, systems, applications, infrastructure, and associated controls.
  • Prepare clear, concise, and evidence-based audit reports, working papers, and executive presentations that effectively communicate audit observations, risk implications, and actionable recommendations.
  • Present audit findings and recommendations to senior management and facilitate discussions to obtain agreement on corrective action plans.
  • Monitor and validate the implementation of agreed management actions through periodic follow-up reviews, providing independent assurance over the effectiveness of remediation activities, including validation of regulatory observations where required.
  • Build and maintain effective working relationships with business units, technology teams, risk management, compliance, and external stakeholders while preserving audit independence and objectivity.
  • Stay informed about emerging technology risks, cybersecurity threats, evolving regulatory requirements, and changes to applicable auditing, governance, and security standards.
  • Provide advisory and consulting services on technology initiatives, digital transformation projects, system implementations, and other ad hoc reviews, maintaining the independence of the Internal Audit function.
  • Contribute to the continuous enhancement of the Internal Audit methodology, including the adoption of data analytics, continuous auditing techniques, and technology-enabled audit tools.

Required Qualifications and Experience

  • A minimum of 5 to 10 years of experience in IT audit or a related field.
  • Demonstrated ability to plan and execute risk-based IT audit engagements.
  • Strong understanding of IT General Controls (ITGC), cybersecurity controls, technology governance, cloud environments, business continuity, and disaster recovery.
  • Proficiency in assessing compliance with regulatory requirements and industry standards, including SAMA Cybersecurity Framework (CSF), SAMA BCM Framework, PCI DSS, ISO/IEC 27001, COBIT, NIST Cybersecurity Framework, and SWIFT CSCF.
  • Excellent communication skills for conducting interviews, preparing reports, and presenting findings to senior management.
  • Ability to build and maintain professional relationships while upholding audit independence and objectivity.

Work Environment and Company Culture

Hala fosters an inclusive and diverse culture that supports innovation and flexibility, offering remote, in-office, and hybrid work setups. The team comprises over 30 nationalities working across 7 countries. The company promotes autonomy, mentoring, and challenging goals, providing opportunities for growth and entrusting employees with significant responsibility.

Application Process

Interested candidates are invited to apply for this full-time position.


متطلبات الوظيفة

  • تتطلب ٥-١٠ سنوات خبرة

وظائف مشابهة