img
Contract TypeFull-time
Workplace typeOn-site
LocationRiyadh

Job Description

About the Role

Tabby | تابي is seeking a Lead Auditor specializing in IT and Cyber Security Audit. This full-time position is based in Riyadh, Saudi Arabia, and involves leading end-to-end execution of IT, cybersecurity, and technology audit engagements. The role requires supervising engagement teams and delivering high-quality audit results in line with Tabby's technology risk-based audit plan.

Key Responsibilities

  • Lead the planning and execution of assigned IT general controls, application controls, and cybersecurity audit engagements, from scoping through reporting.
  • Develop detailed audit programs and risk and control matrices (RCMs) covering IT and cyber risk areas, aligned with the approved audit plan.
  • Supervise and review the fieldwork of Senior Auditors, Auditors, and Interns assigned to engagements, ensuring quality and adherence to methodology.
  • Conduct walkthroughs, technical interviews, and testing of IT general controls, application controls, network and endpoint security, identity and access management, and cloud configurations.
  • Identify control gaps and root causes, and draft clear, actionable audit findings and recommendations on technology and cyber risk.
  • Draft audit reports and present engagement results to Engineering and Information Security process owners.
  • Engage directly with technology process owners to validate findings, agree on corrective action plans, and set remediation timelines.
  • Track and follow up on the implementation of IT and cyber audit recommendations for assigned engagements.
  • Contribute to the annual technology and cyber risk assessment for assigned systems and platforms.
  • Coach and provide on-the-job guidance to Senior Auditors, Auditors, and Interns on IT audit techniques.
  • Support the Audit Manager in preparing quarterly and annual IT/cyber audit reporting materials.
  • Stay current on IT auditing standards, cybersecurity frameworks, and SAMA regulatory requirements (including the SAMA Cyber Security).

Qualifications and Experience

  • A minimum of 5 years of experience in IT audit, information security, or technology risk, including experience leading audit engagements. Experience within banking, fintech, or corporate environments is preferred.
  • Strong knowledge of IT auditing standards, cybersecurity frameworks, and SAMA regulatory requirements.
  • Experience assessing IT general controls, application controls, and cybersecurity controls.
  • Proficiency in IT audit tools and familiarity with cloud platforms (AWS/Azure/GCP).
  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field.
  • CISA certification (obtained or in progress) is highly desirable.

Required Skills

  • Strong communication and interpersonal skills to engage with technology process owners and present audit findings.
  • Strong analytical and problem-solving skills with a detail-oriented approach.

Work Environment

This is a full-time position based in Riyadh, Saudi Arabia, within the Tabby | تابي team. The role involves working closely with technology process owners and internal audit teams.

Application Process

Candidates meeting the above requirements are encouraged to apply. Salary details will be discussed during the interview process.


Requirements

  • Requires 5-10 Years experience

Similar Jobs