img
Contract TypeFull-time
Workplace typeOn-site
LocationSaudi Arabia

Job Description

About the Role

Tabby is seeking a Lead Auditor specializing in IT and Cyber Security Audit. This full-time role involves leading end-to-end execution of IT, cybersecurity, and technology audit engagements. The successful candidate will supervise engagement teams and deliver high-quality audit results in line with Tabby's technology risk-based audit plan.

Key Responsibilities

  • Lead the planning and execution of assigned IT general controls, application controls, and cybersecurity audit engagements, from scoping through reporting.
  • Develop detailed audit programs and risk and control matrices (RCMs) covering IT and cyber risk areas, aligned with the approved audit plan.
  • Supervise and review the fieldwork of Senior Auditors, Auditors, and Interns assigned to engagements, ensuring quality and adherence to methodology.
  • Conduct walkthroughs, technical interviews, and testing of IT general controls, application controls, network and endpoint security, identity and access management, and cloud configurations.
  • Identify control gaps and root causes, and draft clear, actionable audit findings and recommendations on technology and cyber risk.
  • Draft audit reports and present engagement results to Engineering and Information Security process owners.
  • Engage directly with technology process owners to validate findings, agree on corrective action plans, and set remediation timelines.
  • Track and follow up on the implementation of IT and cyber audit recommendations for assigned engagements.
  • Contribute to the annual technology and cyber risk assessment for assigned systems and platforms.
  • Coach and provide on-the-job guidance to Senior Auditors, Auditors, and Interns on IT audit techniques.
  • Support the Audit Manager in preparing quarterly and annual IT/cyber audit reporting materials.
  • Stay current on IT auditing standards, cybersecurity frameworks, and SAMA regulatory requirements (including the SAMA Cyber Security Framework).

Experience and Qualifications

Candidates should possess 5-10 years of experience in IT and cybersecurity audit roles. The role requires a strong understanding of audit methodologies and risk management principles, particularly within technology environments.

Skills and Knowledge

Proficiency in IT general controls, application controls, network and endpoint security, identity and access management, and cloud configurations is essential. The ability to articulate complex technical issues into clear audit findings and recommendations is also required.

Reporting and Collaboration

This role involves direct engagement with technology process owners and collaboration with the Audit Manager for reporting and strategic planning. The Lead Auditor will also be responsible for guiding junior audit staff.

Application Process

Qualified candidates are encouraged to apply. Salary details for this position will be discussed during the interview process.


Requirements

  • Requires 5-10 Years experience

Similar Jobs