Job description
Job Purpose
Perform assigned audit engagements, from start to finish, inclusive of preplanning, wrap up activities ensuring application of risk and control concepts to scenarios encountered, and identify any potential issues.
Assist in the periodic Risk Assessments and development of the Risk-Based Work Plans focusing on IT risks.
Job Specific Accountabilities (Part 1)
Professional Ethics
• Assist in initiating/promoting the establishment and continuous improvement of the Corporate Governance Framework including Enterprise Risk Management, Corporate Code of Conduct, Ethics and Values.
Internal Audit Plan
• Assist in the development of Annual Audit Plan (AAP) based on the results of risk assessment exercise focusing on IT risks.
• Participate in reviewing and updating the IT audit universe to ensure it covers all IT risks.
• Provide input for the periodic reporting on IT audit activities and performance relative to its plans, significant risk exposures, control/governance issues and other related matters.
Audit Execution
• Lead the IT auditors in the examination and analysis of records through executing audit program steps for the assigned audits.
• Develop a detailed audit program / Risk & Control Matrix (RCM) for the assigned audit including the objectives, potential risk, key controls, audit procedures and the use of audit techniques and tools to evaluate governance, risks and controls processes, and submit audit program to the management for review and approval.
• Determine auditing procedures to be applied, including the use of Information Systems Audit Techniques, data analytics, statistical sampling method or others.
• Ensure that adequate working papers and all relevant information are continuously documented and updated in the automated Audit Management System in accordance with pre-defined templates and audit procedures.
• Identify, obtain, analyze and appraise related systems and evidentiary data/information.
• Appraise the adequacy of the corrective actions taken by management on audit recommendations through follow up audits and periodically review and update the status of management action plans.
• Ensure that approved audit objectives have been met with adequate coverage of all relevant areas and sufficient audit evidence is obtained to support the conclusion and recommendations, in accordance with professional audit standards.
• Participate in conducting special reviews and undertakes administrative duties as directed by Head of Internal Audit.
• Supervise audits in accordance with the approved RCM and professional standards on internal auditing.
• Ensure tasks assigned to junior staff are adequately performed and deliverables are in accordance with ADNOC Internal Audit procedures and quality standards.
• Identify high risk areas and key control points of the system to be reviewed.
Audit Reports
• Prepare audit report with conclusion, expressing professional opinions on the adequacy and effectiveness of risk management, control systems and the efficiency with which activities are carried out. Recommend improvement options to rectify reported deficiencies, for Section Head / Department Manager’s review.
• Recommend practical enhancements in IT governance, risks and control processes to assist in the achievement of the company business objectives.
• Follow-up on replies to issued draft and final audit reports and review the adequacy of the corrective actions taken on audit recommendations / improvement options.
Job Specific Accountabilities (Part 2)
• Assist in the periodic reporting to the Audit Committee and Senior Management on internal audit activities, performance, significant risk exposures, controls/governance issues and other related matters.
Coordination
• Assist the Secretary of the Audit Committee in arranging Audit Committee meetings, preparing the agenda, and minutes of meetings (MOMs) and reporting on Corporate Governance Framework, General Controls and other related issues as prescribed in the Audit Committee Charter.
• Conduct workshops or presentations to create awareness about IA function and demonstrate value addition across the ADNOC.
• Communicate identified issues with Internal Audit management to ensure potential high risk area of concerns are addressed in a timely and effective manner.
• Provide professional advice on Group Companies’ Audit Committee Charter,
IA Charter and IT Audit Methodology/Procedures. Provides assistance in the establishment of the Group Audit Committees/IA functions and related governance, when assigned.
• Participate in initiating and coordinating the Group-wide specialized professional training programs.
• Conduct research and benchmarking to resolve audit issues, identify gaps and support IA function.
Job Specific Accountabilities (Part 3)
Generic Accountabilities
Supervision
• Plan, supervise and coordinate all activities in the assigned area to meet functional objectives.
• Train and develop the assigned staff on relevant skills to enable them to become proficient on the job and deliver the respective section objectives.
Budgets
• Provide input for preparation of the Function / Department / Section budgets, assist in the implementation of the approved Budget, and work plans to deliver Section objectives.
• Investigate and highlight any significant variances to support effective performance and cost control.
Policies, Systems, Processes & Procedures
• Implement approved Function/ Department/ Section policies, processes, systems, standards and procedures in order to support execution of the work programs in line with Company and International standards.
Performance Management
• Contribute to the achievement of the approved Performance Objectives for the Function/ Department/ Section in line with the Company Performance framework.
Innovation and Continuous Improvement
• Design and implement new tools and techniques to improve the quality and efficiency of operational processes.
• Identify improvements in internal processes against best practices in pursuit of greater efficiency in line with best industry standards in order to define intelligent solutions for issues confronting the function.
Health, Safety, Environment (HSE) and Sustainability
• Comply with relevant HSE policies, procedures, controls, applicable legislation, and sustainability guidelines in line with international standards, best practices and ADNOC Code of Practices.
Reports
• Provide inputs to prepare MIS and progress reports for Company Management.
Generic Accountabilities (continue)
Internal Communications & Working Relationships
• Regular Contacts with operational level management within all auditable departments throughout ADNOC.
• Frequent contacts within ADNOC at all levels of Management up to SVPs/Directors with respect to audit programs, the conduct of the audits, audit reports, findings and recommendations.
• Regular contacts with Management within the assigned ADNOC Group Companies up to Manager level with regards to the Group Company audits.
External Communications & Working Relationships
• Occasional Contacts with Internal Audit Service Provider(s) to coordinate audit activities, when required.
• Occasional Contacts, as required, with Abu Dhabi Accountability Authority (ADAA) regarding government audits.
• Occasional Contacts with ADNOC External Auditors and other assurance providers to ensure adequate audit coverage and minimize duplicate efforts.
• Regular contacts with ADNOC Group Companies’ Internal Audit Managers with respect to knowledge sharing of audit standards, frameworks, methodologies, policies, processes and coordination across ADNOC Group Companies.
Minimum Qualification
Bachelor Degree in Computer Science or related IT discipline, Finance/ Auditing or equivalent discipline
Minimum Experience, Knowledge & Skills
• 8 years of relevant experience in IT internal auditing, with varied experience in oil and gas operations and their inherent challenges/risks in the context of corporate function.
• In-depth knowledge of International Professional Practices Framework for IT Assurance/IT Assurance Framework (ITAF) and other related frameworks/standards (e.g. COBIT, ITIL, ISO27000, NIST) and their interpretation/application to IS/IT auditing practice.
• Experience in managing and tracking time for different Internal Audit related activities.
• Awareness/knowledge of Operational Technology (OT) processes and systems
• In-depth knowledge of IT processes including, but not limited to, system development, infrastructure review, access right management and change management.
• Expertise in collecting and analysing complex data using data analytics tools, evaluating information and systems, and drawing logical conclusions
• Extensive knowledge of planning and project management areas
• Advance technical knowledge of different operating systems, databases, network infrastructure components (routers, switches, firewalls etc.) and ERP.
Professional Certifications
• IT audit certification, CISA, is mandatory.
• Other related certifications (CISSP, CISM, GIAC, etc.) are preferred.
Work Condition, Physical effort & Work Environment
Physical Effort
Minimal
Work Environment
Normally air-conditioned office environment, however exposed to prevailing weather conditions while in the operating sites / field visits.
Additional Details
Job Family / Sub Family: Governance/Audit
وصف الوظيفة
الغرض من الوظيفة
أداء تدقيقات مفوضة من البدء حتى النهاية، بما في ذلك التخطيط المسبق وعمليات الإغلاق مع تطبيق مفاهيم المخاطر والضوابط على السيناريوهات التي تم مواجهتها، وتحديد أية قضايا محتملة.
المساعدة في تقييمات المخاطر الدورية وتطوير خطط العمل المعتمدة على المخاطر التي تركز على مخاطر تقنية المعلومات.
المسؤوليات الوظيفية الخاصة (الجزء 1)
الأخلاقيات المهنية
• المساعدة في بدء/تعزيز إنشاء وتحسين مستمر لإطار حوكمة الشركة بما في ذلك إدارة المخاطر المؤسسية، مدونة سلوك الشركات، الأخلاقيات والقيم.
خطة التدقيق الداخلي
• المساعدة في تطوير الخطة التدقيقية السنوية (AAP) بناءً على نتائج تمارين تقييم المخاطر مع التركيز على مخاطر تكنولوجيا المعلومات.
• المشاركة في مراجعة وتحديث عالَم التدقيق لتقنية المعلومات لضمان تغطيتها لجميع مخاطر تكنولوجيا المعلومات.
• تقديم مدخلات للتقارير الدورية عن أنشطة تدقيق تكنولوجيا المعلومات وأداءها مقارنةً بخططها، والتعرضات الكبيرة للمخاطر، وقضايا الحوكمة/الضبط وغيرها من المسائل ذات الصلة.
تنفيذ التدقيق
• قيادة مدققي IT في فحص وتحليل السجلات من خلال تنفيذ خطوات برنامج التدقيق للتدقيقات المعينة.
• تطوير برنامج تدقيق تفصيلي / مصفوفة المخاطر والضبط (RCM) للتدقيق المعين بما في ذلك الأهداف والمخاطر المحتملة والضوابط الرئيسية وإجراءات التدقيق واستخدام تقنيات وأدوات التدقيق لتقييم الحوكمة والمخاطر وعمليات الضبط، وتقديم برنامج التدقيق للإدارة للمراجعة والموافقة.
• تحديد إجراءات التدقيق التي ستُطبق، بما في ذلك استخدام تقنيات تدقيق أنظمة المعلومات، تحليل البيانات، طريقة العينة الإحصائية أو غيرها.
• ضمان توثيق كافٍ للأوراق العمل وجميع المعلومات ذات الصلة باستمرار وتحديثها في نظام إدارة التدقيق الآلي وفق قوالب وإجراءات التدقيق المحددة سلفاً.
• تحديد الأنظمة والبيانات/المعلومات ذات الصلة وتقييمها وتوثيقها وتقييمها.
• تقييم كفاية الإجراءات التصحيحية التي اتخذها الإدارة بناءً على توصيات التدقيق من خلال عمليات متابعة التدقيق ومراجعة وتحديث حالة خطط العمل الإدارية بشكل دوري.
• ضمان تحقيق أهداف التدقيق المعتمدة مع تغطية كافية لجميع المجالات ذات الصلة وجمع أدلة تدقيق كافية لدعم الاستنتاجات والتوصيات، وفقاً للمعايير المهنية للتدقيق.
• المشاركة في إجراء المراجعات الخاصة وتولي المهام الإدارية كما يوجه رئيس التدقيق الداخلي.
• الإشراف على التدقيقات وفقاً لمصفوفة المخاطر والضبط المعتمدة والمعايير المهنية الخاصة بالتدقيق الداخلي.
• ضمان أن المهام الموكلة للموظفين الشباب تُنفّذ بشكل كاف وتكون النتائج وفق إجراءات وضوابط ADNOC للتدقيق الداخلي ومعاييره الجودة.
• تحديد مناطق عالية المخاطر ونقاط التحكم الأساسية للنظام قيد المراجعة.
تقارير التدقيق
• إعداد تقرير التدقيق مع الخلاصة، مع التعبير عن الآراء المهنية حول كفاية وفعالية إدارة المخاطر والأنظمة الرقابية والكفاءة التي تُنفذ بها الأنشطة. التوصية بخيارات تحسين لتصحيح العيوب المبلغ عنها، للمراجعة من قِبل رئيس القسم/مدير الإدارة.
• التوصية بتحسينات عملية في حوكمة IT والمخاطر والعمليات الرقابية للمساعدة في تحقيق أهداف أعمال الشركة.
• المتابعة على الردود على مسودات وتقريرات التدقيق النهائية ومراجعة كفاية الإجراءات التصحيحية المتخذة بناءً على توصيات التدقيق/خيارات التحسين.
المسؤوليات الوظيفية الخاصة (الجزء 2)
• المساعدة في الإبلاغ الدوري إلى اللجنة التدقيقية والإدارة العليا عن أنشطة التدقيق الداخلي، الأداء، تعرّضات المخاطر الكبيرة، الضوابط/المسائل الحوكمة وغيرها من الأمور ذات الصلة.
التنسيق
• مساعدة أمين لجنة التدقيق في ترتيب اجتماعات اللجنة، إعداد الأجندة وتوثيق الاجتماعات (MOMs) والتقارير عن إطار حوكمة الشركات والضوابط العامة ومسائل أخرى كما هو منصوص في ميثاق لجنة التدقيق.
• عقد ورش عمل أو عروض توضيحية لخلق الوعي بوظيفة التدقيق الداخلي وإظهار قيمة مضافة عبر ADNOC.
• التواصل مع الإدارة Internal Audit بشأن القضايا المحددة لضمان معالجة المناطق عالية المخاطر المحتملة بشكل فوري وفعال.
• تقديم مشورة مهنية بشأن ميثاق لجنة التدقيق للمجموعات والشركات،
ميثاق IA ومنهجية/إجراءات تدقيق IT. توفر المساعدة في إنشاء لجان التدقيق المجمّعة/وظائف IA والحوكمة ذات الصلة، عندما يتم تكليفها.
• المشاركة في بدء وترتيب برامج التدريب المهني المتخصصة على مستوى المجموعة.
• إجراء البحوث والمقارنات لحل قضايا التدقيق، وتحديد الثغرات ودعم وظيفة IA.
المسؤوليات الوظيفية الخاصة (الجزء 3)
المسؤوليات العامة
الإشراف
• الخطط والإشراف وتنسيق جميع الأنشطة في المنطقة المعينة لتحقيق الأهداف الوظيفية.
• تدريب وتطوير العاملين المعنيين بالمهارات ذات الصلة لتمكينهم من العمل بكفاءة وتحقيق أهداف القسم المعني.
الميزانيات
• تقديم مدخلات للإعداد ميزانيات الوظيفة/الإدارة/القسم، والمساعدة في تنفيذ الميزانية المعتمدة وخطط العمل لتحقيق أهداف القسم.
• التحقيق وتسليط الضوء على أي فروقات كبيرة لدعم الأداء الفعال والرقابة على التكاليف.
السياسات والأنظمة والعمليات والإجراءات
• تنفيذ سياسات وإجراءات ووظائف القسم وفق المعايير المدعومة لضمان تنفيذ برامج العمل وفق المعايير الدولية للشركة.
إدارة الأداء
• المساهمة في تحقيق أهداف الأداء المعتمدة للقسم/الإدارة/القسم وفق إطار أداء الشركة.
الابتكار والتحسين المستمر
• تصميم وتنفيذ أدوات وتقنيات جديدة لتحسين جودة وكفاءة عمليات التشغيل.
• تحديد التحسينات في العمليات الداخلية مقارنةً بأفضل الممارسات في سبيل تحقيق كفاءة أعلى وفق أفضل المعايير الصناعة لتحديد حلول ذكية للمشكلات التي تواجه الوظيفة.
الصحة والسلامة والبيئة (HSE) والاستدامة
• الامتثال لسياسات وإجراءات HSE المعمول بها والضوابط والتشريعات وقواعد الاستدامة بما يتماشى مع المعايير الدولية وأفضل الممارسات ومدونة ممارسات ADNOC.
التقارير
• توفير مدخلات لإعداد تقارير MIS وتقدم تقارير لإدارة الشركة.
المسؤوليات العامة (استمرار)
الاتصالات الداخلية والعلاقات العملية
• التواصل المنتظم مع إدارة المستوى التشغيلي في جميع أقسام التدقيق ضمن ADNOC.
• التواصل المتكرر مع الإدارة في جميع مستويات الإدارة حتى كبار المدراء/النواب مع احترام برامج التدقيق، تنفيذ التدقيق، تقارير التدقيق، النتائج والتوصيات.
• التواصل المنتظم مع الإدارة ضمن شركات ADNOC Group المعينة حتى مستوى المدير فيما يتعلق بتدقيق الشركة القُطرية.
الاتصالات الخارجية والعلاقات العملية
• اتصالات عرضية مع مزودي خدمات التدقيق الداخلي لتنظيم أنشطة التدقيق، عندما تكون مطلوبة.
• اتصالات عرضية، حسب الحاجة، مع هيئة المساءلة أبوظبي (ADAA) بشأن التدقيقات الحكومية.
• اتصالات عرضية مع مدققي ADNOC الخارجيين ومقدمي ضمان آخرين لضمان تغطية تدقيق كافية وتقليل الجهود المكررة.
• التواصل المنتظم مع مديري التدقيق الداخلي لدى شركات المجموعة المعنية بمشاركة المعرفة بمعايير التدقيق والأطر والمنهجيات والسياسات والعمليات والتنسيق عبر شركات ADNOC Group.
المؤهل الأدنى
درجة البكالوريوس في علوم الكمبيوتر أو تخصص IT ذي صلة، المالية/ التدقيق أو تخصص مكافئ
الخبرة الدنيا والمعرفة والمهارات
• 8 سنوات خبرة ذات صلة في التدقيق الداخلي لتكنولوجيا المعلومات، مع خبرة متنوعة في عمليات النفط والغاز وتحدياتها/مخاطرها ضمن سياق الوظيفة المؤسسية.
• معرفة عميقة بإطار الممارسات المهنية الدولية للضمان IT/إطار ضمان IT (ITAF) وغيرها من الأطر/المعايير ذات الصلة (مثلاً COBIT، ITIL، ISO27000، NIST) وتفسيرها/تطبيقها في ممارسات تدقيق IS/IT.
• خبرة في إدارة وتتبع الوقت للأنشطة المختلفة المتعلقة بالتدقيق الداخلي.
• الوعي/المعرفة بعمليات ونظم التكنولوجيا التشغيلية (OT)
• معرفة عميقة بعمليات تكنولوجيا المعلومات بما فيها، على سبيل المثال لا الحصر، تطوير الأنظمة، مراجعة البنية التحتية، إدارة حقوق الوصول وتغيير الإدارة.
• خبرة في جمع وتحليل البيانات المعقدة باستخدام أدوات تحليل البيانات، تقييم المعلومات والأنظمة، واستنتاجات منطقية
• معرفة واسعة بمناطق التخطيط وإدارة المشاريع
• معرفة تقنية متقدمة بأنظمة تشغيل مختلفة، قواعد بيانات، مكونات بنية الشبكة (routers, switches, firewalls إلخ) وERP.
الشهادات المهنية
• شهادة تدقيق IT، CISA، فرضية إلزامية.
• شهادات أخرى ذات صلة (CISSP، CISM، GIAC، إلخ) يفضل وجودها.
ظروف العمل، الجهد البدني والبيئة العمل
الجهد البدني
قليل
بيئة العمل
عادةً بيئة مكتبية مكيفة، لكن معرضة لظروف الطقس السائدة أثناء المواقع التشغيلية/الزيارات الميدانية.
تفاصيل إضافية
فئة الوظيفة/الفئة الفرعية: الحوكمة/التدقيق