نحن نوظف مدققاً داخلياً أول لتكنولوجيا المعلومات لأحد عملائنا في دبي.
هذا الدور هو دور مساهم فردي ضمن فريق تدقيق داخلي صغير يتكون من أربعة أفراد، ويقدم تقاريره إلى مدير التدقيق الداخلي. سيقوم المرشح الناجح بقيادة ودعم مبادرات تدقيق تكنولوجيا المعلومات والحوكمة والمخاطر والامتثال بشكل مستقل، مع العمل بشكل وثيق مع فرق تكنولوجيا المعلومات وأصحاب المصلحة في الأعمال والمراجعين الخارجيين والبائعين. سيلعب هذا الدور دوراً رئيسياً في تعزيز إطار عمل حوكمة ومخاطر وامتثال تكنولوجيا المعلومات في المؤسسة وضمان التوافق المستمر مع متطلبات ISO 27001 وDESC ISR.
المسؤوليات: إجراء عمليات تدقيق تكنولوجيا المعلومات القائمة على المخاطر لتقييم حوكمة تكنولوجيا المعلومات، وضوابط تكنولوجيا المعلومات العامة (ITGCs)، وضوابط التطبيقات، والضوابط الداخلية المتعلقة بالتكنولوجيا. دعم رئيس التدقيق الداخلي في الحفاظ على إطار عمل حوكمة ومخاطر وامتثال تكنولوجيا المعلومات (GRC) وتحسينه باستمرار. تطوير ومراجعة وصيانة سياسات تكنولوجيا المعلومات، والمعايير، والإجراءات التشغيلية القياسية (SOPs)، وسجلات المخاطر، وتقييمات تأثير الأعمال، ووثائق استمرارية الأعمال (BCP) والتعافي من الكوارث (DR) بما يتماشى مع ISO 27001:2022، وDESC ISR، والأطر الأخرى ذات الصلة. تقييم الضوابط عبر نظام تخطيط موارد المؤسسات (ERP)، وZoho، وغيرها من تطبيقات المؤسسة، بما في ذلك إدارة الوصول، والنسخ الاحتياطي، وإدارة الحوادث، والتعافي من الكوارث، واستمرارية الأعمال. تنسيق عمليات التدقيق الداخلية والخارجية، بما في ذلك تدقيق ISO 27001 للمراقبة/إعادة الاعتماد وتدقيق DESC ISR؛ إدارة جمع الأدلة، والتواصل مع المدققين، والإجراءات التصحيحية، وإغلاق النتائج. دعم وتتبع مشاركات اختبار الاختراق وتقييم الثغرات (VAPT)، وإجراءات المعالجة، ودورات إعادة الاختبار بالتنسيق مع فرق تكنولوجيا المعلومات والأمن. إجراء تقييمات المخاطر للأنظمة والمشاريع والبائعين ومشاركات الطرف الثالث الجديدة. إعداد تقارير التدقيق، ولوحات معلومات الامتثال، ووثائق جاهزية التدقيق، وتقارير الحوكمة الجاهزة للعرض على مجلس الإدارة لأصحاب المصلحة الداخليين. إدارة وثائق مخاطر البائعين والأطراف الثالثة، بما في ذلك تقارير SOC، والشهادات، والمتطلبات الأمنية، واتفاقيات مستوى الخدمة (SLAs). العمل بشكل مستقل مع التنسيق بثقة مع كبار أصحاب المصلحة الداخليين والمراجعين والبائعين.
المتطلبات: درجة البكالوريوس في تكنولوجيا المعلومات، أو علوم الحاسب، أو أمن المعلومات، أو الأمن السيبراني، أو مجال ذي صلة. 4-7 سنوات من الخبرة في تدقيق تكنولوجيا المعلومات، وحوكمة ومخاطر وامتثال تكنولوجيا المعلومات، ويفضل أن تكون مكتسبة ضمن بيئة استشارية. خبرة عملية قوية في إجراء عمليات تدقيق تكنولوجيا المعلومات وتقييم ضوابط تكنولوجيا المعلومات العامة (ITGCs)، وضوابط التطبيقات، ومخاطر تكنولوجيا المعلومات، والامتثال، وأطر الحوكمة. معرفة عملية بمعيار ISO/IEC 27001:2022 ولائحة أمن المعلومات لمركز دبي للأمن الإلكتروني (DESC ISR). خبرة في تطوير سياسات تكنولوجيا المعلومات، وسجلات المخاطر، وعمليات VAPT، وإدارة مخاطر البائعين، وضوابط BCP وDR. القدرة على العمل بشكل مستقل في فريق صغير مع التنسيق بثقة مع أصحاب المصلحة الداخليين والمراجعين والبائعين. ستكون الخبرة داخل جهة حكومية، أو سلطة منطقة حرة، أو بيئة مماثلة خاضعة للتنظيم ميزة إضافية كبيرة. ستكون شهادات CIA، أو CISA، أو ISO 27001 Lead Auditor/Lead Implementer، أو CRISC، أو COBIT ميزة إضافية.
إذا كنت تستوفي المعايير المذكورة أعلاه وكنت مهتماً باستكشاف هذه الفرصة، يرجى التقديم بسيرتك الذاتية المحدثة.
We are hiring a Senior IT Internal Auditor for one of our Dubai-based clients.
This is an individual-contributor role within a lean Internal Audit team of four, reporting to the Internal Audit Manager. The successful candidate will independently lead and support IT audit, governance, risk, and compliance initiatives while working closely with IT teams, business stakeholders, external auditors, and vendors. The role will play a key part in strengthening the organisation’s IT GRC framework and ensuring ongoing alignment with ISO 27001 and DESC ISR requirements.
Responsibilities:Conduct risk-based IT audits to assess IT governance, IT General Controls (ITGCs), application controls, and technology-related internal controls. Support the Head of Internal Audit in maintaining and continuously improving the IT Governance, Risk and Compliance (GRC) framework. Develop, review, and maintain IT policies, standards, SOPs, risk registers, Business Impact Assessments, BCP and DR documentation in line with ISO 27001:2022, DESC ISR, and other relevant frameworks. Evaluate controls across ERP, Zoho, and other enterprise applications, including access management, backup, incident management, disaster recovery, and business continuity. Coordinate internal and external audits, including ISO 27001 surveillance/recertification and DESC ISR audits; manage evidence collection, auditor liaison, corrective actions, and closure of findings. Support and track VAPT engagements, remediation actions, and retest cycles in coordination with IT and security teams. Conduct risk assessments for new systems, projects, vendors, and third-party engagements. Prepare audit reports, compliance dashboards, audit-readiness documentation, and board-ready governance reports for internal stakeholders. Manage vendor and third-party risk documentation, including SOC reports, certifications, security requirements, and SLAs. Work independently while coordinating confidently with senior internal stakeholders, auditors, and vendors.
Requirements:Bachelor’s degree in Information Technology, Computer Science, Information Security, Cybersecurity, or a related field.4–7 years of experience in IT Audit, IT Governance, Risk and Compliance, ideally gained within a consultancy environment. Strong hands-on experience conducting IT audits and assessing ITGCs, application controls, IT risk, compliance, and governance frameworks. Working knowledge of ISO/IEC 27001:2022 and DESC Information Security Regulation (ISR). Experience with IT policy development, risk registers, VAPT processes, vendor risk management, BCP, and DR controls. Ability to work independently in a small team while coordinating confidently with internal stakeholders, auditors, and vendors. Experience within a government entity, free zone authority, or similarly regulated environment will be highly preferred. CIA, CISA, ISO 27001 Lead Auditor/Lead Implementer, CRISC, or COBIT certifications will be advantageous.
If you meet the above criteria and are interested in exploring this opportunity, please apply with your updated CV.