On-site Full Time
--
Talent Higher

Job Details

We are hiring a Senior IT Internal Auditor for one of our Dubai-based clients.
This is an individual-contributor role within a lean Internal Audit team of four, reporting to the Internal Audit Manager. The successful candidate will independently lead and support IT audit, governance, risk, and compliance initiatives while working closely with IT teams, business stakeholders, external auditors, and vendors. The role will play a key part in strengthening the organisation’s IT GRC framework and ensuring ongoing alignment with ISO 27001 and DESC ISR requirements.
Responsibilities:Conduct risk-based IT audits to assess IT governance, IT General Controls (ITGCs), application controls, and technology-related internal controls. Support the Head of Internal Audit in maintaining and continuously improving the IT Governance, Risk and Compliance (GRC) framework. Develop, review, and maintain IT policies, standards, SOPs, risk registers, Business Impact Assessments, BCP and DR documentation in line with ISO 27001:2022, DESC ISR, and other relevant frameworks. Evaluate controls across ERP, Zoho, and other enterprise applications, including access management, backup, incident management, disaster recovery, and business continuity. Coordinate internal and external audits, including ISO 27001 surveillance/recertification and DESC ISR audits; manage evidence collection, auditor liaison, corrective actions, and closure of findings. Support and track VAPT engagements, remediation actions, and retest cycles in coordination with IT and security teams. Conduct risk assessments for new systems, projects, vendors, and third-party engagements. Prepare audit reports, compliance dashboards, audit-readiness documentation, and board-ready governance reports for internal stakeholders. Manage vendor and third-party risk documentation, including SOC reports, certifications, security requirements, and SLAs. Work independently while coordinating confidently with senior internal stakeholders, auditors, and vendors.
Requirements:Bachelor’s degree in Information Technology, Computer Science, Information Security, Cybersecurity, or a related field.4–7 years of experience in IT Audit, IT Governance, Risk and Compliance, ideally gained within a consultancy environment. Strong hands-on experience conducting IT audits and assessing ITGCs, application controls, IT risk, compliance, and governance frameworks. Working knowledge of ISO/IEC 27001:2022 and DESC Information Security Regulation (ISR). Experience with IT policy development, risk registers, VAPT processes, vendor risk management, BCP, and DR controls. Ability to work independently in a small team while coordinating confidently with internal stakeholders, auditors, and vendors. Experience within a government entity, free zone authority, or similarly regulated environment will be highly preferred. CIA, CISA, ISO 27001 Lead Auditor/Lead Implementer, CRISC, or COBIT certifications will be advantageous.
If you meet the above criteria and are interested in exploring this opportunity, please apply with your updated CV.

Similar Jobs

About Talent Higher
UAE, Dubai
Management Consulting