Job description
Job Description
We are currently looking for ICFR IT Controls Testing - Banking for our UAE operations with the following terms & conditions.
Job Purpose:
To support the Finance Division in maintaining and enhancing the Bank’s Internal Control over Financial Reporting (ICFR) framework through the independent testing and evaluation of General IT Controls (GITCs), IT Application Controls (ITACs), Interface Controls, and Information Produced by the Entity (IPE). The role is responsible for assessing control effectiveness, identifying control deficiencies, supporting remediation activities, and collaborating with Finance, IT, and audit stakeholders to ensure the integrity, reliability, and compliance of systems and processes supporting financial reporting.
Requirements / Work Experience/ Qualification Specification:
• Bachelor’s degree in information systems, Information Technology, Accounting, Finance, Computer Science, or a related field.
• Professional certification such as CISA, CIA, CPA, CA, ACCA, CRISC, CISSP, or equivalent preferred.
• 4–7 years of experience in IT Audit, ICFR/SOX Compliance, IT Risk, Internal Audit, or Risk Advisory, preferably within banking or financial services.
• Hands-on experience in GITC, ITAC, Interface Controls, and IPE testing.
• Knowledge of ICFR, COSO, and COBIT frameworks.
• Experience with core banking systems, ERP platforms (e.g., Finacle, SAP, Oracle), and financial reporting applications.
• Understanding of system interfaces, database concepts, and automated business processes.
• Experience supporting internal/external audits and regulatory reviews.
• Proficiency in Microsoft Excel and data analysis techniques.
• Strong analytical, communication, documentation, stakeholder management, and problem-solving skills, with the ability to work independently and meet deadlines.
Main Responsibilities and Accountabilities:
ICFR IT Control Testing:
• Perform testing of the design and operating effectiveness of IT controls supporting financial reporting.
• Document process walkthroughs, risk and control assessments, testing workpapers, and conclusions.
• Identify control deficiencies, assess their impact, and track remediation activities.
• Ensure testing is performed in line with ICFR methodology and audit requirements.
GITC (General IT Controls):
• Test key IT controls including User Access Management, privileged access, segregation of duties, change management, and IT operations controls.
• Validate the completeness and accuracy of Information Produced by the Entity (IPE).
• Coordinate with IT and business stakeholders to obtain and assess supporting evidence.
IT Application Controls (ITAC):
• Test automated controls, system configurations, workflows, calculations, and validations impacting financial reporting.
• Assess the reliability of system functionality and key reports used in financial processes.
• Validate the completeness, accuracy, and integrity of system-generated information relied upon for control execution.
Interface Testing & Data Integrity:
• Evaluate interfaces between systems supporting financial reporting.
• Verify the completeness, accuracy, and timeliness of data transfers through reconciliations and exception analysis.
• Assess interface monitoring, error handling, logging, and exception management controls.
• Escalate interface failures, data integrity issues, and control exceptions.
Audit Coordination & Reporting:
• Support internal and external audits by providing testing documentation, evidence, and management responses.
• Monitor and report on control deficiencies, audit findings, and remediation plans.
• Prepare testing summaries, status reports, and management updates on IT control effectiveness.
Terms and conditions
Joining time frame: Immediate
الوصف الوظيفي
وصف الوظيفة
نحن نبحث حاليًا عن ICFR IT Controls Testing - Banking لعملياتنا في الإمارات العربية المتحدة بالشروط والأحكام التالية.
الغرض من الوظيفة:
لدعم قسم المالية في الحفاظ وتعزيز إطار الرقابة الداخلية على التقارير المالية (ICFR) من خلال الاختبار والتقييم المستقلين للضوابط التقنية العامة (GITCs) وضوابط تطبيقات تكنولوجيا المعلومات (ITACs) وضوابط الواجهات والمعلومات الناتجة عن الكيان (IPE). المسؤولية هي تقييم فاعلية الرقابة، وتحديد عيوب الرقابة، ودعم أنشطة الإصلاح، والتعاون مع المالية وتكنولوجيا المعلومات وأصحاب المراجعة لضمان السلامة والموثوقية والامتثال للأنظمة والعمليات التي تدعم التقرير المالي.
الأنظمة / خبرة العمل / المواصفات المؤهلة:
• درجة البكالوريوس في نظم المعلومات، تكنولوجيا المعلومات، المحاسبة، المالية، علوم الحاسوب، أو مجال ذو صلة.
• يفضل وجود شهادة مهنية مثل CISA، CIA، CPA، CA، ACCA، CRISC، CISSP أو ما يعادلها.
• من 4–7 سنوات خبرة في تدقيق تكنولوجيا المعلومات، الامتثال ICFR/SOX، مخاطر تكنولوجيا المعلومات، التدقيق الداخلي، أو استشارات المخاطر، ويفضل ضمن البنوك أو الخدمات المالية.
• خبرة عملية في اختبارات GITC، ITAC، ضوابط الواجهات، وIPE.
• معرفة بأطر ICFR وCOSO وCOBIT.
• خبرة مع أنظمة البنوك الأساسية، منصات ERP (مثل Finacle، SAP، Oracle)، وتطبيقات إعداد التقارير المالية.
• فهم لواجهات النظام، مفاهيم قاعدة البيانات، والعمليات التجارية الآلية.
• خبرة في دعم التدقيقات الداخلية/الخارجية والمراجعات التنظيمية.
• الكفاءة في Microsoft Excel وتقنيات تحليل البيانات.
• مهارات تحليلية قوية، تواصل، توثيق، إدارة أصحاب المصلحة، وحل المشكلات، والقدرة على العمل بشكل مستقل والالتزام بالمواعيد.
المسؤوليات والاختصاصات الرئيسية:
اختبار ضوابط ICFR IT:
• إجراء اختبارات تصميم وفعالية تشغيل الضوابط التقنية الداعمة للإبلاغ المالي.
• توثيق جولات العمليات وتقييم المخاطر والضوابط ووثائق الاختبار والاستنتاجات.
• تحديد عيوب الرقابة وتقييم أثرها وتتبع أنشطة الإصلاح.
• ضمان إجراء الاختبار وفقًا لمنهج ICFR ومتطلبات التدقيق.
GITC (الضوابط العامة لتكنولوجيا المعلومات):
• اختبار ضوابط تكنولوجيا المعلومات الرئيسية بما في ذلك إدارة وصول المستخدمين، والوصول المميز، وت segregation of duties، وإدارة التغيير، وضControls تشغيل تكنولوجيا المعلومات.
• التحقق من اكتمال ودقة المعلومات الناتجة عن الكيان (IPE).
• التنسيق مع أصحاب المصلحة في تكنولوجيا المعلومات والأعمال للحصول على الأدلة الداعمة وتقييمها.
ضوابط تطبيقات تكنولوجيا المعلومات (ITAC):
• اختبار الضوابط الآلية وتكوينات النظام وتدفقات العمل والحسابات والتحققات التي تؤثر على التقارير المالية.
• تقييم موثوقية وظائف النظام والتقارير الرئيسية المستخدمة في عمليات المالية.
• التحقق من اكتمال ودقة ونزاهة المعلومات التي ينتجها النظام والمعتمد عليها لأداء الضوابط.
اختبار الواجهات واتصال البيانات integrity:
• تقييم الواجهات بين الأنظمة الداعمة للإبلاغ المالي.
• التحقق من اكتمال ودقة ووقتهم لتحويل البيانات من خلال عمليات التسوية وتحليل الاستثناءات.
• تقييم مراقبة الواجهات، والتعامل مع الأخطاء، وتسجيل الأحداث، وإدارة الاستثناءات.
• تصعيد فشل الواجهات، ومشاكل سلامة البيانات، واستثناءات الرقابة.
تنسيق وReporting التدقيق:
• دعم التدقيقات الداخلية والخارجية من خلال تقديم وثائق الاختبار، والأدلة، واستجابات الإدارة.
• متابعة وتقرير عن عيوب الرقابة، ونتائج التدقيق، وخطط الإصلاح.
إعداد ملخصات الاختبار، وتحديثات الحالة، وتحديثات الإدارة حول فاعلية ضوابط تكنولوجيا المعلومات.
الشروط والأحكام
إطار الانضمام: فوري
\t