Job description
Job Description
We are currently looking for ICFR IT Controls Testing - Banking for our UAE operations with the following terms & conditions.
Job Purpose:
To support the Finance Division in maintaining and enhancing the Bank’s Internal Control over Financial Reporting (ICFR) framework through the independent testing and evaluation of General IT Controls (GITCs), IT Application Controls (ITACs), Interface Controls, and Information Produced by the Entity (IPE). The role is responsible for assessing control effectiveness, identifying control deficiencies, supporting remediation activities, and collaborating with Finance, IT, and audit stakeholders to ensure the integrity, reliability, and compliance of systems and processes supporting financial reporting.
Requirements / Work Experience/ Qualification Specification:
• Bachelor’s degree in information systems, Information Technology, Accounting, Finance, Computer Science, or a related field.
• Professional certification such as CISA, CIA, CPA, CA, ACCA, CRISC, CISSP, or equivalent preferred.
• 4–7 years of experience in IT Audit, ICFR/SOX Compliance, IT Risk, Internal Audit, or Risk Advisory, preferably within banking or financial services.
• Hands-on experience in GITC, ITAC, Interface Controls, and IPE testing.
• Knowledge of ICFR, COSO, and COBIT frameworks.
• Experience with core banking systems, ERP platforms (e.g., Finacle, SAP, Oracle), and financial reporting applications.
• Understanding of system interfaces, database concepts, and automated business processes.
• Experience supporting internal/external audits and regulatory reviews.
• Proficiency in Microsoft Excel and data analysis techniques.
• Strong analytical, communication, documentation, stakeholder management, and problem-solving skills, with the ability to work independently and meet deadlines.
Main Responsibilities and Accountabilities:
ICFR IT Control Testing:
• Perform testing of the design and operating effectiveness of IT controls supporting financial reporting.
• Document process walkthroughs, risk and control assessments, testing workpapers, and conclusions.
• Identify control deficiencies, assess their impact, and track remediation activities.
• Ensure testing is performed in line with ICFR methodology and audit requirements.
GITC (General IT Controls):
• Test key IT controls including User Access Management, privileged access, segregation of duties, change management, and IT operations controls.
• Validate the completeness and accuracy of Information Produced by the Entity (IPE).
• Coordinate with IT and business stakeholders to obtain and assess supporting evidence.
IT Application Controls (ITAC):
• Test automated controls, system configurations, workflows, calculations, and validations impacting financial reporting.
• Assess the reliability of system functionality and key reports used in financial processes.
• Validate the completeness, accuracy, and integrity of system-generated information relied upon for control execution.
Interface Testing & Data Integrity:
• Evaluate interfaces between systems supporting financial reporting.
• Verify the completeness, accuracy, and timeliness of data transfers through reconciliations and exception analysis.
• Assess interface monitoring, error handling, logging, and exception management controls.
• Escalate interface failures, data integrity issues, and control exceptions.
Audit Coordination & Reporting:
• Support internal and external audits by providing testing documentation, evidence, and management responses.
• Monitor and report on control deficiencies, audit findings, and remediation plans.
• Prepare testing summaries, status reports, and management updates on IT control effectiveness.
Terms and conditions
Joining time frame: Immediate
وصف الوظيفة
الوصف الوظيفي
نحن حاليًا نبحث عن ICFR لاختبارات ضوابط تكنولوجيا المعلومات - البنوك لعملياتنا في الإمارات مع الشروط والأحكام التالية.
الغرض من الوظيفة:
لدعم قسم المالية في الحفاظ على إطار الرقابة الداخلية على التقارير المالية (ICFR) وتطويره من خلال الاختبار المستقل وتقييم ضوابط تكنولوجيا المعلومات العامة (GITCs)، وضوابط تطبيقات تكنولوجيا المعلومات (ITACs)، وضوابط الواجهة، والمعلومات التي ينتجها الكيان (IPE). السياسة مسؤولة عن تقييم فاعلية الرقابة، وتحديد عيوب الرقابة، ودعم أنشطة الإصلاح، والتعاون مع أصحاب المصلحة في المالية وتقنية المعلومات والتدقيق لضمان السلامة والموثوقية والامتثال للأنظمة والعمليات التي تدعم التقارير المالية.
المتطلبات/الخبرة العملية/المواصفة المؤهلة:
• درجة البكالوريوس في نظم المعلومات، تكنولوجيا المعلومات، المحاسبة، المالية، علوم الحاسوب، أو مجال ذي صلة.
• شهادة مهنية مثل CISA، CIA، CPA، CA، ACCA، CRISC، CISSP، أو ما يعادلها مفضلة.
• 4–7 سنوات من الخبرة في تدقيق تكنولوجيا المعلومات، امتثال ICFR/SOX، مخاطر تقنية المعلومات، التدقيق الداخلي، أو استشارات المخاطر، ويُفضل ضمن القطاع المصرفي أو الخدمات المالية.
• خبرة عملية في اختبار GITC، ITAC، وضوابط الواجهة، وIPE.
• معرفة بإطارات ICFR، COSO، وCOBIT.
• خبرة مع أنظمة البنوك الأساسية، منصات ERP (مثلاً Finacle، SAP، Oracle)، وتطبيقات التقارير المالية.
• فهم لواجهات النظام، مفاهيم قواعد البيانات، وعمليات الأعمال الآلية.
• خبرة في دعم التدقيقات الداخلية/الخارجية والمراجعات التنظيمية.
• البراعة في Microsoft Excel وتقنيات تحليل البيانات.
• مهارات تحليلية قوية، واتصال، وتوثيق، وإدارة أصحاب المصلحة، وحل المشكلات، مع القدرة على العمل بشكل مستقل والالتزام بالمواعيد النهائية.
المسؤوليات الرئيسية والمحاسبة:
اختبار ضوابط IT لـ ICFR:
• إجراء اختبارات تصميم وفعالية تشغيلية لضوابط تكنولوجيا المعلومات الداعمة للتقارير المالية.
• توثيق استعراضات العمليات، وتقييمات المخاطر والضوابط، ودفاتر الاختبار، والاستنتاجات.
• تحديد عيوب الرقابة، وتقييم أثرها، وتتبع أنشطة الإصلاح.
• التأكد من أن الاختبار يتم وفق منهج ICFR ومتطلبات التدقيق.
GITC (ضوابط تكنولوجيا المعلومات العامة):
• اختبار ضوابط تكنولوجيا المعلومات الرئيسية مثل إدارة وصول المستخدمين، والوصول المميز، وفصل المهام، وإدارة التغيير، وضوابط تشغيل تكنولوجيا المعلومات.
• التحقق من اكتمال ودقة المعلومات التي ينتجها الكيان (IPE).
• التنسيق مع الجهات المعنية بتقنية المعلومات وبيئة الأعمال للحصول على الأدلة الداعمة وتقييمها.
ضوابط تطبيقات تكنولوجيا المعلومات (ITAC):
• اختبار الضوابط الآلية، وتكوينات النظام، ومسارات العمل، والحسابات، والتحققات التي تؤثر على التقارير المالية.
• تقييم موثوقية وظائف النظام والتقارير الرئيسية المستخدمة في العمليات المالية.
• التحقق من اكتمال ودقة وتكامل المعلومات المُولَّدة من النظام التي تعتمد عليها تنفيذ الضوابط.
اختبار الواجهة وتكامل البيانات:
• تقييم الواجهات بين الأنظمة الداعمة للتقارير المالية.
• التحقق من اكتمال ودقة وتوقيت تحويل البيانات من خلال التسوية والتحليل الاستثنائي.
• تقييم مراقبة الواجهات، ومعالجة الأخطاء، وتسجيل السجلات، والتحكم في الاستثناءات.
• تصعيد فشلات الواجهة، قضايا تكامل البيانات، واستثناءات الرقابة.
تنسيق وتقرير التدقيق:
• دعم التدقيقات الداخلية والخارجية من خلال توفير وثائق الاختبار والأدلة واستجابات الإدارة.
• مراقبة والتبليغ عن عيوب الرقابة، نتائج التدقيق، وخطط الإصلاح.
• إعداد ملخصات الاختبار، تقارير الحالة، وتحديثات الإدارة حول فاعلية ضوابط تكنولوجيا المعلومات.
الشروط والأحكام
إطار الانضمام: فوري