IT Audit and Compliance Officer

Listing reference: cartr_000606
Listing status: Under Review
Apply by: 2 April 2025
Position summary
Industry: IT & Internet
Job category: Internal Auditing
Location: Rosebank
Contract: Permanent
EE position: No
Introduction
A bit about us We’re a world-leading smart mobility SaaS tech company with over 1.9 million subscribers across 27 countries. Our teams are collaborative, vibrant and fast-growing, and all team members are empowered with the freedom to influence our products and technology. Are you curious, innovative and passionate? Do you take ownership, embrace challenges, and love problem-solving? We are looking for an IT Auditor to evaluate the organization's information technology systems, security protocols, and compliance with relevant regulations.
Job description

Responsibilities
  • Identify IT risks and weaknesses in IT Systems, applications and networks. 
  • Develop and execute IT audit plans in line with industry standards.
  • Evaluate the effectiveness of IT security measures, firewalls, and access controls.
  • Review IT policies, procedures, and compliance with standardised frameworks like ISO 27001.
  • Assess data integrity, backup, and disaster recovery processes.
  • Ensure adherence and compliance to applicable laws such as SOX and HIPAA.
  • Recommend and implement corrective actions for non-compliance issues.
  • Test and validate the applicable six ITGC audit controls including physical and environmental security, logical security, change management, backup and recovery, incident management and information security.  
  • Assess internal Enterprise Resource Planning systems and other financial applications.
  • Prepare audit reports with findings and risk mitigation strategies.
  • Advise on improvements to IT security, governance, and operations.
  • Work with IT, security, and business teams to enhance controls.
  • Provide guidance on emerging IT risks and industry best practices.

Minimum requirements

Requirements

  • Matric
  • Relevant Tertiary qualification
  • Certified Information Systems Auditor (CISA) is advantageous
  • Certified Information Systems Security Professional (CISSP) is advantageous
  • Certified Information Security Manager (CISM) is advantageous
  • Knowledge of IT frameworks (COBIT, NIST, ISO 27001)
  • Knowledge of ITGC Controls
  • Familiarity with cybersecurity, network security, and database security.
  • Proficiency in audit tools and/or data analytics platforms.
  • Strong analytical and problem-solving abilities.
  • Effective communication and report-writing skills.
  • Attention to detail and critical thinking.
  • Strong planning and organization skills

Our website uses cookies so that we can provide you with the best user experience. By continuing to use our website, you agree to our use of cookies.