IT Audit and Compliance Officer
Listing reference: cartr_000606
Listing status: Under Review
Apply by: 2 April 2025
Position summary
Industry: IT & Internet
Job category: Internal Auditing
Location: Rosebank
Contract: Permanent
EE position: No
Introduction
A bit about us
We’re a world-leading smart mobility SaaS tech company with over 1.9 million subscribers across 27 countries. Our teams are collaborative, vibrant and fast-growing, and all team members are empowered with the freedom to influence our products and technology.
Are you curious, innovative and passionate?
Do you take ownership, embrace challenges, and love problem-solving?
We are looking for an IT Auditor to evaluate the organization's information technology systems, security protocols, and compliance with relevant regulations.
Job description
Responsibilities
- Identify IT risks and weaknesses in IT Systems, applications and networks.
- Develop and execute IT audit plans in line with industry standards.
- Evaluate the effectiveness of IT security measures, firewalls, and access controls.
- Review IT policies, procedures, and compliance with standardised frameworks like ISO 27001.
- Assess data integrity, backup, and disaster recovery processes.
- Ensure adherence and compliance to applicable laws such as SOX and HIPAA.
- Recommend and implement corrective actions for non-compliance issues.
- Test and validate the applicable six ITGC audit controls including physical and environmental security, logical security, change management, backup and recovery, incident management and information security.
- Assess internal Enterprise Resource Planning systems and other financial applications.
- Prepare audit reports with findings and risk mitigation strategies.
- Advise on improvements to IT security, governance, and operations.
- Work with IT, security, and business teams to enhance controls.
- Provide guidance on emerging IT risks and industry best practices.
Minimum requirements
Requirements
- Matric
- Relevant Tertiary qualification
- Certified Information Systems Auditor (CISA) is advantageous
- Certified Information Systems Security Professional (CISSP) is advantageous
- Certified Information Security Manager (CISM) is advantageous
- Knowledge of IT frameworks (COBIT, NIST, ISO 27001)
- Knowledge of ITGC Controls
- Familiarity with cybersecurity, network security, and database security.
- Proficiency in audit tools and/or data analytics platforms.
- Strong analytical and problem-solving abilities.
- Effective communication and report-writing skills.
- Attention to detail and critical thinking.
- Strong planning and organization skills