Bachelor's degree in Accountancy, Information Systems, Information Technology, Computer Science, Computer Engineering, or a related field.
- At least 3 years of experience in Internal Audit, IT Audit, IT Risk Management, IT Compliance, or IT Governance.
Strong knowledge of COBIT, ITIL, ISO 27001, IT governance, risk management, and information security principles.
- Good understanding of IT General Controls (ITGCs), internal controls, audit methodologies (IIA and ISACA), and the Data Privacy Act of 2012.
- Strong analytical, problem-solving, report writing, and presentation skills.
- Professional certifications such as CISA, CRISC, or CGEIT are an advantage.
Proficient in Microsoft Office applications; experience with ERP systems and data analytics tools is preferred.
High level of integrity, professionalism, and confidentiality.
Specific Duties And Responsibilities
Operational Functions
Plan and perform IT audits covering IT governance, cybersecurity, infrastructure, applications, ERP systems, and IT operations.
Review and evaluate IT policies, standards, and procedures to ensure adequacy, effectiveness, and compliance with Company policies and regulatory requirements.
Assess IT governance, risk management, and internal control processes using recognized frameworks such as COBIT, ITIL, and ISO 27001.
Evaluate IT general controls (ITGCs), including logical access, change management, system development, backup and recovery, and disaster recovery processes.
Identify control weaknesses, technology risks, and operational inefficiencies, and recommend practical corrective actions.
Monitor the implementation of audit recommendations and validate the effectiveness of corrective action plans.
Administrative Functions
Prepare audit programs, risk assessments, working papers, and audit reports. Maintain complete, accurate, and organized audit documentation.
Present audit findings and recommendations to Management and process owners.
Coordinate with the MIS Department and other business units during audit engagements. Assist in the preparation and execution of the annual IT Audit Plan.
Compliance and Audit Functions
Evaluate compliance with applicable laws, regulations, and Company policies, including the Data Privacy Act of 2012 and information security requirements.
Ensure adherence to internal audit standards, IT governance frameworks, and regulatory requirements.
Safeguard the confidentiality and integrity of audit information and Company data.
Report significant control deficiencies, compliance issues, and technology risks to the Internal Audit Manager.
Assist in external audits, regulatory reviews, and special investigations involving information systems.
Other Duties
Participate in process improvement initiatives and IT risk management activities.
Attend training programs related to IT audit, cybersecurity, governance, and compliance. Perform other duties and responsibilities that may be assigned by the Internal Audit Manager or Management.