وصف الوظيفة
Role Overview
Senior Auditor, IT (Digital Systems & Solutions) at ADNOC. This role is based at ADNOC and involves leading IT audit engagements across the organization.
Role Purpose
Perform assigned IT audit engagements from start to finish, including preplanning and wrap-up activities. Apply risk and control concepts to scenarios encountered and identify potential issues. Assist in periodic risk assessments and development of risk-based work plans focusing on IT risks.
Key Responsibilities
Professional Ethics & Governance
- Assist in initiating and promoting the establishment and continuous improvement of the Corporate Governance Framework, including Enterprise Risk Management, Corporate Code of Conduct, Ethics and Values.
- Assist the Secretary of the Audit Committee in arranging Audit Committee meetings, preparing agendas and minutes of meetings, and reporting on Corporate Governance Framework, General Controls and related issues as prescribed in the Audit Committee Charter.
- Provide professional advice on Group Companies' Audit Committee Charter, IA Charter and IT Audit Methodology/Procedures.
- Provide assistance in the establishment of Group Audit Committees/IA functions and related governance when assigned.
Audit Planning
- Assist in the development of Annual Audit Plan (AAP) based on risk assessment results focusing on IT risks.
- Participate in reviewing and updating the IT audit universe to ensure it covers all IT risks.
- Provide input for periodic reporting on IT audit activities and performance relative to plans, significant risk exposures, control/governance issues and related matters.
Audit Execution
- Lead IT auditors in the examination and analysis of records through executing audit program steps for assigned audits.
- Develop detailed audit programs and Risk & Control Matrix (RCM) for assigned audits, including objectives, potential risks, key controls, audit procedures, and use of audit techniques and tools to evaluate governance, risks and controls processes. Submit audit programs to management for review and approval.
- Determine auditing procedures to be applied, including Information Systems Audit Techniques, data analytics, statistical sampling methods or others.
- Ensure adequate working papers and all relevant information are continuously documented and updated in the automated Audit Management System in accordance with pre-defined templates and audit procedures.
- Identify, obtain, analyze and appraise related systems and evidentiary data/information.
- Supervise audits in accordance with the approved RCM and professional standards on internal auditing.
- Ensure that approved audit objectives have been met with adequate coverage of all relevant areas and sufficient audit evidence is obtained to support conclusions and recommendations in accordance with professional audit standards.
- Identify high risk areas and key control points of the system to be reviewed.
- Ensure tasks assigned to junior staff are adequately performed and deliverables are in accordance with ADNOC Internal Audit procedures and quality standards.
Audit Follow-up & Monitoring
- Appraise the adequacy of corrective actions taken by management on audit recommendations through follow-up audits.
- Periodically review and update the status of management action plans.
- Follow up on replies to issued draft and final audit reports.
- Review the adequacy of corrective actions taken on audit recommendations and improvement options.
Audit Reporting
- Prepare audit reports with conclusions expressing professional opinions on the adequacy and effectiveness of risk management, control systems and the efficiency with which activities are carried out.
- Recommend improvement options to rectify reported deficiencies for Section Head/Department Manager review.
- Recommend practical enhancements in IT governance, risks and control processes to assist in achieving company business objectives.
Coordination & Knowledge Sharing
- Conduct workshops or presentations to create awareness about IA function and demonstrate value addition across ADNOC.
- Communicate identified issues with Internal Audit management to ensure potential high risk areas of concern are addressed in a timely and effective manner.
- Participate in initiating and coordinating group-wide specialized professional training programs.
- Conduct research and benchmarking to resolve audit issues, identify gaps and support IA function.
- Maintain regular contacts with ADNOC Group Companies' Internal Audit Managers with respect to knowledge sharing of audit standards, frameworks, methodologies, policies, processes and coordination across ADNOC Group Companies.
Special Reviews & Administrative
- Participate in conducting special reviews and undertake administrative duties as directed by Head of Internal Audit.
Supervision & Team Development
- Plan, supervise and coordinate all activities in the assigned area to meet functional objectives.
- Train and develop assigned staff on relevant skills to enable them to become proficient on the job and deliver section objectives.
Budget & Resource Management
- Provide input for preparation of Function/Department/Section budgets.
- Assist in the implementation of approved budgets and work plans to deliver section objectives.
- Investigate and highlight any significant variances to support effective performance and cost control.
Policy Implementation & Standards
- Implement approved Function/Department/Section policies, processes, systems, standards and procedures to support execution of work programs in line with Company and International standards.
Performance & Continuous Improvement
- Contribute to the achievement of approved Performance Objectives for the Function/Department/Section in line with Company Performance framework.
- Design and implement new tools and techniques to improve the quality and efficiency of operational processes.
- Identify improvements in internal processes against best practices in pursuit of greater efficiency in line with best industry standards to define intelligent solutions for issues confronting the function.
Reporting & Management Communication
- Provide inputs to prepare MIS and progress reports for Company Management.
- Assist in periodic reporting to the Audit Committee and Senior Management on internal audit activities, performance, significant risk exposures, controls/governance issues and related matters.
Health, Safety, Environment & Sustainability
- Comply with relevant HSE policies, procedures, controls, applicable legislation and sustainability guidelines in line with international standards, best practices and ADNOC Code of Practices.
Qualifications & Experience
Education
- Bachelor Degree in Computer Science or related IT discipline, Finance/Auditing or equivalent discipline.
Experience
- 8 years of relevant experience in IT internal auditing with varied experience in oil and gas operations and their inherent challenges/risks in the context of corporate function.
- Experience in managing and tracking time for different Internal Audit related activities.
- Extensive knowledge of planning and project management areas.
Knowledge & Technical Expertise
- In-depth knowledge of International Professional Practices Framework for IT Assurance/IT Assurance Framework (ITAF) and other related frameworks/standards including COBIT, ITIL, ISO27000, NIST and their interpretation/application to IS/IT auditing practice.
- Awareness/knowledge of Operational Technology (OT) processes and systems.
- In-depth knowledge of IT processes including system development, infrastructure review, access right management and change management.
- Expertise in collecting and analyzing complex data using data analytics tools, evaluating information and systems, and drawing logical conclusions.
- Advanced technical knowledge of different operating systems, databases, network infrastructure components (routers, switches, firewalls etc.) and ERP.
Professional Certifications
- IT audit certification, CISA, is mandatory.
- Other related certifications (CISSP, CISM, GIAC, etc.) are preferred.
Additional Information
Work Conditions
- Physical Effort: Minimal
- Work Environment: Normally air-conditioned office environment, however exposed to prevailing weather conditions while in operating sites and field visits.
Internal Communications & Working Relationships
- Regular contacts with operational level management within all auditable departments throughout ADNOC.
- Frequent contacts within ADNOC at all levels of Management up to SVPs/Directors with respect to audit programs, conduct of audits, audit reports, findings and recommendations.
- Regular contacts with Management within assigned ADNOC Group Companies up to Manager level regarding Group Company audits.
External Communications & Working Relationships
- Occasional contacts with Internal Audit Service Provider(s) to coordinate audit activities when required.
- Occasional contacts as required with Abu Dhabi Accountability Authority (ADAA) regarding government audits.
- Occasional contacts with ADNOC External Auditors and other assurance providers to ensure adequate audit coverage and minimize duplicate efforts.