Job description
Role Overview
HALA, a leading fintech player in the MENAP region, is seeking an IT Audit Manager to join the team. The role is based at HALA, which operates multiple entities across UAE, Saudi Arabia, and Egypt.
Company Overview
HALA is a fintech organization founded in 2017, licensed by the Saudi Arabian Central Bank, that aims to redefine financial services and empower SMEs to start, run, and grow their businesses. HALA currently holds multiple entities in UAE, Saudi Arabia, and Egypt, including HALA Payments and HALA Logistics, offering solutions that enable merchants to digitize payments and manage sales and operations. The organization comprises a talented team of over 30 nationalities working across 7 countries.
Role Purpose
The IT Audit Manager will lead audits across Information Technology, Cybersecurity, Business Continuity Management (BCM), and other technology-enabled business processes. The role involves planning and executing risk-based audits, evaluating the design and operating effectiveness of IT general controls, identifying technology risks and control deficiencies, and providing practical recommendations to strengthen governance, enhance cyber resilience, improve operational effectiveness, and support compliance with regulatory requirements and industry standards.
Key Responsibilities
Audit Planning & Execution
- Plan and execute risk-based IT audit engagements, including IT General Controls (ITGC), cybersecurity, cloud computing, digital platforms, data governance, business continuity management (BCM), disaster recovery (DR), third-party risk, and technology-enabled business processes.
- Perform audit planning activities, including risk assessments, audit scoping, control identification, and development of audit programs and testing procedures.
- Conduct interviews and walkthroughs with business and technology stakeholders to obtain an understanding of IT processes, systems, applications, infrastructure, and associated controls.
Controls & Risk Assessment
- Evaluate the design and operating effectiveness of IT controls, identify technology risks and control deficiencies, and provide practical recommendations to strengthen governance, security, resilience, and operational effectiveness.
- Assess compliance with applicable regulatory requirements, internal policies, and recognized industry frameworks and standards, including SAMA Cybersecurity Framework (CSF), SAMA BCM Framework, PCI DSS, ISO/IEC 27001, COBIT, NIST Cybersecurity Framework, SWIFT CSCF (where applicable), and other relevant technology risk and security standards.
Reporting & Communication
- Prepare clear, concise, and evidence-based audit reports, working papers, and executive presentations that effectively communicate audit observations, risk implications, and actionable recommendations.
- Present audit findings and recommendations to senior management and facilitate discussions to obtain agreement on corrective action plans.
Monitoring & Follow-Up
- Monitor and validate the implementation of agreed management actions through periodic follow-up reviews and provide independent assurance over the effectiveness of remediation activities, including validation of regulatory observations where required.
Stakeholder Management
- Build and maintain effective working relationships with business units, technology teams, risk management, compliance, and external stakeholders while preserving audit independence and objectivity.
Continuous Improvement & Advisory
- Stay abreast of emerging technology risks, cybersecurity threats, evolving regulatory requirements, and changes to applicable auditing, governance, and security standards.
- Provide advisory and consulting services on technology initiatives, digital transformation projects, system implementations, and other ad hoc reviews, while maintaining the independence of the Internal Audit function.
- Contribute to the continuous enhancement of the Internal Audit methodology, including the adoption of data analytics, continuous auditing techniques, and technology-enabled audit tools.
Additional Information
- HALA offers an inclusive and diverse culture that encourages innovation and flexibility in remote, in-office, and hybrid work setups.
- Highly competitive compensation packages are provided, including the potential for shares.
- Regular training and an annual learning stipend support personal development and career growth in a hyper-growth environment.
- The role offers autonomy, mentoring, and challenging goals with significant responsibility and trust.