Job description
Role Overview
VP & Head of Audit, Information Security at First Abu Dhabi Bank. The role leads audit planning and execution across Group Security Office, Business Continuity Management, Data Domain, Group Technology, and System Integration Projects in the UAE and all international locations.
Role Purpose
Serve as a subject matter expert responsible for planning and executing comprehensive audits of Group Security Office, Business Continuity Management, Data Domain (Data Governance, Data Privacy, Data Analytics & AI), Group Technology, and System Integration Projects across FAB Group domestically and internationally. Provide assurance to Management by identifying weaknesses, reporting significant findings timely, and agreeing action plans to address issues raised.
Key Responsibilities
Strategic Contribution
- Lead audits of FAB Group's Information Security, Business Continuity Management, Information Technology, Data Domain (Data Governance, Data Privacy, Data Analytics & AI), and System Integration functions and related activities in the UAE and across the international network.
- Cover Group Subsidiaries with Information Security, Technology, Business Continuity Management, Data Domain, and System Integration presence.
- Ensure audits in Information Security, Business Continuity Management, Data Domain, and System Integration areas are conducted in accordance with objectives laid down in the Annual Plan.
- Ensure work programs are completed in an efficient and effective manner on or ahead of schedule.
- Inform Head of Audit of any potential delays and/or changes to the Annual Plan.
People Management
- Provide guidance and on-the-job training for junior colleagues and conduct knowledge sharing to facilitate achievement of team objectives.
- Ensure completion of tasks in an efficient manner consistent with operating procedures and policy.
- Promote the organization's values and ethics in all activities within the team to support establishment of a value-driven culture within the bank.
Budgeting and Financial Performance
- Monitor financial performance of given areas of activities versus budgets.
- Ensure all activities are carried out in line with approved guidelines.
- Promptly report any variances to management.
Policies, Systems, Processes & Procedures
- Execute all tasks in accordance with established GIA Policies, Guidance Notes, Procedures, and Practice Notes.
- Provide input to the development of GIA practices as per industry standards and regulatory expectations.
- Review all activities of Units within Information Security, Technology, Data Domain, and System Integration related activities in all jurisdictions where the group operates.
- Define and maintain the Audit Universe.
- Coordinate with other teams to ensure efficient and effective coverage.
- Prepare and maintain a Risk Assessment of each Process Stream within Information Security, Technology, Data Domain, and System Integration related Units and applicable subsidiaries.
- Work with businesses to promote periodic self-assessment of risks and controls.
- Establish, update, and maintain Audit programs in the central audit management tool.
- Conduct audits of Processes within Information Security, Technology, Data Domain, and System Integration related activities and assess whether divisional/unit line management have identified and classified risks in their activities.
- Assess whether governance, risk management, and control procedures are adequate, effective, and efficient to reduce risks of errors, omissions, and loss to acceptable levels at an acceptable cost.
- Identify improvements and enhancements required to governance, risk management, and internal control structure.
- Assess whether data and transaction processing meet required standards of reliability, integrity, and availability.
- Verify that divisional/unit assets are being safeguarded.
- Evaluate whether use of resources is efficient and effective.
- Ensure draft audit reports submitted by auditors are properly reviewed and finalized.
- Discuss and finalize audit reports with GIA management/client within 6 weeks of completion of fieldwork.
- Negotiate with Unit management to agree on a documented Management Action Plan to resolve issues raised.
Continuous Improvement
- Lead identification of change through continuous improvement of processes and practices considering global standards.
- Consider changes in the business environment that demand proactive action plans.
Relationship Management
- Develop and maintain effective business relationships with all relevant external and internal entities and stakeholders with the highest standards of business ethics.
- Promptly attend to all critical issues to ensure services required by the organization are delivered in the most effective manner.
- Act as the Audit Business Partner for Line Managers within Information Security, Technology, Data Domain, and System Integration Functions.
- Actively manage relationships through regular meetings with Line Managers to promote this concept and identify emerging risks.
- Use meetings to discuss any material gaps between audit assessment of risks and controls and the business's self-assessment.
- Provide ongoing consultancy and advice to Unit management from a governance, risk management, and control perspective for improvements in their processes.
- Ensure recommendations are based on market best practices.
- Ensure effective and efficient controls are implemented.
- On an ongoing basis, ensure pending audit issues are followed up with Unit management.
- Verify that all corrective actions are fully and properly implemented.
- Conduct any investigations or special reviews assigned by Head of Audit or GCAO.
Reporting
- Prepare all functional reports timely and accurately.
- Ensure reports meet Group requirements, policies, and quality standards.
Safeguarding and Risk Assessment
- Safeguard against potential loss and contribute to Information Security, Technology, Data Domain, and System Integration systems and procedures.
- Report whether operational and regulatory controls of FAB standards are effectively carried out and are efficient in the units and departments audited.
- Review functions within Information Security, Technology, Data Domain, and System Integration of the bank end to end.
- Identify areas of correction and improvement.
Data Analytics and Continuous Auditing
- Lead and guide team members on applying data analytics, automated, and enhanced testing techniques in audit execution.
- Guide use of continuous monitoring routines across domains of Information Security, Technology, Data Domain, and System Integration systems.
- Extend assurance beyond sample-based testing.
- Support continuous auditing of key controls.
- Examine and comment on the process for early recognition of problems and their remedial management to minimize loss.
Audit Management Information Systems
- Prepare and review Audit MIS and dashboards including audit committee presentation slides relating to audits conducted in the Group Security Office, Technology, and Data domains.
Regulatory Knowledge and Compliance
- Maintain up-to-date knowledge and understanding of key regulatory developments and banking practices across Information Security, Cyber Security, Business Continuity and Resilience, Technology, Data Domain (including Data Privacy), and System Integration.
- Cover different jurisdictions relevant to FAB Group.
- Interpret regulatory requirements into practical control and evidence expectations.
- Drive necessary changes in Audit plan and working programs to take into consideration regulatory changes across relevant auditable areas.
Advisory and Strategic Partnership
- Act as a trusted advisor to the Business, Group Security, Group Technology, and Data Domain.
- Provide advisory services in the areas of Information Security, Cyber Security, Business Continuity and Resilience, Technology Governance & Risk Management, Technology Portfolio Management, Technology Outsourcing, Data Privacy, Data Governance, Applied and Advanced Analytics, and related Regulatory Compliance.
- Contribute towards enhancement of relationship between GIA and stakeholders.
- Keep abreast of local and international economic trends, banking practices, and regulatory prescriptions.
Qualifications & Experience
Education
- Bachelor's degree.
- Relevant post-graduate qualification and/or relevant professional qualification and/or certification desirable.
Professional Certifications
- CISA Certification is essential.
- Additional relevant certifications such as CISSP, CISM, and CSX are desirable.
Experience
- Minimum 10 years' relevant experience with an International Bank or Big 4.
- Internal Audit experience strongly preferred (but not mandatory).
- At least 5 years in similar positions of progressively increasing managerial responsibilities in Bank Operations, Risk Management, and/or Audit function.
- Expert knowledge of operational activities and processes and associated risks within Information Security, Cyber Security, Business Continuity Management, Technology, and Data domains.
- Expert knowledge of control frameworks and standards commonly used to design and assess controls in those domains.
- Strong working knowledge and demonstrable ability to interpret regulatory expectations across multiple jurisdictions in the domains of Information Security, Technology, Business Continuity Management, and Data Management.
Skills & Competencies
- Strong leadership capability and team-oriented approach.
- Highly developed problem-solving skills.
- Self-directed with ability to manage multiple tasks.
- Ability to work under pressure.
- Excellent analytical skills.
- Exceptional verbal and written communication skills.
- Strong ability to comprehend, articulate, and translate complex technology, cybersecurity, and business concepts for diverse stakeholders.