Assistant Director: Information Technology Audit
Department Of Tourism · Pretoria, Gauteng
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →REQUIREMENTS
- A recognised NQF 6 qualification in Internal Auditing, Information Systems Auditing or related fields. Minimum of Four 4 years in ICT Audit or Internal Audit of which 2 years must be at a senior practitioner level or equivalent. Experience in conducting ICT governance, cybersecurity, application controls and ICT general control reviews.
- Professional Certification Advantageous: Certified Information Systems Auditor CISA. Certified Internal Auditor CIA. Certified Information Security Manager CISM. COBIT Foundation Certification. Other recognised ICT Governance or Cybersecurity certifications. Public Finance Management Act PFMA. Treasury Regulations. Public Service Act and Regulations.
- Protection of Personal Information Act POPIA. DPSA Corporate Governance of ICT Policy Framework CGICTPF. Global Internal Audit Standards. COBIT Framework. ISO 27001 Information Security Standards. Risk Management Frameworks. ICT Governance and Cybersecurity Principles. BAS, PERSAL, LOGIS and other government systems.
- ICT Audit and Assurance. Risk Assessment and Control Evaluation. Data Analysis and CAATs. Report Writing. Communication and Presentation Skills. Stakeholder Management. Problem Solving and Analytical Thinking. Project Management. Quality Assurance. Time Management. Teamwork and Interpersonal Skills. A valid driver's licence Persons with disabilities that prevent them from driving will still be considered.
DUTIES
- The successful candidate will be responsible for ICT Audit Planning and Risk Assessment; Assisting in the development of the annual and rolling ICT audit plans based on departmental risk assessments; Conducting preliminary surveys and risk assessments for assigned ICT audit engagements; Analysing ICT risks, control environments and business processes.
- Developing audit objectives, scope, criteria and audit programmes; Preparing audit planning documentation in accordance with the Internal Audit Methodology; Executing of ICT Audit Engagements; Conducting ICT audits covering ICT Governance, Information Security, Cybersecurity, Infrastructure Management, Identify and Access Management, Change Management, Business Continuity Management and Disaster Recovery;
- Performing application control reviews and data analytics; Evaluating the adequacy and effectiveness of ICT controls; Conducting interviews, walkthroughs and control testing; Utilising Computer-Assisted Audit Techniques CAATs and other audit tools during audit engagements; Compiling and maintain comprehensive audit working papers;
- Auditing Reporting and Follow-up; Analysing audit evidence and develop audit findings; Identifying root causes, risks and control weaknesses; Drafting audit reports and obtain management comments; Presenting audit findings to the Deputy Director and management during audit engagements; Monitoring implementation of agreed management action plans;
- Conducting follow-up audits and report on implantation status; ICT Governance, Risk and Compliance Reviews; Assessing compliance with applicable legislation, frameworks and standards, including PFMA, Treasury Regulation, POPIA, DPSA Corporate Governance of ICT Policy Framework, COBIT and ISO 27001;
- Evaluating ICT governance structures and processes; Reviewing digital transformation initiatives and ICT projects; Assessing ICT risk management and information security practices; Evaluating business continuity and disaster recovery arrangements; Stakeholder Engagement and Advisory Services; Liaising with management during audit engagements;
- Participating in entrance, progress and exit meetings; Providing advisory services relating to ICT control and governance where required; Assisting management in understanding audit findings and recommendations; Liaising with external auditors and service providers when required; Contributing to combined assurance initiatives; Quality Assurance and Knowledge Management;
- Ensuring compliance with the Global Internal Audit Standards and departmental methodologies; Performing quality reviews of audit working papers and supporting evidence; Maintaining accuracy and complete audit documentation;
- Contributing to continuous improvement initiatives within the Internal Audit Unit; Providing coaching and technical support to interns and junior audit staff where required; Keeping abreast of emerging ICT risks, technologies and auditing techniques