Audit Manager, Technology & Cyber Security
Kuwait Finance House · Bahrain · 15h ago
KEY RESPONSIBILITIES:
Audit Planning & Risk Assessment:
Participate in the annual Technology & Cyber Security risk assessment and audit planning processes.
Identify key technology and cybersecurity risks across infrastructure, applications, digital channels, and IT operations.
Recommend audit priorities based on risk exposure, incidents, regulatory updates, and emerging threats
Audit Execution & Fieldwork:
Execute end‑to‑end IT and cyber-security audits in line with the approved audit plan, methodology, and allocated time budgets.
Assess the design and operating effectiveness of IT and cybersecurity control areas, including IT general controls, application controls, cybersecurity controls, and technology governance processes.
Benchmark compliance against relevant IT and cybersecurity standards, frameworks, laws, and regulations.
Leverage data analytics and automated techniques to enhance audit efficiency, accuracy, and coverage
Reporting & Stakeholder Management:
Prepare high‑quality audit reports that clearly present findings, associated risks, root causes, and practical recommendations in accordance with the approved methodology.
Conduct meetings with audit clients to ensure effective communication throughout the audit lifecycle.
Present audit results to senior management and relevant committees as required.
Maintain strong, professional relationships with Technology, Cyber Security, Risk, and Business stakeholders while preserving audit independence.
Follow-Up, Issue Tracking, and Validation:
Monitor the remediation of audit findings and validate the closure of open issues in accordance with the audit manual.
Ensure timely follow‑up and escalate delays that expose the bank to unacceptable levels of risk.
Quality Assurance & Methodology:
Maintain detailed, high‑quality working papers that comply with the approved audit methodology.
Ensure audit engagements are executed in a manner that upholds audit quality while fostering positive client relationship and maintaining professional independence.
Contribute to the continuous enhancement of Internal Audit processes, templates, and the adoption of digital audit tools and technology-driven improvements.
Advisory, Training & Development:
Serve as a subject‑matter expert on digital transformation, cloud technologies, fintech, data analytics, AI/ML controls, and relevant IT regulatory requirements.
Conduct ad‑hoc audit assignments or investigations as directed by the Audit Committee or the Head of Audit.
Provide advisory support while maintaining strict adherence to audit independence.
Maintain up‑to‑date professional knowledge and continuing professional development (CPD), particularly on regulatory, legislative, and emerging risk and control developments relevant to the bank’s activities.
Act as a champion for the audit management software and other audit and data analytics tools.
Complete all mandatory and assigned training programs within the stipulated timelines, ensuring full compliance with Internal Audit and bank-wide learning requirements.
QUALIFICATIONS & EXPERIENCE
Academic Qualifications (Minimum Requirement):
Bachelor’s degree in Information Technology, Computer Science, Cyber Security, or related field.
Master’s degree preferred.
Professional Certifications (Minimum Requirement / Preferred):
Certified Information Systems Auditor (CISA) is required
CIA, CISM, CISSP, CFE, CRSIC, CGEIT, ACCA, CPA, CFA, Cloud (AWS/Azure), or similar is preferred.
Minimum Experience:
6 years or more technology and cyber security experience, including a minimum of 3 years IT auditing experience in financial services or related industry.