
Senior IT Auditor
- Hong Kong
- Permanent
- Full-time
- Perform IT audits, regulatory audits, financial Sarbanes-Oxley (SOX) controls testing and advisory reviews. As part of the IT audit responsibilities, the successful candidate will test controls relating to IT processes such as operations, security, system development, change management, application controls such as automated data interface reconciliation controls and other controls in operational areas/functions including Artificial Intelligence (AI) systems.
- On assigned audits/project, take ownership on key components of the end-to-end audit process, such as audit planning (perform walkthroughs, draft risk assessments), fieldwork (execute controls testing), and reporting (draft audit reports/memos/control deficiencies).
- Use problem solving and critical thinking skills to identify internal control deficiencies, evaluate their risk implications, and draw the appropriate conclusions to best advise management auditees.
- Play a substantive role with audits including SOX controls testing and required reviews by managing information request lists and providing regular status updates to IA management and auditees on progress of the audits or controls testing.
- Provide support to junior staff on assigned audits and SOX cycles. Additionally, perform testing for higher risk processes and controls.
- Build and nurture positive working relationships with management auditees.
- Contribute to IA's on-going focus to continuous improvement in our audit processes using AI capabilities.
- A minimum of 3 years in IT audit experience.
- Experience with IT controls (e.g., application logical security, software development, change management, disaster recovery, application controls including data interfaces and reconciliation controls)
- Experience in the insurance industry (e.g., Property, Casualty, Life etc.) is desirable.
- Excellent written and oral communications skills.
- Must be a team player with proven track record of collaboration.
- Strong analytical skills with ability to understand complex processes.
- Basic project management skills are preferrable.
- Professional level of fluency in using Mandarin and English.
- Travel to locations in Mainland China around 25%.
- Relevant degree.
- Relevant professional designations (e.g., CISA, etc.).
- Familiar with IT Audit Concepts, including Information Security, Application Development Controls, Disaster Recovery, Computer Operations Controls, System Development Implementation Controls and Application Controls including data interfaces and reconciliation controls.
- Knowledge in auditing AI system is desirable.