As Audit Lead – IT & Cyber Security Audit, you will lead the end-to-end execution of IT, cybersecurity, and technology audit engagements, supervising engagement teams and delivering high-quality audit results in line with Tabby's technology risk-based audit plan.
● Lead the planning and execution of assigned IT general controls,
● application controls, and cybersecurity audit engagements, from scoping through reporting.
● Develop detailed audit programs and risk and control matrices (RCMs) covering IT and cyber risk areas, aligned with the approved audit plan.
● Supervise and review the fieldwork of Senior Auditors, Auditors, and
Interns assigned to the engagement, ensuring quality and adherence to methodology.
● Conduct walkthroughs, technical interviews, and testing of IT general controls, application controls, network and endpoint security, identity and access management, and cloud configurations.
● Identify control gaps and root causes, and draft clear, actionable audit findings and recommendations on technology and cyber risk.
● Draft audit reports and present engagement results to Engineering and
Information Security process owners.
● Engage directly with technology process owners to validate findings, agree on corrective action plans, and set remediation timelines.
● Track and follow up on the implementation of IT and cyber audit recommendations for assigned engagements.
● Contribute to the annual technology and cyber risk assessment for assigned systems and platforms.
● Coach and provide on-the-job guidance to Senior Auditors, Auditors, and Interns on IT audit techniques.
● Support the Audit Manager in preparing quarterly and annual IT/cyber audit reporting materials.
● Stay current on IT auditing standards, cybersecurity frameworks, and
● SAMA regulatory requirements (including the SAMA Cyber Security
● 5+ years of experience in IT audit, information security, or technology risk, including experience leading audit engagements, preferably within banking, fintech, or corporate environments.
● Strong knowledge of IT auditing standards, cybersecurity frameworks, and SAMA regulatory requirements.
● Experience assessing IT general controls, application controls, and cybersecurity controls.
● Strong communication and interpersonal skills to engage with technology process owners and present audit findings.
● Strong analytical and problem-solving skills with a detail-oriented approach.
● Proficiency in IT audit tools and familiarity with cloud platforms
(AWS/Azure/GCP).
● Bachelor's degree in Computer Science, Information Systems,
Cybersecurity, or a related field; CISA (obtained or in progress) highly desirable.