Text copied to clipboard!

Title

Text copied to clipboard!

Information Systems Auditor

Description

Text copied to clipboard!
We are looking for an Information Systems Auditor with strong experience in evaluating technology controls, risk management, regulatory compliance, and information security processes. The selected candidate will be responsible for assessing the effectiveness of systems, identifying vulnerabilities, reviewing policies and procedures, and providing recommendations that strengthen the organization’s internal control environment. This role requires a balanced combination of technical knowledge, analytical thinking, professional judgment, and the ability to communicate findings clearly to both technical teams and business leadership. The Information Systems Auditor will participate in internal audits and special reviews related to technology infrastructure, business applications, databases, networks, business continuity, cybersecurity, data privacy, and IT governance. The role also works closely with information security, compliance, risk, operations, finance, and internal audit teams to ensure that systems adequately support business objectives and comply with regulatory requirements and industry best practices. Key responsibilities include planning risk-based audits, performing tests of IT general controls and automated controls, documenting evidence, preparing reports, and following up on corrective action plans. The ideal candidate will have experience with frameworks such as COBIT, ISO 27001, NIST, ITIL, SOX, or equivalent standards, as well as a solid understanding of access management, segregation of duties, change management, backup and recovery, incident monitoring, and protection of information assets. We are seeking someone with strong attention to detail, professional integrity, and the ability to work both independently and collaboratively. The successful candidate should be able to interpret complex risks, prioritize findings based on potential impact, and recommend practical solutions aligned with the organization’s operational reality. In addition, this person is expected to stay current on emerging threats, regulatory trends, and technological developments that may affect the company’s risk profile. This position offers the opportunity to contribute directly to stronger internal controls, operational resilience, and trust in information systems. If you are interested in evaluating technology environments, improving processes, and delivering value through objective and well-supported audits, this role can be an excellent next step in your professional development.

Responsibilities

Text copied to clipboard!
  • Plan and execute risk-based information systems audits.
  • Evaluate IT general controls, logical access, and segregation of duties.
  • Review change management, backup, recovery, and operational continuity processes.
  • Analyze security configurations, event logs, and technology incidents.
  • Document findings, evidence, conclusions, and improvement recommendations.
  • Prepare clear audit reports for technical teams and leadership.
  • Track remediation plans and validate corrective actions.
  • Verify compliance with internal policies, regulations, and applicable standards.

Requirements

Text copied to clipboard!
  • Bachelor’s degree in information systems, computer science, auditing, or a related field.
  • Experience in IT audit, information security, or internal controls.
  • Knowledge of frameworks such as COBIT, ISO 27001, NIST, or ITIL.
  • Ability to assess technology risks and automated controls.
  • Experience reviewing access management, changes, backups, and business continuity.
  • Strong report writing and technical documentation skills.
  • Familiarity with analysis, data query, or control monitoring tools.
  • Certifications such as CISA, CISSP, CRISC, or equivalent are valued.

Potential interview questions

Text copied to clipboard!
  • How much experience do you have in information systems auditing?
  • Have you worked with frameworks such as COBIT, ISO 27001, or NIST?
  • Do you have experience evaluating access controls and segregation of duties?
  • Have you participated in audits related to cybersecurity or business continuity?
  • What tools do you use to document evidence and analyze controls?
  • Have you prepared reports for both technical and executive audiences?
  • Do you hold any certifications such as CISA, CRISC, or similar?
  • What has been your most significant audit finding and how did you communicate it?