📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة

شركة علم تعلن عن وظيفة مدقق أول - تدقيق تقنية المعلومات والأمن في الرياض

Senior Auditor - IT & Security Audit Job
🏢 علم (Elm)
🕒 نُشرت: (اليوم) 📍 الرياض وظائف الأمن والسلامة
التقديم على الوظيفة من المصدر الرسمي ↗

تفاصيل الوظيفة

تعلن شركة علم ( Elm ) في الرياض عن توفر فرصة وظيفية شاغرة بمسمى Senior Auditor - IT & Security Audit (مدقق أول - تقنية المعلومات وأمن المعلومات).

نبذة عن الوظيفة

يهدف الدور إلى تنفيذ مهام التدقيق في تقنية المعلومات وأمن المعلومات لتقديم تأكيد مستقل حول فعالية الحوكمة وإدارة المخاطر والأمن السيبراني والرقابة الداخلية. يدعم الدور تنفيذ خطة التدقيق الداخلي المعتمدة من خلال إجراء مراجعات قائمة على المخاطر، وتحديد نقاط الضعف في الرقابة، وتقييم الامتثال للمعايير واللوائح المعمول بها، والتوصية بتحسينات عملية تعزز بيئة الرقابة والمرونة التشغيلية للمنظمة.

المهام والمسؤوليات

  • تنفيذ مهام تدقيق تقنية المعلومات والأمن السيبراني وفقاً لخطة التدقيق المعتمدة.
  • إجراء اختبارات التدقيق وتقييم فعالية ضوابط التقنية.
  • توثيق النتائج والأدلة الداعمة.
  • تقييم المخاطر المتعلقة بأنظمة المعلومات والبنية التحتية والتطبيقات والأمن السيبراني.
  • تحديد فجوات الرقابة والتوصية بفرص التحسين.
  • تقييم إجراءات تخفيف المخاطر.
  • مراجعة الامتثال للسياسات الداخلية والمتطلبات التنظيمية ومعايير التقنية.
  • تقييم ضوابط تقنية المعلومات العامة (ITGCs) والضوابط الآلية.
  • تقييم فعالية حوكمة وأمن المعلومات.
  • إعداد ملاحظات وتقارير التدقيق.
  • إيصال النتائج والتوصيات إلى أصحاب المصلحة.
  • دعم إغلاق وحل قضايا التدقيق.
  • تتبع خطط العمل التصحيحية.
  • التحقق من تنفيذ الإجراءات المتفق عليها.
  • الإبلاغ عن حالة ملاحظات التدقيق المعلقة.
  • المشاركة في مراجعات تغطي الأمن السيبراني، وإدارة الوصول، وإدارة التغيير، وضوابط حماية البيانات.
  • دعم تدقيق المنتجات الرقمية والتطبيقات والمبادرات التقنية.
  • التنسيق مع فرق الأعمال والتقنية أثناء مهام التدقيق.
  • الحفاظ على علاقات عمل فعالة مع أصحاب المصلحة.
  • تسهيل جمع المعلومات والمناقشات.
  • المساهمة في تحسين منهجيات وممارسات التدقيق.
  • دعم استخدام تحليلات البيانات وتقنيات التدقيق المعتمدة على التقنية.
  • اتباع جميع السياسات والعمليات والإجراءات والتعليمات المعيارية المعمول بها.
  • الامتثال لسياسات وضوابط السلامة والجودة والبيئة.
  • الامتثال لممارسات ومعايير أمن المعلومات لضمان سلامة البيانات وسريتها.

الشروط والمتطلبات

  • درجة البكالوريوس في تقنية المعلومات، علوم الحاسب، نظم المعلومات، الأمن السيبراني، هندسة البرمجيات، أو مجال ذي صلة.
  • الشهادات المهنية التالية مفضلة: CISA، CISSP، ISO 27001 Lead Auditor، CRISC، CIA، أو ما يعادلها.
  • خبرة عملية تتراوح بين 4-6 سنوات في مجال تدقيق تقنية المعلومات، تدقيق أمن المعلومات، مخاطر التقنية، الأمن السيبراني، تطوير المنتجات، تطوير الذكاء الاصطناعي، الشبكات، أو التدقيق الداخلي.
  • معرفة بحوكمة تقنية المعلومات، الأمن السيبراني، إدارة المخاطر، ومنهجيات التدقيق.
عرض النص الأصلي للإعلان

 

Job Description

OVERVIEW

Job Title

Senior Auditor

Job Code

675389

Grade

I3

Group

-

Division

Internal Audit

Department

IT & Security Audit

Unit

Information Technology & Security Audit

 

ROLE PURPOSE

The aim is to state the overall significance of the job from the organization’s perspective.

The role is responsible for executing information technology and security audit engagements to provide independent assurance on the effectiveness of governance, risk management, cybersecurity, and internal controls. The role supports the delivery of the approved internal audit plan by conducting risk-based reviews, identifying control weaknesses, evaluating compliance with applicable standards and regulations, and recommending practical improvements that enhance the organization's control environment and operational resilience.

 

KEY ACCOUNTABILITIES & ACTIVITIES

This section describes the principal outputs required from the job.

Key Accountabilities

Key Activities

  1. IT & Security Audit Execution
  •  Execute IT and cybersecurity audit engagements in accordance with the approved audit plan.
  •  Perform audit testing and evaluate the effectiveness of technology controls.
  •  Document findings and supporting evidence.
  1. Technology Risk Assessment
  • Assess risks related to information systems, infrastructure, applications, and cybersecurity.
  •  Identify control gaps and recommend improvement opportunities.
  •  Evaluate risk mitigation measures.
  1. Control & Compliance Reviews
  •  Review compliance with internal policies, regulatory requirements, and technology standards.
  •  Assess IT General Controls (ITGCs) and automated controls.
  •  Evaluate governance and security control effectiveness.
  1. Audit Reporting
  • Prepare audit observations and reports.
  •  Communicate findings and recommendations to stakeholders.
  •  Support closure and resolution of audit issues.
  1. Follow-Up Activities
  • Track corrective action plans.
  •  Validate implementation of agreed actions.
  •  Report status of outstanding audit observations.
  1. Specialized Technology Audits
  •  Participate in reviews covering cybersecurity, system access, change management, and data protection controls.
  •  Support audits of digital products, applications, and technology initiatives.
  1. Stakeholder Collaboration
  • Coordinate with business and technology teams during audit engagements.
  •  Maintain effective working relationships with stakeholders.
  •  Facilitate information gathering and discussions.
  1. Continuous Improvement
  • Contribute to the enhancement of audit methodologies and practices.
  •  Support the use of data analytics and technology-enabled auditing techniques.
  1. Policies, Processes & Procedures
  •  Follow all relevant departmental policies, processes, standard operating procedures, and instructions so that work is carried out in a controlled and consistent manner.
  •  Comply with all relevant safety, quality, and environmental management policies, procedures, and controls to ensure a healthy and safe work environment.
  1. Information Security
  • Comply with all relevant information security practices and standards to ensure data integrity and confidentiality.

 

 

JOB SPECIFICATIONS

Academic and professional qualifications

  • Bachelor's degree in Information Technology, Computer Science, Information Systems, Cybersecurity, Software Engineering, or a related discipline.
  •  Professional certifications are preferred, such as CISA, CISSP, ISO 27001 Lead Auditor, CRISC, CIA, or equivalent.

Years and Nature of Experience

  • 4-6 years of relevant experience in IT Audit, Information Security Audit, Technology Risk, Cybersecurity, product development , AI developer, networking or Internal Audit.
  • Knowledge of IT governance, cybersecurity, risk management, and audit methodologies

 

 

VERSION TRACKING

Prepared by:

 

First review by:

 

Approved by:

Name

 

Signature

 

Date

 

 

 

 

 

المصدر: الموقع الرسمي للجهة - أُضيفت للموقع في 5 أغسطس 2026

وظائف أخرى لدى علم