Job Purpose
Under the supervision of Head of Internal Audit, IT Audit Specialist will provide independent, objective assurance to Nedbank Lesotho Limited Board of Directors, ensures that the Governance processes and management of risk and systems of internal control, are adequate and effective to mitigate the most significant risks both current and emerging, that threaten the achievement of the Nedbank Lesotho’s objectives, and in so doing help improve the control culture of the Bank.
Job Responsibilities
- Perform audit work based on annual audit plan.
- Identify high risk areas by analyzing all business documents, results and reports
- Assist in preparing an annual audit plan based on outcome of the risk assessment.
- Maintain good relations with regulators (CBL), external auditors, business (heads of departments and branch managers).
- Identify the Areas/Functions within the Bank with risks or potential risks that need to be audited, identifies the Risks and Controls (RACM)
- Identification of new or emerging IT risks, including technological and regulatory changes
- Ensure best practice by doing continuous research.
- Participate in Nedbank culture-building initiatives (eg staff surveys) to contribute to a culture conducive to the achievement of transformation goals.
- Ensure completeness and relevance of the Audit planning documentation through participation in the development thereof
- Assessment of IT control’s effectiveness in preventing or mitigating risks
- Network and liaise with the internal and external clients to build and sustain stakeholder relationships.
- Participate in business meetings for the relevant structures; eg committees and associations to contribute to stakeholder relationships.
- Negotiate and meet service level agreements to satisfy clients’ requirements.
- Highlight benefits in support of the implementation of recommendations to obtain buy-in for developing new and/or enhanced processes (eg operational processes) that will improve the functioning of stakeholders’ businesses.
Job Responsibilities Continue
- Cyber Assessment reviews to identify vulnerabilities, threats and potential breaches.
- Follow up on audit findings to ensure that corrective actions are implemented.
- Training and awareness to enhance staff understanding of IT controls and compliance requirements.
Essential Qualification
Degree in Computer Science and /Certified Information Systems Auditor (CISA) /equivalent.
Minimum Experience Level
Minimum of 4 years’ Experience in IT/ IT Auditing.
Technical / Professional Knowledge
- Ethics and Fraud
- Governance, Risk and Controls
- Accounting principles
- Principles of project management
- Relevant regulatory knowledge
- Business writing skills
- Auditing
- Institute of Internal Auditors standards
Technical Continued
- Expertise in IT general controls, application controls and frameworks
- Knowledge of IT environments, including networks, databases, operating systems
- Skills in analysing large databases using data analysis tools
- Familiarity with cyber-security principles, threat management, data protection etc.
Behavioural Competencies
- Applied Learning
- Communication
- Collaborating
- Decision Making
- Technical/Professional Knowledge and Skills
Closing date: 5th February 2025