Ebrahim Khalil Kanoo
We, at Ebrahim K. Kanoo, are looking for an Auditor, IT Security for our company based in the Kingdom of Bahrain, This position will directly be reporting to the Chief Internal Auditor and Senior Manager, Internal Audit.
Candidates who meet the below criteria can apply for the role attaching your updated CV.
Responsibilities:
Preparation of effective 3 yearly & annual IT Security Audit Plan and ensure completion of the same as scheduled.
Conduct risk-based reviews of IT Security for the Organization, verify compliance to various policies, procedures and established practices & standards, conduct analysis to identify loopholes and strengthen IT Security controls.
To carry out reviews of the following:
Policies and procedures adopted by the Group on IT Security for the IT Assets and Applications.
Security & Control requirements of IT infrastructure of the Group including various Networks, Servers and end point devices and compliance.
IT Security architecture in place and opportunities for improvement.
Data entry and exit points from Network and Application’s scope.
Data Backup and Recovery plans and periodical testing of the same by the concerned business units.
Configuration and Change management controls for the IT infrastructure and Applications.
IT Operating Systems, Applications, Websites, and security risks involved in them and mitigating controls taken.
User access authorization for Operating Systems and Applications.
Patch management and vulnerability remediation.
Compliance to regulatory requirements, wherever applicable.
Prepare & finalize IT Security Audit Reports and categorization of the audit findings based on the risk assessments and present audit findings based on risk perception and suggest practicable solutions.
Conduct regular follow-up for the compliance of reported findings / recommendations to achieve a logical conclusion for the audit findings.
Qualifications:
IT Engineer or IT Graduate. Certifications like CISA / CISM is a must.
Certifications in IT security related matters.
5 – 10 years of on hands-on experience in the field of IT, out of which 3-5 years in IT Security Audit in a diversified organization.
Knowledge of Audit concepts.