Job description
Job Summary
The incumbent will support audits covering the IT Applications Audit portfolio as a member of the Group Internal Audit Function. The role provides independent assurance on the effectiveness of controls over technology risks, cybersecurity threats, data governance, and digital transformation initiatives across the enterprise. It also supports the strategic implementation and integration of advanced data analytics tools and continuous auditing techniques across the audit function to enhance efficiency and real-time risk monitoring. This role requires full compliance with the GIAD Group Audit Manual, IIA standards, and all relevant local regulations and industry IT audit standards. As a member of the Group Internal Audit Function, this role ensures technology risks are effectively integrated into the overall audit strategy and contributes to strengthening the organization's resilience against evolving cyber threats.
Main Responsibilities
Essential Duties & Responsibilities by Dimensions:
Shareholder & Financial:
-Contribute to the execution of the risk-based annual plan that aligns with the Group Internal Audit strategy and helps safeguard critical IT assets, data, and systems that underpin the organization's financial operations and shareholder value.
-Assist in identifying significant IT and cybersecurity risks that could lead to financial loss, operational disruption, or reputational damage, providing actionable recommendations to mitigate these risks.
-Assess the efficiency and effectiveness of IT investments and technology-related processes.
-Implements KPIs and best practices for the Global IT and Information Security audit function.
-Promote cost consciousness and efficiency and enhance productivity, to minimise cost, avoid waste, and optimise benefits for the bank.
-Act within the limits of the powers delegated to the incumbent
-Demonstrate clear understanding of the drivers behind the bank's financial & non-financial performance.
Customer (Internal & External):
-Build and maintain strong, independent, and collaborative relationships with relevant business and support function staff and stakeholders across the Group.
-Communicate complex technical audit findings, cyber risk assessments, and recommendations to the SVP, EVP, GCAE and other senior stakeholders as directed, translating technical jargon into clear business implications.
-Provide advisory services to IT and business leaders as directed by the SVP and EVP on matters of IT governance, information security, and technology risk management.
-To assist (internal) customers in all their queries on Bank’s product and seek solution to their requests.
-Maintain activities in accordance with Service Level Agreements (SLAs) with internal departments/units to achieve improvements in turn-around time.
-Build and maintain strong/effective relationships with related departments/units to achieve the Group’s objectives.
Provide timely/accurate data to external/internal Auditors, Compliance, Financial Control and Risk when required
Coordinate effectively with external IT auditors, cybersecurity consultants, and regulatory bodies on technology-related assurance activities.
Internal (Processes, Products, Regulatory):
-Act as a team member on audit engagements for the IT Applications Audit portfolio, including infrastructure, applications, data management, network security, access controls, incident response, and business continuity across all Group entities. All audit activities must be conducted in full compliance with the GIAD Group Audit Manual, the IIA's International Professional Practices Framework (IPPF), and relevant ISACA IT audit standards.
-Engagements: support the team leader in executing the audit engagements and ensuring own work is performed efficiently and effectively and meets GIAD quality standards.
-Planning phase: support the team leader in conducting detailed risk assessments and interviews with auditees to define and document the precise audit scope and work program in the required deliverables (APM, RCM and ToR) addressing the most significant risks.
-Fieldwork phase: conduct testing of assigned scope areas and support the team leader to prepare progress updates and interim meetings with the auditees.
-Reporting phase: draft clear and concise audit issues and recommendations supported by solid evidence, present audit findings to the auditees to obtain management actions.
-Issue Follow up Phase: Perform issue closure validation in accordance with the latest audit methodology and timely escalate potential delays to management, as needed.
-Timely conduct audit file closure procedures in accordance with the latest audit methodology and standards.
-Collaborate with peers to achieve full coverage of domestic subsidiaries, support, control and risk functions in the organization.
-Support the delivery of IT applicationaudits, assessing the design and operating effectiveness of technology controls against industry best practices and regulatory requirements.
-Assess the adequacy and effectiveness of the organization's information security frameworks (e.g., ISO 27001, NIST, COBIT), IT governance structures, and disaster recovery capabilities.
-Identify and report on IT control weaknesses, cybersecurity vulnerabilities, and operational inefficiencies within technology environments, providing technically sound and actionable recommendations.
-Ensure the consistent application of IT audit methodologies, tools, and best practices across all IT and Information Security audit engagements.
-Support the strategic integration of data analytics (tools) into the audit practice to enhance risk identification, efficiency, and depth of analysis. Drive the implementation and maturation of continuous auditing capabilities to provide real-time assurance and insights.
Learning & Knowledge:
-Stay abreast of global IT trends, evolving cyber threats, and new technologies to proactively identify emerging risks and adapt audit strategies. This includes actively fostering practical skills in data analytics and continuous auditing techniques within the audit division.
-Identify areas for professional development of self and undertake development activities.
-Remain current with all developments in professional field.
-Escalate unresolved grievances or conflicts with team members to the SVP and EVP for resolution.
Legal, Regulatory, and Risk Framework Responsibilities:
-Ensure compliance with all applicable legal, regulatory and internal compliance requirements including, but not limited to, Group Compliance Policies and Procedures (AML & CTF, Sanctions Policy, Data Protection Policy, Fraud Control Policy, Whistle Blowing Policy, Conflict of Interest and Insider Dealing Policy).
-Understand and effectively perform your role under the Three Lines of Defence principle to identify measure, monitor, manage and report risks.
-Ensure systematic good outcomes for clients in accordance with Conduct Risk policy.
-Support the framework of RCSA, KRI, Incident reporting and remediation, as appropriate, in accordance with the Operational Risk Management requirements.
-Maintain appropriate knowledge to ensure full qualification to undertake the role.
-Complete all mandatory training provided by the Bank, attain, and maintain the required levels of competence.
-Attend mandatory (internal and external) seminars as instructed by the Bank.
-Ensure the Information Security Audit function operates in full compliance with all applicable global IT regulations, data privacy laws (e.g., GDPR, CCPA), cybersecurity frameworks, and industry standards relevant to the organization's technology operations.
-This includes strict adherence to the GIAD Group Audit Manual, the IIA Standards, and specific local regulatory requirements.
-Provide insights from audit findings to the EVP to contribute to the enhancement of the organization's enterprise-wide risk management framework.
-Ensure IT audit engagements incorporate relevant regulatory compliance requirements and address inherent technology-related compliance risks.
-Contribute to strengthening the organization's overall cybersecurity posture, data governance, and IT risk management culture.
Other:
-Ensure high standards of data protection and confidentiality to safeguard commercially sensitive information.
-Maintaining utmost confidentiality concerning customer and internal bank information obtained during the course of business and provide such information on a need-to-know basis only to Senior Management of QNB, Audit and Compliance functions, and relevant Regulators.
-Maintain high professional standards to uphold QNB's reputation and to strengthen its market leadership position
-All other ad hoc duties/activities related to QNB that management might request from time to time.
Education and Experience Requirements
-University graduate preferably with a Major in Information Technology, Computer Science, Cybersecurity, Business Administration, or a related field. Master’s is preferred.
-Desirable Certifications: Certified Information Systems Auditor (CISA) and/or Certified Internal Auditor (CIA) is preferred. Additional certifications such as CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), CRISC (Certified in Risk and Information Systems Control), or relevant cloud certifications are highly desirable.
-Good analytical, critical thinking, and problem-solving abilities with a strong technical aptitude; superior verbal and written communication skills, with the ability to translate complex technical issues into understandable business risks for diverse audiences; high level of integrity, objectivity, and professional skepticism; excellent interpersonal and influencing skills, with the ability to effectively challenge IT and business leaders; demonstrated ability to work independently and collaboratively as part of the Internal Audit Management Team.
-Excellent oral and written communication skills (including report writing) in English and Arabic (preferred).
-Good interpersonal and presentation skills.
-Understanding of the relevant laws, regulations, and practices.
-Ability to make decisions and follow through with initiatives.
-Personal integrity and self-management.
-Planning, organizing, and analytical ability.
-Results oriented.
-Strong analytical skills and the ability to communicate both verbally and in writing with all levels of management.
الوصف الوظيفي
ملخص الوظيفة
سيقوم شاغل الوظيفة بتقديم الدعم لأعمال التدقيق التي تغطي محفظة تدقيق تطبيقات تكنولوجيا المعلومات بصفته عضواً في قطاع التدقيق الداخلي للمجموعة. يوفر هذا الدور تأكيداً مستقلاً بشأن فاعلية الضوابط الخاضعة لمخاطر التكنولوجيا، والتهديدات السيبرانية، وحوكمة البيانات، ومبادرات التحول الرقمي عبر المؤسسة. كما يدعم التنفيذ الاستراتيجي والدمج لأدوات تحليل البيانات المتقدمة وتقنيات التدقيق المستمر عبر إدارة التدقيق لتعزيز الكفاءة ومراقبة المخاطر في الوقت الفعلي. يتطلب هذا الدور الالتزام الكامل بدليل التدقيق الخاص بقطاع التدقيق الداخلي للمجموعة (GIAD)، ومعايير المعهد الأمريكي للمدققين الداخليين (IIA)، وجميع اللوائح المحلية ذات الصلة ومعايير تدقيق تكنولوجيا المعلومات القطاعية. وبصفته عضواً في قطاع التدقيق الداخلي للمجموعة، يضمن هذا الدور دمج مخاطر التكنولوجيا بفاعلية في استراتيجية التدقيق الشاملة ويسهم في تعزيز مرونة المؤسسة ضد التهديدات السيبرانية المتطورة.
المسؤوليات الرئيسية
الواجبات والمسؤوليات الأساسية حسب المحاور:
المساهمون والشؤون المالية:
-المساهمة في تنفيذ الخطة السنوية القائمة على المخاطر والتي تتوافق مع استراتيجية التدقيق الداخلي للمجموعة وتساعد في حماية أصول تكنولوجيا المعلومات الحيوية والبيانات والأنظمة التي تدعم العمليات المالية للمؤسسة وقيمة المساهمين.
-المساعدة في تحديد مخاطر تكنولوجيا المعلومات والأمن السيبراني الجوهرية التي قد تؤدي إلى خسارة مالية، أو تعطل تشغيلي، أو إضرار بالسمعة، وتقديم توصيات قابلة للتنفيذ للحد من هذه المخاطر.
-تقييم كفاءة وفاعلية استثمارات تكنولوجيا المعلومات والعمليات المتعلقة بالتكنولوجيا.
-تطبيق مؤشرات الأداء الرئيسية وأفضل الممارسات لوظيفة تدقيق تكنولوجيا المعلومات والأمن السيبراني العالمية.
-تعزيز الوعي بالتكاليف والكفاءة وتحسين الإنتاجية، للحد من التكاليف وتجنب الهدر وتحقيق أقصى استفادة للبنك.
-العمل في حدود الصلاحيات الممنوحة لشاغل الوظيفة.
-إظهار فهم واضح للمحركات التي تقف وراء الأداء المالي وغير المالي للبنك.
العملاء (الداخليون والخارجيون):
-بناء وتعزيز علاقات قوية ومستقلة وتعاونية مع موظفي قطاعات الأعمال والوظائف المساندة ذات الصلة وأصحاب المصلحة في جميع أنحاء المجموعة.
-توصيل نتائج التدقيق الفنية المعقدة وتقييمات المخاطر السيبرانية والتوصيات إلى نائب الرئيس الأول، ونائب الرئيس التنفيذي، والرئيس التنفيذي للتدقيق الداخلي للمجموعة، وغيرهم من كبار أصحاب المصلحة وفقاً للتوجيهات، مع ترجمة المصطلحات الفنية إلى آثار تجارية واضحة.
-تقديم خدمات استشارية لقادة تكنولوجيا المعلومات والأعمال وفقاً لتوجيهات نائب الرئيس الأول ونائب الرئيس التنفيذي بشأن أمور حوكمة تكنولوجيا المعلومات، وأمن المعلومات، وإدارة مخاطر التكنولوجيا.
-مساعدة العملاء (الداخليين) في جميع استفساراتهم المتعلقة بمنتجات البنك والبحث عن حلول لطلباتهم.
-المحافظة على الأنشطة وفقاً لاتفاقيات مستوى الخدمة (SLAs) مع الإدارات/الوحدات الداخلية لتحقيق تحسينات في زمن إنجاز الأعمال.
-بناء وتطوير علاقات قوية/فعالة مع الإدارات/الوحدات ذات الصلة لتحقيق أهداف المجموعة.
توفير بيانات دقيقة وفي الوقت المناسب للمدققين الخارجيين/الداخليين، والالتزام، والرقابة المالية، وإدارة المخاطر عند الطلب.
التنسيق بفاعلية مع مدققي تكنولوجيا المعلومات الخارجيين، ومستشاري الأمن السيبراني، والجهات التنظيمية بشأن أنشطة التأكيد المتعلقة بالتكنولوجيا.
الأمور الداخلية (العمليات، المنتجات، الأمور التنظيمية):
-العمل كعضو فريق في مهام التدقيق لمحفظة تدقيق تطبيقات تكنولوجيا المعلومات، بما في ذلك البنية التحتية، والتطبيقات، وإدارة البيانات، وأمن الشبكات، وضوابط الوصول، والاستجابة للحوادث، واستمرارية الأعمال عبر جميع كيانات المجموعة. يجب إجراء جميع أنشطة التدقيق بالالتزام الكامل بدليل التدقيق الخاص بقطاع التدقيق الداخلي للمجموعة (GIAD)، والإطار المهني الدولي لممارسة التدقيق الداخلي (IPPF) الصادر عن IIA، ومعايير تدقيق تكنولوجيا المعلومات ذات الصلة من ISACA.
-مهام التدقيق: دعم قائد الفريق في تنفيذ مهام التدقيق وضمان أداء العمل الخاص به بكفاءة وفاعلية واستيفائه لمعايير الجودة لقطاع التدقيق الداخلي للمجموعة (GIAD).
-مرحلة التخطيط: دعم قائد الفريق في إجراء تقييمات مفصلة للمخاطر وإجراء مقابلات مع الخاضعين للتدقيق لتحديد وتوثيق نطاق التدقيق الدقيق وبرنامج العمل في المخرجات المطلوبة (مذكرة التخطيط للتدقيق APM، ومصفوفة المخاطر والضوابط RCM، والشروط المرجعية ToR) التي تعالج أبرز المخاطر الجوهرية.
-مرحلة العمل الميداني: إجراء اختبارات لمجالات النطاق المحددة ودعم قائد الفريق لإعداد تحديثات سير العمل والاجتماعات المرحلية مع الخاضعين للتدقيق.
-مرحلة إعداد التقارير: صياغة ملاحظات وتوصيات التدقيق بشكل واضح وموجز ومدعوم بأدلة قوية، وتقديم نتائج التدقيق إلى الخاضعين للتدقيق للحصول على إجراءات الإدارة.
-مرحلة متابعة الملاحظات: إجراء التحقق من إغلاق الملاحظات وفقاً لأحدث منهجية تدقيق وتصعيد التأخيرات المحتملة للإدارة في الوقت المناسب حسب الحاجة.
-إجراء إجراءات إغلاق ملف التدقيق في الوقت المناسب وفقاً لأحدث منهجية ومعايير التدقيق.
-التعاون مع الزملاء لتحقيق تغطية كاملة للشركات التابعة المحلية، ووظائف الدعم والرقابة والمخاطر في المؤسسة.
-دعم تنفيذ تدقيق تطبيقات تكنولوجيا المعلومات، وتقييم تصميم وفاعلية تشغيل الضوابط التكنولوجية مقابل أفضل الممارسات القطاعية والمتطلبات التنظيمية.
-تقييم مدى كفاية وفاعلية أطر أمن المعلومات بالمؤسسة (مثل ISO 27001، NIST، COBIT)، وهياكل حوكمة تكنولوجيا المعلومات، وإمكانيات التعافي من الكوارث.
-تحديد والإبلاغ عن نقاط الضعف في ضوابط تكنولوجيا المعلومات، الثغرات الأمنية السيبرانية، وعدم الكفاءة التشغيلية داخل بيئات التكنولوجيا، وتقديم توصيات سليمة فنياً وقابلة للتنفيذ.
-ضمان التطبيق الاتساق لمنهجيات وأدوات وأفضل ممارسات تدقيق تكنولوجيا المعلومات عبر جميع مهام تدقيق تكنولوجيا المعلومات وأمن المعلومات.
-دعم الدمج الاستراتيجي لـ (أدوات) تحليل البيانات في ممارسة التدقيق لتعزيز تحديد المخاطر، والكفاءة، وعمق التحليل. قيادة تنفيذ وتطوير قدرات التدقيق المستمر لتقديم تأكيدات ورؤى في الوقت الفعلي.
التعلم والمعرفة:
-مواكبة التوجهات العالمية في مجال تكنولوجيا المعلومات، والتهديدات السيبرانية المتطورة، والتكنولوجيات الجديدة لتحديد المخاطر الناشئة استباقياً وتكييف استراتيجيات التدقيق. ويشمل ذلك تعزيز المهارات العملية بفاعلية في تقنيات تحليل البيانات والتدقيق المستمر داخل قسم التدقيق.
-تحديد مجالات التطوير المهني الذاتي والقيام بأنشطة التطوير.
-متابعة أحدث المستجدات والتطورات في المجال المهني.
-تصعيد المظالم أو النزاعات غير المحسومة مع أعضاء الفريق إلى نائب الرئيس الأول ونائب الرئيس التنفيذي للبت فيها.
مسؤوليات الإطار القانوني والتنظيمي والمخاطر:
-ضمان الالتزام بجميع المتطلبات القانونية والتنظيمية والامتثال الداخلي المعمول بها، بما في ذلك، على سبيل المثال لا الحصر، سياسات وإجراءات الامتثال للمجموعة (مكافحة غسل الأموال وتمويل الإرهاب، سياسة العقوبات، سياسة حماية البيانات، سياسة مكافحة الاحتيال، سياسة الإبلاغ عن المخالفات، سياسة تعارض المصالح والتعامل بناءً على معلومات داخلية).
-فهم دورك وأداؤه بفاعلية بموجب مبدأ خطوط الدفاع الثلاثة لتحديد المخاطر وقياسها ومراقبتها وإدارتها والإبلاغ عنها.
-ضمان تحقيق نتائج جيدة ومنهجية للعملاء وفقاً لسياسة مخاطر السلوك المهني.
-دعم إطار تقييم المخاطر والضوابط الذاتية (RCSA)، ومؤشرات المخاطر الرئيسية (KRI)، والإبلاغ عن الحوادث ومعالجتها، حسب الاقتضاء، وفقاً لمتطلبات إدارة المخاطر التشغيلية.
-الحفاظ على المعرفة المناسبة لضمان التأهيل الكامل للقيام بالدور.
-إكمال جميع التدريبات الإلزامية التي يحددها البنك، واكتساب مستويات الكفاءة المطلوبة والحفاظ عليها.
-حضور الندوات الإلزامية (الداخلية والخارجية) وفقاً لتوجيهات البنك.
-ضمان عمل وظيفة تدقيق أمن المعلومات بالالتزام الكامل بجميع لوائح تكنولوجيا المعلومات العالمية المعمول بها، وقوانين خصوصية البيانات (مثل GDPR وCCPA)، وأطر الأمن السيبراني، والمعايير القطاعية ذات الصلة بالعمليات التكنولوجية للمؤسسة.
-ويشمل ذلك الالتزام الصارم بدليل التدقيق الخاص بقطاع التدقيق الداخلي للمجموعة (GIAD)، ومعايير المعهد الأمريكي للمدققين الداخليين (IIA)، والمتطلبات التنظيمية المحلية المحددة.
-تقديم رؤى مستمدة من نتائج التدقيق إلى نائب الرئيس التنفيذي للمساهمة في تعزيز إطار إدارة المخاطر على مستوى المؤسسة ككل.
-ضمان تضمين مهام تدقيق تكنولوجيا المعلومات لمتطلبات الامتثال التنظيمي ذات الصلة ومعالجة مخاطر الامتثال المتأصلة ذات الصلة بالتكنولوجيا.
-المساهمة في تعزيز الجاهزية الشاملة للأمن السيبراني في المؤسسة، وحوكمة البيانات، وثقافة إدارة مخاطر تكنولوجيا المعلومات.
أخرى:
-ضمان تطبيق معايير عالية لحماية البيانات والسرية للحفاظ على المعلومات الحساسة تجارياً.
-الحفاظ على أقصى درجات السرية فيما يتعلق بمعلومات العملاء والمعلومات الداخلية للبنك التي يتم الحصول عليها أثناء ممارسة الأعمال، وتقديم هذه المعلومات على أساس "الحاجة إلى المعرفة" فقط للإدارة العليا لبنك QNB، ووظائف التدقيق والامتثال، والجهات التنظيمية ذات الصلة.
-الحفاظ على معايير مهنية عالية لدعم سمعة QNB وتعزيز مكانتها الريادية في السوق.
-جميع المهام/الأنشطة الإضافية الأخرى المتعلقة بمجموعة QNB التي قد تطلبها الإدارة من وقت لآخر.
متطلبات المؤهلات والخبرة
-خريج جامعي ويفضل أن يكون حاصلاً على تخصص في تكنولوجيا المعلومات، أو علوم الحاسوب، أو الأمن السيبراني، أو إدارة الأعمال، أو مجال ذي صلة. يفضل الحصول على درجة الماجستير.
-الشهادات المرغوبة: يفضل الحصول على شهادة مدقق نظم معلومات معتمد (CISA) و/أو مدقق داخلي معتمد (CIA). الشهادات الإضافية مثل CISSP (ممارس أمن نظم المعلومات المعتمد)، CISM (مدير أمن المعلومات المعتمد)، CRISC (معتمد في مخاطر ونظم المعلومات والرقابة)، أو شهادات السحابة ذات الصلة مرغوبة بشدة.
-قدرات جيدة في التحليل، والتفكير الناقد، وحل المشكلات مع ميول تقنية قوية؛ مهارات ممتازة في التواصل الشفهي والكتابي، مع القدرة على ترجمة القضايا الفنية المعقدة إلى مخاطر أعمال مفهومة لمختلف الفئات؛ مستوى عالٍ من النزاهة والموضوعية والشك المهني؛ مهارات ممتازة في التعامل مع الآخرين والتأثير، مع القدرة على توجيه تحديات بناءة لقادة تكنولوجيا المعلومات والأعمال بفاعلية؛ قدرة مثبتة على العمل بشكل مستقل وبتعاون كجزء من فريق إدارة التدقيق الداخلي.
-مهارات ممتازة في التواصل الشفهي والكتابي (بما في ذلك كتابة التقارير) باللغتين الإنجليزية والعربية (تفضل اللغة العربية).
-مهارات جيدة في التواصل مع الآخرين وتقديم العروض التقديمية.
-فهم القوانين واللوائح والممارسات ذات الصلة.
-القدرة على اتخاذ القرارات ومتابعة المبادرات.
-النزاهة الشخصية والإدارة الذاتية.
-القدرة على التخطيط والتنظيم والتحليل.
-التركيز على تحقيق النتائج.
-مهارات تحليلية قوية والقدرة على التواصل شفهياً وكتابياً مع جميع مستويات الإدارة.