Job Summary
The IT Audit Manager is responsible for leading the development and execution of the organization's IT audit strategy and annual audit plan. The role oversees audits of IT infrastructure, applications, cybersecurity, and technology governance to evaluate the effectiveness of internal controls, risk management, and compliance while providing recommendations to strengthen IT security and operational performance.
Key Responsibilities
- Develop and execute the annual IT audit strategy and audit plan in alignment with the Internal Audit Department's objectives and the company's business strategy.
- Lead IT audits covering information security, enterprise applications, IT infrastructure, networks, operating systems, data centers, SAP ERP, retail systems, and other technology platforms to assess the effectiveness of IT controls and cybersecurity measures.
- Evaluate IT security risks, identify control weaknesses and vulnerabilities, and assess the adequacy of mitigation measures in collaboration with business units and external cybersecurity specialists.
- Design, review, and continuously enhance IT audit programs by defining audit objectives, scope, methodologies, and risk-based procedures in accordance with professional auditing standards.
- Manage and supervise audit engagements to ensure audit quality, timely completion, and compliance with internal audit methodologies and professional standards while providing technical guidance to the audit team.
- Maintain and enhance the organization's enterprise IT risk assessment framework to support risk-based audit planning and continuous monitoring.
- Prepare comprehensive audit reports, communicate audit findings, and provide practical recommendations to strengthen internal controls, governance, cybersecurity, and operational effectiveness.
- Monitor and follow up on management action plans to ensure timely implementation of agreed corrective actions.
- Provide advisory services to business and IT management on IT governance, internal controls, cybersecurity, technology risk management, application security, and infrastructure security.
- Lead, coach, and develop the IT audit team while promoting continuous improvement through the adoption of data analytics, audit technologies, and best practices to improve audit efficiency and effectiveness.
Qualifications
- Bachelor's or Master's degree in Information Technology, Computer Science, Management Information Systems, Computer Engineering, Cybersecurity, or a related field.
- Minimum 7 years of experience in Internal Audit, IT Audit, IT Risk Management, Information Security, IT Controls, or related disciplines, with at least 3 years in a managerial or team leadership role.
- Strong knowledge of IT audit methodologies, IT governance, cybersecurity, IT general controls (ITGC), application controls, risk management, and internal control frameworks.
- Experience auditing enterprise systems such as SAP ERP, retail systems, data centers, networks, operating systems, and cloud or infrastructure environments is highly preferred.
- Proven leadership, people management, project management, and decision-making skills with the ability to manage multiple audit engagements.
- Strong analytical, strategic thinking, and problem-solving capabilities.
- Excellent communication, stakeholder management, presentation, and report-writing skills.
- Proficient in Microsoft Office applications and SAP ERP.
- Professional certifications such as CISA, CISSP, CISM, CRISC, CIA, or other relevant IT audit or cybersecurity certifications will be an advantage.
Work location : The Mall Ramkhamhaeng (Headquarter), Nearby Airport Link Ramkhamhaeng station