Senior Internal Auditor
Tropical Bank
About this role
Assess the bank’s IT risks, evaluate the adequacy of IT controls, and recommend improvements to enhance system integrity, security, and efficiency.
Responsibilities
- Execute IT audits as per the audit plans and in accordance with policies, procedures, and best practices as might be necessary.
- 2. Participate in developing the annual Internal Audit Plan concerning IT audits.
- 3. Provide assurance on IT governance, security, and processes to ensure that the bank’s objectives are achieved.
- 4. Provide consultancy services to project teams on IT risk, system controls, and best practices while maintaining audit independence.
- 5. Carry out regular reviews of Bank IT systems and analysis of financial data to provide early warning signs needed for further investigations.
- 6. Monitor the bank’s IT environment for emerging risks and trends, ensuring timely response and adaptation.
- 7. Review the bank’s IT systems and processes and advise on compliance with applicable laws, regulations, and industry standards, such as data privacy regulations
- 8. Provide practical suggestions (recommendations) to Management and the Board to address IT control weaknesses identified across the bank.
- 9. Contribute to developing and refining IT audit methodologies and tools.
- 10. Evaluate and assess significant merging/consolidating functions and new or changing services, processes, operations, and control processes coincident with their development, implementation, and /or expansion.
- 11. Undertake to assist in investigating internal and external fraud cases, as requested.
- 12. Regularly carry out reviews on disaster recovery, IT Security, change management process, user access rights, and super user activities, among others.
- 13. Ensure that snap checks, including ICT (super-user activities, Access rights, etc.), are carried out occasionally.
- 14. Give guidance and advice on the impact of non-compliance with IT controls and statutory regulation on the Bank.
- Position Senior Internal Auditor- IT Systems
- Department Internal Audit Department
- Reports to Head Internal Audit
- Supervises: NA NA
- Interacts/interfaces with: Internal: Heads of department External: External Auditors, Regulators
- 15. Liaise with IT departmental heads to ensure audit findings and recommendations are fully accepted and implemented.
- 16. Evaluate the adequacy and effectiveness of IT controls in safeguarding the bank’s information assets.
- 17. Evaluate the integrity of the risk management information systems, including the accuracy, reliability, and completeness of the data used.
- 18. Comply with AML/CFT/CPF policies and procedures, non -compliance of which shall be addressed as per the bank disciplinary processes.
- 19. Any other duty as shall be assigned to you from time to time.
- Person Specification (Education, training, skills and experience)
Requirements
- Bachelor’s degree in accounting, statistics, Information Technology, Computer Science, or a related field
- Professional certifications: CISA, CRISC, or other related certifications.
- Experience
- · Minimum of 4 years of work experience in audit, IT audit, or IT risk management, preferably within the banking or financial services industry.
- · Excellent knowledge of IIA Standards and Legislation.
- · Knowledge and application of modern IT security management practices in financial services.
- · Experience with auditing core banking systems, IT infrastructure, and cybersecurity frameworks.
- Competencies & Knowledge
- · Proficiency in drafting professional correspondence, reports, and proposals.
- · Excellent communication and presentation skills.
- · Strategic and dynamic thinking.
- · Leadership and Change Management skills
- · Stakeholder and Relationship Management skills
- · High ethical standards and integrity.
- · neutrality and independence of judgment
- · Problem-solving abilities.
- · Proficiency in English Language and any other local language, preferably Luganda