Open role
IT Auditor (ITGC Expert)
Hirexa Solutions B.V.
About the role
To liaise on the ITGC annual audit planning with the IT internal control team;
To communicate and liaise on the audit plan, activities and mandatory input / evidence to the auditees (i.e. control owners and control executors);
To maintain test scripts / test reports;
To ensure timely receipt of mandatory input/evidence by auditees;
To test the design and operational effectiveness of the controls according the ITGC audit plan;
To safeguard the evidences and test reports in the IT internal Control team files;
To deliver the draft test report incl. conclusions and suggestions to the IT internal Control Coordinator for quality review;
To report findings on control design and operational effectiveness, and issues to stakeholders e.g. control owners, process owners, departmental management team and Internal Control Coordinator;
To provide advice on control issue remediation and redesign (upon request);To re-test the design and operational effectiveness - including management actions- of a control after issue remediation has been completed. Input (by us):
What you'll bring
Internal Auditing
Experience (Years):
8-10
Dutch Speaking mandatory.
IT General controls (ITGC) supporting the organization business applications in scope for internal control over financial reporting have to be audited annually.
We are looking for senior IT audit capability to conduct such IT audits in line with the organization IT internal control framework and related policies & procedures and our annual audit/test plan.
IT audit certification / accreditation: e.g. CISA (Certified Information Systems Auditor by ISACA), RE (Registered EDP Auditor by Dutch NOREA);
Minimum of 5 year experience in IT auditing and ITGC Expert technical knowledge of:
a) HANA, MySQL, Oracle, Kubernetes, MS windows, MS Azure, GCP, Unix, Linux, SAP.
Nice to have: z/OS and DB2
b) IT processes in general, ITIL and Agile way of working, DevOpsGeneric knowledge of
c) best practices and frameworks such as ISO 27001 / 27002, Cobit for SoX, it4it, coso. Preferred are: ISO 27017 / 27018
d) reasonable assurance and independent auditing e.g. ISAE / SSAE / Service Organisation Control reports type i and type ii
e) tooling such as: servicenow, splunk, O365, Github, Terraform
Language: fluent in English (both orally and in writing).