The Role
Leads end-to-end IT, cybersecurity, and technology risk audit engagements, including planning, control testing, fieldwork supervision, reporting, remediation tracking, and risk assessment. Evaluates IT general controls, application controls, identity and access management, cloud configurations, network and endpoint security. Presents findings to technology stakeholders, agrees corrective actions, coaches audit staff, and supports annual and quarterly technology audit reporting.
Summary Generated by Built In
As Audit Lead – IT & Cyber Security Audit, you will lead the end-to-end execution
of IT, cybersecurity, and technology audit engagements, supervising
engagement teams and delivering high-quality audit results in line with Tabby's
technology risk-based audit plan.
of IT, cybersecurity, and technology audit engagements, supervising
engagement teams and delivering high-quality audit results in line with Tabby's
technology risk-based audit plan.
Key Responsibilities
● Lead the planning and execution of assigned IT general controls,
● application controls, and cybersecurity audit engagements, from
scoping through reporting.
● Develop detailed audit programs and risk and control matrices (RCMs)
covering IT and cyber risk areas, aligned with the approved audit plan.
● Supervise and review the fieldwork of Senior Auditors, Auditors, and
Interns assigned to the engagement, ensuring quality and adherence to
methodology.
● Conduct walkthroughs, technical interviews, and testing of IT general
controls, application controls, network and endpoint security, identity
and access management, and cloud configurations.
● Identify control gaps and root causes, and draft clear, actionable audit
findings and recommendations on technology and cyber risk.
● Draft audit reports and present engagement results to Engineering and
Information Security process owners.
● Engage directly with technology process owners to validate findings,
agree on corrective action plans, and set remediation timelines.
● Track and follow up on the implementation of IT and cyber audit
recommendations for assigned engagements.
● Contribute to the annual technology and cyber risk assessment for
assigned systems and platforms.
● Coach and provide on-the-job guidance to Senior Auditors, Auditors,
and Interns on IT audit techniques.
● Support the Audit Manager in preparing quarterly and annual IT/cyber
audit reporting materials.
● Stay current on IT auditing standards, cybersecurity frameworks, and
● SAMA regulatory requirements (including the SAMA Cyber Security
scoping through reporting.
● Develop detailed audit programs and risk and control matrices (RCMs)
covering IT and cyber risk areas, aligned with the approved audit plan.
● Supervise and review the fieldwork of Senior Auditors, Auditors, and
Interns assigned to the engagement, ensuring quality and adherence to
methodology.
● Conduct walkthroughs, technical interviews, and testing of IT general
controls, application controls, network and endpoint security, identity
and access management, and cloud configurations.
● Identify control gaps and root causes, and draft clear, actionable audit
findings and recommendations on technology and cyber risk.
● Draft audit reports and present engagement results to Engineering and
Information Security process owners.
● Engage directly with technology process owners to validate findings,
agree on corrective action plans, and set remediation timelines.
● Track and follow up on the implementation of IT and cyber audit
recommendations for assigned engagements.
● Contribute to the annual technology and cyber risk assessment for
assigned systems and platforms.
● Coach and provide on-the-job guidance to Senior Auditors, Auditors,
and Interns on IT audit techniques.
● Support the Audit Manager in preparing quarterly and annual IT/cyber
audit reporting materials.
● Stay current on IT auditing standards, cybersecurity frameworks, and
● SAMA regulatory requirements (including the SAMA Cyber Security
Skills, Knowledge and Expertise
● 5+ years of experience in IT audit, information security, or technology risk,
including experience leading audit engagements, preferably within
banking, fintech, or corporate environments.
● Strong knowledge of IT auditing standards, cybersecurity frameworks,
and SAMA regulatory requirements.
● Experience assessing IT general controls, application controls, and
cybersecurity controls.
● Strong communication and interpersonal skills to engage with
technology process owners and present audit findings.
● Strong analytical and problem-solving skills with a detail-oriented
approach.
● Proficiency in IT audit tools and familiarity with cloud platforms
(AWS/Azure/GCP).
● Bachelor's degree in Computer Science, Information Systems,
Cybersecurity, or a related field; CISA (obtained or in progress) highly
desirable.
including experience leading audit engagements, preferably within
banking, fintech, or corporate environments.
● Strong knowledge of IT auditing standards, cybersecurity frameworks,
and SAMA regulatory requirements.
● Experience assessing IT general controls, application controls, and
cybersecurity controls.
● Strong communication and interpersonal skills to engage with
technology process owners and present audit findings.
● Strong analytical and problem-solving skills with a detail-oriented
approach.
● Proficiency in IT audit tools and familiarity with cloud platforms
(AWS/Azure/GCP).
● Bachelor's degree in Computer Science, Information Systems,
Cybersecurity, or a related field; CISA (obtained or in progress) highly
desirable.
About
Tabby creates financial freedom in the way people shop, earn and save, by reshaping their relationship with money.The company’s flagship offering allows shoppers to split their payments online and in-store with no interest or fees. Over 32,000 global brands and small businesses, including Amazon, Noon, IKEA and Shein use Tabby to accelerate growth and gain loyal customers by offering easy and flexible payments online and in stores.Tabby has generated over $7 billion in transaction volume for its partner brands and has the highest rated, most reviewed, largest and fastest growing app of any fintech in the GCC region.Tabby launched operations in 2020 and has raised +$1 billion in equity and debt funding from global and regional investors.
Skills Required
- 5+ years of experience in IT audit, information security, or technology risk, including leading audit engagements
- Knowledge of IT auditing standards, cybersecurity frameworks, and SAMA regulatory requirements
- Experience assessing IT general controls, application controls, and cybersecurity controls
- Strong communication and interpersonal skills
- Strong analytical and problem-solving skills with attention to detail
- Proficiency in IT audit tools and familiarity with AWS, Azure, or GCP
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related field
- CISA certification, obtained or in progress
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Tabby is a financial technology company on a mission to create financial freedom by reshaping people's relationship with money through buy now, pay later services, allowing consumers to split purchases into interest-free payments.






