Manager, IT Audit

Posted 2 Days Ago
Be an Early Applicant
Kuala Lumpur, Wilayah Persekutuan Kuala Lumpur, MYS
In-Office
Mid level
Financial Services
The Role
Leads and supports technology audit engagements from risk assessment and planning through reporting, issue assurance, and closure. Evaluates IT controls, security, infrastructure, applications, operations, governance, third-party risk, resilience, privacy, cloud, and emerging technologies. Develops audit findings and recommendations, engages senior stakeholders, monitors remediation, contributes to risk-based audit planning, expands data analytics testing, and supports board and management reporting.
Summary Generated by Built In

Prudential’s purpose is to be partners for every life and protectors for every future. Our purpose encourages everything we do by creating a culture in which diversity is celebrated and inclusion assured, for our people, customers, and partners. We provide a platform for our people to do their best work and make an impact to the business, and we support our people’s career ambitions. We pledge to make Prudential a place where you can Connect, Grow, and Succeed.

A member of the Global IT audit resource pool, you are responsible for:
• Assisting to develop and continuously review the half-yearly risk based audit plan for Prudential, aligned to LBU strategy
• Lead or support in delivering the assigned audit which includes entire audit process from planning to issue assurance and closure
• Other GwIA driven initiatives

Principal accountabilities:

To provide value adding contribution to audit reviews of processes, controls and systems, within Prudential and across the other business units in the Group as required:

Project/Audit Execution:
•    Deliver good quality audit assignments in line with GwIA audit methodology, Group requirements and standards, resulting in accurate and complete identification of issues
•    Execute the audits in the approved audit plan including risk assessment and control management over operations’ effectiveness and compliance with all applicable standards and regulations
•    Understand the business, risk and controls through information gathered on the audit scope area, involvement in walkthroughs and discussions with management
•    Review the adequacy and efficiency of the controls in place via review of documented procedures and conducting audit testing
•    Working papers are documented properly in accordance with GwIA Audit Methodology and approved within the established deadline 
•    Responsible for discussing the audit report and findings with senior management and ensuring that appropriate responses are obtained for each issue raised in the report, including demonstration of good conflict management skill and remaining professional when criticised
•    Draft internal audit report for discussion with GwIA management and auditee management, including display of good and concise presentation of issues/risks
•    Monitor progress and adequacy of actions taken to rectify and close out audit issues
•    Demonstrate the ability to evaluate, synthesise, organise and interpret data and information
•    Seek opportunities to increase the use of data analytics testing by adding new tests to the data analytics library 
•    Continuous monitoring of emerging risks and key changes to the businesses, and are factored in the risk assessment of the audit planning process

Self-Development:
•    Keeps abreast of new information and developments in the industry or best practices in auditing (e.g., by reading, liaising with organization and business core group contacts, or by attending learning and training events)

Relationship Management:
•    Routinely engages and meets business stakeholders as part of GwIA continuous monitoring activities
•    To promote GwIA and the service it provides by building strong and effective working relationships with senior management, other staff and external auditors

Reporting and Management Information
•    At the request of the GwIA Management, assist in the preparation of internal audit reports and papers for Board and Management committee reporting, on the status of the audit plan, audit results and issues status

Core Competences Required:

  • Serve as the technical advisor for the assigned audit engagements
  • Demonstrate the ability to listen, understand and respond effectively. Willing to engage in constructive conversation with others
  • Work co-operatively within diverse teams, work groups and collaborate with other departments across the organization to achieve group and organizational goals
  • Display self-confidence when taking on responsibilities and dealing with key stakeholders
  • Facilitate teamwork by contributing to team effort, sharing responsibility for team results, and exhibiting a positive attitude
  • Accept ownership and responsibility, including taking on additional responsibilities to help the team’s objectives

Education and Experience:

  • Post Qualification - at least 3 years relevant experience in 2nd or 3rd line (will consider 1st line on a case to case basis)
  • In addition to a technology degree, is CISA certified and / or has other relevant technical certification around Cybersecurity, Cloud, Software Engineering, Technology Risk Management or Project Management.
  • Preferred industry (in order of priority)

    Financial services (Banking, Insurance etc.)

    Consultancy (e.g. Big-4, Accenture etc.) – Technical Advisory, Internal audit services

    Tech Companies (Digital Fintech, Digital Banks etc.)

  • Experience in auditing controls, security, and management in at least four or more of the following areas:
    • IT infrastructure management (e.g. network, platforms such as IBM, Unix, Windows, middleware, and databases)
    • IT operations (e.g. data centre management, backup, batch processing, incident, and problem management)
    • Application and interface security
    • Transformation
    • Software development lifecycle (SDLC) and Project management
    • Third party risk management
    • IT governance and technology risk management
    • Identity and access management (including familiarity with tools such as SailPoint and CyberArk)
    • Cybersecurity (e.g. NIST framework, security tools, security operations)
    • Resilience (Business Continuity and Disaster Recovery)
    • Data Privacy
  • Added advantage if candidates have experience in auditing and risk assessing controls, security, and management in at least one or more of the following areas:
    • Cloud (PaaS, IaaS, and SaaS)
    • DevOps and DevSecOps (including containerization, orchestration, and CI/CD pipeline)
  • Artificial intelligence
  • Data governance
  • API management
  • Robotics process automation
  • Mobile device management
  • Mobile application development
  • Familiar with emerging technologies and associated risks (e.g. artificial intelligence, blockchain, internet of things, robotics)
  • Coding background / data analytics capability (familiar with tools such as Python, SQL) an advantage
  • Known as an SME in own functional area and is often sought after for advice / consultation
  • An awareness of current and emerging industry risks within financial services and a clear appreciation of the regulatory environments within the industry
  • Apart from business-as-usual audit work, have track records of delivering impactful initiatives / products which have helped elevate the function (e.g. helped automate a certain manual process / delivered an automated dashboard for more efficient risk identification etc.) will be advantageous
  • Good understanding of the local regulations
  • Possesses good verbal and written communication skills
  • Demonstrable experience of influencing and challenging senior management and building excellent relationships
  • Track record of producing value-adding, commercially realistic recommendations in risk, consultancy or internal audit environment
  • Leading edge risk management knowledge and expertise
  • Relevant industry experience
  • High attention to detail and rigorous thinking ability
  • Good Team player, who can gain the professional respect of the team

 

Prudential is an equal opportunity employer. We provide equality of opportunity of benefits for all who apply and who perform work for our organisation irrespective of sex, race, age, ethnic origin, educational, social and cultural background, marital status, pregnancy and maternity, religion or belief, disability or part-time / fixed-term work, or any other status protected by applicable law. We encourage the same standards from our recruitment and third-party suppliers taking into account the context of grade, job and location. We also allow for reasonable adjustments to support people with individual physical or mental health requirements.

Skills Required

  • At least 3 years of relevant post-qualification experience in second- or third-line functions; first-line experience may be considered case by case.
  • Technology degree.
  • CISA certification and/or another relevant technical certification in cybersecurity, cloud, software engineering, technology risk management, or project management.
  • Experience in financial services, consultancy, or technology companies, preferably in the listed priority order.
  • Experience auditing controls, security, and management in at least four specified areas, including IT infrastructure, IT operations, application and interface security, transformation, SDLC, third-party risk, IT governance, identity and access management, cybersecurity, resilience, or data privacy.
  • Awareness of current and emerging industry risks and regulatory environments within financial services.
  • Good understanding of local regulations.
  • Strong verbal and written communication skills.
  • Experience influencing and challenging senior management and building strong stakeholder relationships.
  • Track record of producing commercially realistic, value-adding recommendations in risk, consultancy, or internal audit.
  • Leading-edge risk management knowledge and expertise.
  • High attention to detail and rigorous thinking ability.
  • Ability to work collaboratively in diverse teams and gain professional respect.
  • Experience auditing and risk assessing cloud, DevOps, DevSecOps, artificial intelligence, data governance, API management, robotics process automation, mobile device management, mobile application development, or other emerging technologies.
  • Coding or data analytics capability using Python and SQL.
  • Track record of delivering initiatives or products that improve audit or risk functions through automation or dashboards.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: London
52,292 Employees

What We Do

In Asia and Africa, Prudential has been providing familiar, trusted financial security to people for 100 years. Today, headquartered in Hong Kong and London, we are ranked top three in 12 Asian markets with 18 million customers, around 68,000 average monthly active agents and access to over 27,000 bank branches in the region. Prudential is focused on opportunities in the most exciting growth markets in Asia and Africa. With access to over 4 billion people in both these regions, we are investing in broadening our presence and building our leadership in the life and asset management markets. We are committed to making a positive impact on our customers, our employees and our communities by delivering the best savings, health and protection solutions to people so they can get the most out of life. Visit our websites for more information Prudential plc: https://www.prudentialplc.com/ Prudence Foundation: https://www.prudentialplc.com/en/prudence-foundation

Similar Jobs

Pfizer Logo Pfizer

Brand Manager

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office
Kuala Lumpur, Wilayah Persekutuan Kuala Lumpur, MYS
121990 Employees

Pfizer Logo Pfizer

Health Representative - Vaccine (GP -Central)

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office
Kuala Lumpur, Wilayah Persekutuan Kuala Lumpur, MYS
121990 Employees

Capco Logo Capco

Accounting Manager

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Hybrid
Kuala Lumpur, Wilayah Persekutuan Kuala Lumpur, MYS
6000 Employees

JPMorganChase Logo JPMorganChase

Data Analyst

Financial Services
Hybrid
Kuala Lumpur, Wilayah Persekutuan Kuala Lumpur, MYS
289097 Employees

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account