Senior Lead Auditor - IT

Date:  1 Oct 2026
Company:  Power International Holding
Location: 

QA

Job Summary

The Senior Lead Auditor - IT executes technology-focused internal audit engagements across Power International Holding and its business groups, providing independent assurance over the design and operating effectiveness of technology, cybersecurity, data protection, and system-control environments.

Reporting to the IT Audit Manager within the Group Internal Audit function, the role evaluates IT general controls, ERP application controls, SAP security and authorizations, segregation of duties, cybersecurity, access management, change management, business continuity, and data governance. The position applies risk-based audit methodologies, data analytics, and professional standards to identify control weaknesses, determine root causes, and communicate practical recommendations to technical and non-technical stakeholders.

The role works independently across technical and business-process environments while supporting audit planning, scoping, fieldwork, reporting, remediation tracking, and continuous improvement of the Group IT audit plan.

Job Responsibilities 1

IT Audit Planning & Execution

  • Execute risk-based IT audit engagements covering IT general controls, application controls, cybersecurity, access management, change management, IT operations, business continuity, disaster recovery, and related technology risks across the Group.
  • Support the IT Audit Manager in defining audit scope, objectives, testing strategies, resource requirements, and engagement timelines in alignment with the approved IT audit plan.
  • Perform fieldwork, obtain and evaluate audit evidence, document procedures and conclusions, and maintain complete workpapers in accordance with IIA IPPF and relevant ISACA standards.

ERP, SAP & Application Controls

  • Perform ERP-focused audit work covering SAP access controls, role design, authorizations, segregation of duties, master data governance, system configuration, interfaces, workflows, and key automated controls.
  • Assess business-process and application-control dependencies across SAP S/4HANA and other critical enterprise systems.
  • Evaluate SAP GRC Process Control and access-risk-management arrangements, including mitigating controls and remediation of SoD conflicts.

Risk & Control Assessment

  • Develop and execute IT-specific Risk Control Matrices, clearly distinguishing design effectiveness from operating effectiveness.
  • Assess control objectives, risks, control ownership, evidence requirements, testing frequency, sample selection, exceptions, and residual exposure.
  • Identify control gaps, recurring issues, root causes, and risk concentrations requiring management attention.

Data Analytics & Continuous Auditing

  • Extract, reconcile, and analyze data from key business systems to identify anomalies, unauthorized activity, control exceptions, and compliance breaches.
  • Use appropriate analytics tools and repeatable audit scripts to strengthen testing coverage, evidence quality, and insight generation.
  • Validate the completeness and accuracy of data used for audit testing and document analytical procedures and results.

Audit Reporting & Stakeholder Engagement

  • Draft clear, evidence-based IT audit findings and contribute to audit reports by translating technical issues into concise risk, impact, root-cause, and control language for business stakeholders.
  • Engage with IT, Information Security, data owners, system owners, and business-process owners to validate findings and agree practical corrective action plans, owners, and target dates.
  • Present audit observations professionally and respond constructively to technical challenge while maintaining independence and objectivity.

Remediation, Quality & Knowledge Development

  • Track open findings through remediation closure, assess supporting evidence, and escalate overdue or inadequately addressed actions through the established audit governance process.
  • Support quality assurance activities, methodology improvements, risk assessments, audit-universe updates, and development of reusable IT audit programs.
  • Maintain current knowledge of technology risk, cybersecurity, privacy, SAP controls, regulatory expectations, and emerging audit practices.

Job Responsibilities 2

Additional Responsibilities 3

Job Knowledge & Skills

Technology Risk & Control Knowledge: Strong understanding of IT general controls, application controls, cybersecurity, data protection, privacy, business continuity, and technology governance.

Audit Methodology & Professional Standards: Working knowledge of risk-based auditing, Risk Control Matrices, design and operating effectiveness testing, IIA IPPF, ISACA guidance, and relevant assurance practices.

Analytical Thinking & Professional Judgment: Ability to assess complex technical and business-process environments, identify root causes, evaluate risk significance, and reach evidence-based conclusions.

Stakeholder Communication & Report Writing: Strong written and verbal communication skills with the ability to translate technical findings into clear business risk and control language for non-technical audiences.

Independent Delivery & Collaboration: Ability to manage assigned engagements with limited supervision while collaborating effectively with audit colleagues, IT teams, Information Security, and business-process owners.

Job Experience

Professional Experience: Minimum 5 years of relevant experience in IT audit, information security, technology risk management, IT controls, or a closely related assurance discipline.

IT General Controls: Demonstrated hands-on experience testing access management, change management, IT operations, system development, backup, recovery, and business continuity controls.

ERP & SAP Controls: Practical experience auditing ERP application controls, SAP security and authorizations, segregation of duties, master data, workflows, and configurable controls, preferably within SAP S/4HANA.

SAP Functional Background: SAP Functional Analysts with expert SAP configuration and business-process knowledge who are prepared to specialize in SAP IT audit and control testing may be considered.

Audit Delivery: Experience independently planning and executing fieldwork, maintaining audit workpapers, drafting findings, and validating management remediation.

Competencies

Agility
AI Fluency
Build High-Performing Teams
Business Understanding & process analysis L3
Data analysis L3_1141677111
Financial Analysis tools and techniques L3
Governance, IA and control tools and techniques L3
Leadership_321977503
Provide Direction
Quality_321977507
Resilience
Risk analysis & control assessment techniques L3

Education

Bachelor's Degree in Information Technology
Professional Qualification in any related field or Certified Internal Auditor (CIA)