The Systems Auditor will play a critical role in safeguarding Tower SACCO Society’s information systems and business processes. This position ensures risks are identified, controls are evaluated, and compliance is maintained, providing independent assurance on the integrity of the organization’s internal control environment.
JOB DESCRIPTION
Lead the information system audit function within the Internal Audit Department.
Develop and implement the annual IS audit plan in collaboration with the Head of Internal Audit.
Ensure SACCO maintains robust IS policies and procedures that minimize risk while supporting efficiency.
Support the Audit Committee with accurate reports during the monthly and quarterly board reviews.
Assess risks in SACCO’s information systems and recommend mitigation measures.
Conduct special audits and investigations as required.
Conduct system implementation review on new software and system upgrades undertaken.
Evaluate compliance with IS policies, procedures, and operating instructions.
Track and follow up on audit findings to ensure timely closure.
Review business continuity and disaster recovery plans, including backup procedures and usability.
Evaluate and report on system infrastructure, system development processes and life cycle management.
Audit network security, firewalls and user access controls to prevent data breaches.
Recommend improvements to audit procedures for enhanced efficiency.
Execute multiple audit projects, ensuring scope, timing, and regulatory compliance.
Monitor implementation of defined controls and recommendations.
Any other duty that may be assigned by the Head of Internal Audit, the CEO or any authorized officer.
PREFERRED QUALIFICATIONS
Bachelor of Science degree in Information Technology or related field or either a Bachelor’s degree in Economics, Commerce or related field
Certified Information Systems Auditor (CISA) qualification is mandatory.
Additional certifications such as Certified Information Security Manager (CISM) , Certified Information System Security Professional (CISSP), Certified in Risk & Information Systems
At least 5 years relevant experience in System Audit or Information Technology environment.
KCSE mean Grade C (plain) with C plain in Mathematics and English.