IT Audit Executive
Closing on: Jan 6, 2027
Key responsibilities
- Plan and perform IT audits for clients, covering IT General Controls (ITGC), application controls, and system security configurations.
- Review system access controls, backup processes, and change management practices to ensure compliance and resilience.
- Support IT risk assessments and policy reviews, preparing client-specific IS audit reports with clear recommendations.
- Coordinate with external audit teams to integrate ISMS and IT audit findings into overall assurance reports.
- Maintain ISMS compliance by conducting reviews, collecting audit evidence, and ensuring alignment with ISO 27001 standards.
- Assist in internal ISMS audits, support corrective actions, and contribute to continual improvement initiatives.
Requirements
- 1-2 years of experience in ISMS, IT audit, or compliance roles.
- Degree in Information Technology, Information Systems, Cybersecurity, or related discipline.
- Familiarity with IT General Controls (ITGC), application controls.
- Good documentation, coordination, and analytical skills with the ability to produce clear audit reports.
- Proficiency in MS Excel, Word, and email communication tools.
- Knowledge of ISO 27001 controls and risk assessment methodologies will be an added advantage.
- Financial literacy and understanding of business processes will be considered a plus.
About the company
Kreston Sri Lanka is a member firm of Kreston Global UK and a correspondent firm of Grant Thornton International, one of the five most prestigious global accounting organizations of independent assurance, tax and advisory firms.
When applying
If you are the right candidate, please send your CV while mentioning the name of the job title under the subject line of the email.
Company: Kreston Sri Lanka
Company email: [email protected]
Job Location: Colombo
Job Category: Cybersecurity / Information Security
Job Type: Full Time
