Jobs Career Advice Post Job
X

Send this job to a friend

X

Did you notice an error or suspect this job is scam? Tell us.

  • Posted: Aug 24, 2026
    Deadline: Aug 28, 2026
    • @gmail.com
    • @yahoo.com
    • @outlook.com
  • Never pay for any notarisation, certificate or assessment as part of any recruitment process. When in doubt, contact us

    CIC Insurance Group Limited, commonly referred to as CIC Group, is an insurance and investment group that operates mainly in Kenya, Uganda, South Sudan and Malawi
    Read more about this company

     

    Internal Auditor – ICT

    About the Role

    Reporting to the Director Internal Audit, the role holder will provide independent and objective assurance and advisory services that strengthen governance, risk management and internal controls across assigned business units. The role supports delivery of the Internal Audit Strategy through risk-based auditing, data-driven assurance, continuous monitoring and practical recommendations that improve business performance and control effectiveness.

    Key Responsibilities

    • Execute end-to-end risk-based ICT and technology audits in accordance with the approved Internal Audit Plan, Internal Audit methodology, professional standards, regulatory requirements and the organization’s ICT risk profile.
    • Participate in enterprise and ICT risk assessments and contribute to the development of the annual Internal Audit work plan, with consideration of emerging technology risks, cybersecurity threats and changes in the organization’s technology landscape.
    • Develop audit objectives, scope, risk and control matrices, audit programmes and testing strategies for assigned ICT audit engagements.
    • Conduct ICT audits covering IT governance, cybersecurity, information security, IT general controls, application controls, IT infrastructure, networks, databases, cloud services, system development, change management, access management, IT operations, data management, business continuity and disaster recovery, as applicable.
    • Assess the design and operating effectiveness of IT General Controls (ITGCs), including logical and physical access controls, privileged access, segregation of duties, change management, backup and recovery, incident management and IT operations.
    • Review the adequacy of controls over business applications and core systems, including system configurations, application controls, interfaces, automated controls, system-generated reports and data integrity.
    • Assess the governance, implementation and effectiveness of ICT projects, system implementations, system upgrades and technology transformation initiatives, including project governance, requirements management, testing, implementation and post-implementation controls.
    • Evaluate IT service management and operational controls, including incident management, problem management, service availability, capacity management, service-level agreements and IT support processes.
    • Assess the effectiveness of business continuity and disaster recovery arrangements, including adequacy of recovery strategies, backup arrangements, recovery testing, system resilience and alignment with critical business processes.
    • Review controls over third-party and outsourced technology services, including vendor due diligence, contractual obligations, service-level agreements, information security requirements, performance monitoring, access to organizational data and exit arrangements.
    • Develop data-driven audit tests to identify unauthorized access, unusual user activity, segregation-of-duties conflicts, dormant accounts, duplicate transactions, system overrides, control breaches, anomalies and other indicators of technology or fraud risk.
    • Use appropriate audit, data analytics and visualization tools, including advanced Excel, IDEA, Power BI, SQL and other relevant ICT audit or analytics tools, where applicable.
    • Contribute to the development and implementation of continuous auditing, continuous monitoring and automated control testing to improve audit efficiency, coverage and early identification of emerging technology risks.
    • Discuss audit observations with ICT and business process owners and management, provide practical recommendations and support timely resolution of identified technology and control weaknesses.
    • Follow up on agreed management actions and validate the implementation and effectiveness of corrective measures relating to ICT audit findings.
    • Support the preparation of Audit Committee and Board papers relating to ICT audits, cybersecurity, technology risk, data governance and other key technology control themes.
    • Assess the governance and control environment around emerging technologies, including Artificial Intelligence (AI), automation, cloud computing, digital platforms and other technology-enabled business solutions, where applicable.
    • Contribute to the continuous improvement of Internal Audit methodologies, ICT audit tools, data analytics, automation, continuous monitoring, knowledge resources and quality assurance practices.

    Audit Quality, Professional Standards and Independence

    • Perform audit work in accordance with the Internal Audit Charter, approved methodology, policies and applicable professional standards.
    • Ensure audit assignments are completed to required quality standards and within agreed timelines.
    • Maintain complete, accurate and well-organized audit documentation to support review and quality assurance.

    Stakeholder Engagement

    • Build effective working relationships with business and functional management while maintaining appropriate audit independence.
    • Communicate audit issues clearly and constructively to process owners and senior management.

    Who We’re Looking For

    Essential Knowledge/Skills and Experience Required:

    • Bachelor’s degree in a business-related field.
    • CISA
    • CPA/ACCA / CIA/ Computer Assisted Audit Techniques is desirable
    • Insurance Professional Qualification is desirable
    • 3-5 years’ experience. At least 2 years’ experience in the big 4 audit firms or an organization similar in size or larger than CIC Group is an added advantage
    • Knowledge of current technological developments/trends in area of expertise and knowledge of software requirements for audit of systems procedures
    • Basic knowledge of regulations by AKI and IRA
    • Excellent communication skills – written, oral, presentation and report writing
    • Ability to maintain highest levels of integrity and objectivity
    • Flexibility in mobility

    Check how your CV aligns with this job

    Method of Application

    Interested and qualified? Go to CIC Insurance on careers.cicinsurancegroup.com to apply

    Build your CV for free. Download in different templates.

  • Get new Finance / Accounting / Audit jobs like this on Telegram.Subscribe on Telegram
  • Send your application

    View All Vacancies at CIC Insurance Back To Home

Career Advice

View All Career Advice
 

Subscribe to Job Alert

 

Join our happy subscribers

 
 
Send your application through

GmailGmail YahoomailYahoomail