Never pay for any notarisation, certificate or assessment as part of any recruitment process. When in doubt, contact us
Kenya Red Cross is one of the many International Red Cross and Red Crescent Movement societies around the world.
The Kenya organisation was established in 1965, The Kenya Red Cross supports and runs a number of projects whilst raising awareness to the Kenyan public about the current issues or problems which may affect them.
Overall Purpose
The Systems Auditor provides independent assurance and advisory on the adequacy, effectiveness, and security of information systems, IT governance, and technology controls across the Kenya Red Cross Society (KRCS) commercial entities, including Boma Hotels, Eplus, Switch TV, and Boma International Hospitality College (BIHC). The role supports business continuity and operational efficiency by evaluating IT risks, cybersecurity, ERP controls and compliance with information systems policies and standards.
Key Responsibilities
Audit Planning & Execution
- Conduct financial, operational, compliance, investigative, IT, and systems audits in line with approved audit plans and professional standards.
- Identify operational inefficiencies, control gaps, process improvement opportunities and recommend corrective actions.
Governance, Risk & Internal Controls
- Evaluate governance, risk management, internal controls and IT controls to identify weaknesses and improvement opportunities.
- Review controls to ensure the accuracy, integrity, security and availability of organizational information.
IT & Systems Audit
- Review IT governance, cybersecurity, information security, business continuity, disaster recovery and change management controls.
- Review ERP systems, application controls, user access, system configurations and automated controls.
- Review IT projects, system implementations, upgrades, and integrations to ensure adequate controls are in place.
- Use data analytics and CAATs to identify anomalies, control weaknesses, fraud risks, and unusual transactions.
Compliance & Investigations
- Assess compliance with policies, laws, regulations, contractual obligations, ICT requirements, software licensing, and data protection standards.
- Conduct fraud and investigative audits and report suspected irregularities or policy violations.
Reporting, Follow-Up & Advisory
- Prepare audit reports, communicate findings and follow up on implementation of agreed recommendations.
- Advise management on internal controls, risk management, cybersecurity, IT governance and emerging technology risks.
Person Specifications
Academic Qualifications
- Bachelor's Degree in Information Technology, Computer Science, Information Systems, Computer Engineering or a related field.
Professional Qualifications
- CISA (Certified Information Systems Auditor) is required.
- Relevant certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor/Implementer, or CPA(K) will be an added advantage.
- Membership in ISACA or another relevant professional body.
Experience
- Minimum of four (4) years' experience in IT audit
- Experience auditing ERP systems and business applications such as Sun Systems, Navision, Opera, Microsoft Dynamics or similar platforms.
- Experience with data analytics, IT general controls (ITGCs), application controls and systems implementation reviews.
Competencies, Skills and Knowledge
- Strong knowledge of IT auditing standards, COBIT, ISO 27001, IT General Controls (ITGCs), cybersecurity and risk management.
- Proficiency in audit data analytics and CAATs (e.g., ACL, IDEA, Power BI, SQL, Excel).
- Knowledge of cloud computing, network security, databases, ERP systems and data privacy regulations.
- Strong analytical, report writing, and problem-solving skills.
- Excellent communication and stakeholder management skills.
- High integrity, professionalism, and ability to maintain confidentiality.
- Ability to manage multiple assignments and work collaboratively across diverse business units.
Compliance and Risk Management
- Ensure adherence to financial policies, procedures and internal controls.
- Support implementation of audit recommendations.
- Monitor compliance with donor and statutory requirements.
- Support periodic asset verification exercises.
- Identify and report financial and operational risks.