Job description
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.
As a global leader in assurance, tax, transaction and advisory services, we hire and develop the most passionate people in their field to help build a better working world. This starts with a culture that believes in giving you the training, opportunities, and creative freedom to make things better. This is what makes us different, and renders working here a unique, lifetime experience.
EY Ford Rhodes Chartered Accountants is a member firm of Ernst & Young Global Limited (EYGL) providing Assurance, Tax, Consulting and Strategy & Transaction Advisory services to our clients, both global and local, operating out of or seeking advice on doing business in Pakistan. With its Principal Office in Karachi and branches in Lahore and Islamabad, EY Ford Rhodes has been operating in Pakistan since 1948.
The Opportunity: your next adventure awaits!
The rapid evolution of technology and the risks related to this now regularly make headline news. The potential impact from threats ranging from external attacks to internal rogue trading makes the need for IT assurance an item of Board level concern. As a Senior Consultant, Technology Risk you’ll be helping our clients gain the comfort they and their regulators require. That will mean using your technical knowledge of IT risks and controls and your client facing experience to work with our Managers and Senior Managers to provide clients with the assurance or advice they need. Working with prestigious organizations you will be an integral part of our Technology Risk (TR) Team.
With our support you’ll have the opportunity to work on a range of IT Assurance projects, including IT External Audit Support, IT Internal Audit, Service Organization Controls Reporting, IT Risk Assessment, Development of BCP & DRP and Cyber Security Maturity Assessment etc. There is also the potential to work on Advisory engagements supporting clients in designing or assessing effectiveness of their IT risk and IT control mechanisms. We’re currently growing our TR team to help meet increasing market demand. Our projects typically involve managing multiple stakeholders and require you to give the best advice to our clients using your knowledge and experience to provide the best outcomes.
Key responsibilities:
You will manage your time between working on client site and in our offices, as a member of our highly skilled engagement teams. You will work with a number of high-profile clients undertaking various engagements focused on strengthening processes and controls around big issues relating to technology and data risks. The range of projects with which TR is involved means that there is a dynamic team environment providing you with a wealth of opportunities for personal growth and development.
Following would be your key responsibilities:
- Assist in the development of detailed audit plans and programs based on a risk-based approach.
- Perform specific audit procedures and prepare work-papers documenting the audit procedures performed.
- Analyze data obtained for evidence of deficiencies in controls or lack of compliance with laws, government regulations, and management policies or procedures.
- Prepare audit work programs and computer extracts necessary to fulfill the audit objectives.
- Prepare reports of findings and recommendations. Makes recommendations regarding improving operations and controls efficiency.
- Be effective in communication of audit results, both verbally and in writing, to ensure they are persuasive, placed in the appropriate context, and understood by the recipient.
- Complete work assignment independently or as a part of the team.
To qualify for the role, you must have:
- ACCA qualification, or bachelor’s or master’s degree in IT/CS/Communication or in relevant discipline.
- A minimum of 3-4 years of experience working as an IT/IS Auditor or IT Risk Consulting.
- Experience working for a professional services consultancy firm in IT external audit, IT internal audit, third- party reporting (e.g. SOC1, SOC2), IT/IS Policies & Procedures, or IT risk management is highly preferred.
- Sound technical knowledge of information technology (primarily telecommunication and financial institutions industry) to perform audits in SDLC, Change Management, Access Controls, IT Operations, Network Domain, etc.
- Good Understanding and Experience in technology landscape with diverse industry experiences
- Understanding of PK regulatory requirements for IT and Cyber Security.
- CISA, CISM, ISO 27001, certification is desired; non-certified hires are required to become certified to be eligible for progression.
Skills and attributes for success
- Bring your experience in applying relevant IT technical knowledge in at least one of the following engagements: (a) financial statement audits; (b) internal or operational audits; (c) Service Organization Controls (SOC) Reporting engagements; and/or (d) ERP Security and Control reviews (Oracle, SAP and Peoplesoft).
- Development of Technology and Information Security Policies and Procedures in line with the leading Standards and Frameworks.
- Managing client relationships and expectations
- Building relationships with colleagues across the business, supporting them and promoting a collaborative culture
- Ability to multitask and plan effectively.
What we offer:
- You will join a young, international, dynamic team, genuinely passionate about its work, within a leading global professional services firm;
- We offer extensive training, both on technical matters, as well as on soft skills and project management;
- We are proud of our flexible working arrangements, and we will support you to build a successful career without sacrificing your personal priorities;
- At EY we are passionate about the inclusion and support of individuals of all groups; we do not discriminate on the basis of race, religion, gender, sexual orientation, or disability status.
If you can demonstrate that you meet the criteria above, please contact us as soon as possible.
At EY, the spotlight is on our people. You are empowered to build your expertise and explore the world so that you can innovate and challenge the status quo. Because building a better working world begins here.
This is what makes us different, and renders working here a unique, lifetime experience.
For further information, and to apply, please visit our website via the “Apply” button below.