A leading institution in the Higher Education sector in the UAE is seeking a senior, technically exceptional IT Auditor and Data Analyst to execute risk-based IT audit engagements across high-risk systems, processes, and technology areas — reporting to the Director of Internal Audit. This demanding role requires CISA certification (mandatory), a minimum of 8 years of progressive IT audit, risk, and compliance experience with at least 3 years of hands-on data analytics in an audit or risk context, and deep proficiency in ITGC, ERP application controls (Oracle, SAP, Banner), ISO 27001, ISACA frameworks, Power BI, SQL, and advanced Excel — with preferred exposure to Python or R for data extraction and continuous auditing methodologies.
About This IT Auditor & Data Analyst Opportunity — UAE Higher Education
Sector: Higher Education — UAE — a uniquely complex IT audit environment combining academic ERP systems, student data privacy obligations, cybersecurity risks, and regulatory compliance requirements
Function: Internal Audit — reporting directly to the Director of Internal Audit — executing risk-based IT audit engagements across the approved Internal Audit Plan
Data Analytics Mandate: Design and execute data analytics procedures, build dashboards and automated scripts, and support continuous auditing and monitoring mechanisms as a core part of the role
Scope: ITGC, application controls, ERP (Oracle, SAP, Banner), logical access, privileged access management, change management, SDLC, and IT operations
Why This IT Auditor & Data Analyst Role Stands Out
CISA + Data Analytics Combination: A rare senior IT audit role that genuinely combines deep CISA-level IT audit expertise with advanced data analytics capability — Power BI, SQL, and Python — in a structured internal audit function
Full IT Audit Lifecycle Authority: Risk-based engagement design, ITGC testing, ERP application controls, access management reviews, anomaly detection, fraud risk indicators, and continuous monitoring — comprehensive scope
Higher Education Sector Complexity: Apply IT audit expertise across a uniquely diverse technology environment — Banner ERP, Oracle or SAP, academic information systems, cybersecurity, and ISO 27001 compliance
Emerging Technology Focus: Stay current with evolving cybersecurity risks, technology audit practices, and continuous auditing techniques — in a forward-thinking UAE higher education institution
Position Overview
This IT Auditor and Data Analyst in the UAE executes risk-based IT audit engagements in accordance with the approved Internal Audit Plan, performs assessments of IT General Controls, logical access, privileged access management, change management, SDLC, and IT operations, conducts walkthroughs, control design assessments, and operating effectiveness testing, assesses compliance with ISACA guidelines, ISO 27001, and applicable regulatory requirements, evaluates ERP application controls within Oracle, SAP, or Banner environments, prepares draft audit findings and management action plans for the Director of Internal Audit, designs and executes data analytics procedures using Power BI, SQL, and advanced Excel, applies exception reporting, anomaly detection, segregation of duties analysis, and fraud risk indicators, and develops dashboards, automated scripts, and continuous auditing mechanisms to improve audit efficiency and coverage across the UAE higher education institution’s technology environment.
Why This Role Matters: As IT Auditor and Data Analyst at a UAE higher education institution, you provide the independent, evidence-based assurance that the systems holding thousands of students’ academic records, financial data, research outputs, and personal information are governed, controlled, and protected as they should be. When your ITGC assessment identifies a privileged access control gap that could enable unauthorised data modification, your SQL-based anomaly detection flags a segregation of duties violation in the student finance ERP module, or your ISO 27001 compliance review reveals a change management process operating outside its defined controls — you are not producing an internal audit report. You are protecting institutional integrity, regulatory compliance, and the trust that students, faculty, and the academic community place in the institution’s technology governance.
Key Responsibilities
Risk-Based IT Audit Execution & ITGC Assessment
- Execute risk-based IT audit engagements in accordance with the approved Internal Audit Plan — ensuring adequate coverage of assigned high-risk systems, processes, and technology areas within the UAE higher education institution
- Perform assessments of IT General Controls (ITGCs) — including logical access controls, privileged access management, change management processes, SDLC, and IT operations — as directed by the Director of Internal Audit
- Conduct walkthroughs, control design assessments, and operating effectiveness testing — preparing comprehensive audit documentation and working papers in accordance with professional auditing standards and ISACA methodology
- Assess compliance with recognised frameworks and standards including ISACA guidelines, ISO 27001, and applicable regulatory requirements — documenting findings clearly, objectively, and with appropriate supporting evidence
ERP Application Controls & Audit Findings Preparation
- Evaluate ERP application controls within Oracle, SAP, or Banner environments — identifying control gaps, segregation of duties violations, access provisioning weaknesses, and configuration vulnerabilities relevant to the institution’s financial and academic processes
- Prepare draft audit findings, reports, and management action plans for review by the Director of Internal Audit — ensuring findings are accurate, well-evidenced, clearly communicated, and commercially actionable
- Contribute to the development and standardisation of IT audit programs, working papers, and methodology documentation — supporting audit quality, consistency, and professional standards compliance
- Participate in IT risk assessment activities and assist in maintaining the IT risk universe and audit universe — keeping the institution’s technology risk profile current and accurately prioritised
Data Analytics, Dashboard Design & Continuous Auditing
- Design and execute data analytics procedures across financial and non-financial datasets — using Power BI, SQL, and advanced Excel to enhance audit coverage, support risk identification, and strengthen audit conclusions
- Apply analytics techniques including exception reporting, anomaly detection, segregation of duties analysis, and fraud risk indicators — across ERP, financial, and operational datasets in assigned audit engagements
- Develop dashboards, automated scripts, and data visualisation outputs — improving audit efficiency, reporting accuracy, and the institution’s visibility into ongoing control performance
- Support the implementation and maintenance of continuous auditing and monitoring mechanisms — reducing reliance on point-in-time audit testing through ongoing automated analytics coverage
Special Reviews, Investigations & Stakeholder Coordination
- Assist in special reviews, investigations, and data-driven assignments as directed — applying structured analytical approaches, professional scepticism, and strict objectivity throughout
- Coordinate with auditee staff to schedule walkthroughs, gather evidence, and follow up on outstanding audit requests — in a timely, professional, and constructive manner that builds audit relationships without compromising independence
- Keep current with emerging technology risks, cybersecurity developments, and evolving IT audit practices — particularly as they relate to the higher education technology sector in the UAE and GCC
Qualifications, Knowledge & Skills
Essential Requirements
- Bachelor’s Degree in Information Technology, Computer Science, Finance, or a related field — Master’s Degree preferred
- CISA certification — mandatory; ISO 27001 Internal or Lead Auditor certification preferred; CIA advantageous
- Minimum 8 years of progressive experience in IT audit, risk, and compliance — including minimum 3 years hands-on data analytics within an audit or risk context
- Demonstrated experience executing IT General Controls audits, application controls reviews, and ERP audit assignments within Oracle, SAP, Banner, or equivalent environments
- Strong knowledge of ISACA frameworks, ISO 27001, and risk-based internal audit methodology
- Proficiency in data analytics tools — advanced Excel and Power BI; working knowledge of SQL or equivalent querying tools
- Strong documentation and report writing skills — with attention to detail, clarity of expression, and ability to communicate complex findings to senior management
- Professional scepticism, analytical thinking, and the ability to identify and articulate control weaknesses clearly and objectively
Preferred Skills
- Exposure to fraud risk assessment methodologies and forensic data analysis techniques
- Experience with scripting tools such as Python or R — for data extraction, transformation, and analytics within audit assignments
- Knowledge of continuous auditing and monitoring tools, practices, and implementation approaches
- Higher education sector IT audit experience — familiarity with academic ERP systems, student data privacy regulations, and the unique governance challenges of UAE university environments
About This Role — IT Audit Excellence in UAE Higher Education
This IT Auditor and Data Analyst position at a UAE higher education institution offers CISA-certified professionals the opportunity to apply senior-level IT audit expertise — ITGC, ERP application controls, ISO 27001, access management, change management, and SDLC — within one of the most technically diverse and governance-complex institutional environments in the UAE. With a genuine data analytics mandate — Power BI, SQL, advanced Excel, and preferred Python or R capability — this role goes beyond traditional point-in-time IT audit to build the continuous monitoring infrastructure that gives the institution’s leadership real-time assurance over its most critical technology controls. Reporting directly to the Director of Internal Audit, the successful candidate provides the independent, evidence-based technology governance assurance that UAE higher education institutions increasingly depend on to protect students, data, and institutional integrity.
Career Excellence: Execute CISA-level IT audit and data analytics — ITGC, Oracle SAP Banner, ISO 27001, Power BI, SQL — at a UAE higher education institution.
Who Should Apply?
- CISA-Certified IT Auditors — ERP & ITGC: With 8+ years of IT audit experience and demonstrated Oracle, SAP, or Banner ERP application controls and ITGC audit execution capability
- IT Audit Analytics Specialists — Power BI & SQL: Who combine CISA-level IT audit rigour with Power BI dashboard development, SQL querying, and data analytics for anomaly detection and continuous audit coverage
- ISO 27001 & ISACA Framework Auditors: With ISO 27001 internal or lead auditor certification and ISACA framework proficiency — delivering information security compliance assessments within complex institutional technology environments
- Internal Audit Data Analytics Professionals: With 3+ years of hands-on data analytics in an IT audit or risk context — building automated scripts, exception reports, segregation of duties analyses, and fraud risk indicator dashboards
- UAE Higher Education Sector IT Auditors: With experience or genuine interest in applying risk-based IT audit methodology to the unique governance challenges of UAE university and academic institution technology environments
Recently Opening job👇



