Skip to main content

Get Matched To Jobs You Qualify For, Automatically!

T

Senior Internal Audit Manager: IT Audit (3025) at The South African National Roads Agency (SANRAL)

The South African National Roads Agency (SANRAL)
August 27, 2026
Full-time
On-site
MINIMUM REQUIREMENTS:


BCom Honours (Information Systems) / Bsc Honours (IT) Or Equivalent Qualification (NQF8).
Must hold a CISA certification.
Must have a valid Membership with ISACA.
A Minimum of 10 years public sector experience; 8 years IT audit experience of which 5 must be at managerial level; 5 years previous experience auditing public sector (PFMA) entity.
Exposure to COBIT/ Prince 2/ cybersecurity or ITIL


ADVANTAGEOUS:



CISM, CISSP, CA(SA) / CIA / RGA certification will be an added advantaged.



TECHNICAL COMPETENCIES:


Assurance - Provide assurance over IT governance, systems audits and security controls audits etc.
Combined assurance - Drive combined assurance on IT assurance with AGSA.
Consulting services - Engage in advisory and IT consulting services as required.
Proactive reviews - Involvement in proactive assurance reviews.
Planning, budgeting, forecasting/ Business development/ IFC audit etc.
Critical review - Critical review of projects and return on investments (ROI) analyses
Maintenance of Internal audit methodology
Special audits


KEY RESPONSIBILITIES:

Strategic Functions


Provide input in development of strategic plan for the unit
Oversee development of operational plan in assigned portfolio, delivery of outputs including staff and stakeholder management
Direct the identification, evaluation and monitoring of the risk areas and assist with the development of the Internal Audit Methodology and the Annual Risk Based Audit Plan and the three-year rolling plan.
Lead the IT audit function in playing a strategic role in providing value-add audit insights, meaningful stakeholder partnerships and embedding the principles of good governance.
Environmental scanning and monitoring of macro and micro risks that impact IA unit and delegated functions
Provide value added assurance and consulting activities that offer proactive as opposed to detective assurance.
Partner more closely with key internal and external stakeholders to ensure optimal combined assurance to the Board and Management and make certain that key risks are appropriately addressed and best practices are recommended and implemented.
Stay updated on emerging technologies and IT risks, challenge existing processes, and implement best practices to improve audit effectiveness
Participate and lead key IT related steerco to enhance advocacy and good governance in assigned areas.


Audit Planning


Develop and execute annual IT audit plan including IT general controls, cybersecurity, data governance, compliance audits etc. including advisory assignments
Assess risks, define audit scopes, design audit programs, and perform fieldwork, including evidence collection.
Analyse IT risks, evaluate the adequacy and effectiveness of controls, to provide assurance IT systems maintain data integrity, confidentiality, and availability.
Lead the review and assessment of systems of control, compliance, risk management and governance to determine if the organization has adequate standards/processes in place to achieve organizational objectives.
Supervise the performance of audits from identification and planning of projects to issuing and presenting of final reports to executive management and those charged with governance in accordance with The International Standards for the Professional Practice of Internal Auditing and best practice frameworks.
Participate in the development of the annual audit plan in consultation with Management, Risk Management and the Auditor General for review and approval.
Conduct risk and control assessment of assigned department or functional area in established/required timeline for the development of the audit plan and the basis for planning audit projects.
Perform ongoing environmental scanning for emerging risks and keep abreast with all relevant legislative changes, standard operating procedures, methodology and guidelines.


Audit Execution


Design and execute assurance and advisory engagements
Oversee recommendations around key business processes e.g. consolidation of infrastructure assets and technologies (particularly ex-GFIP/etoll assets) into National data center to streamline operations and improve efficiencies
Ensure IT and related risks are adequately covered and responded to
Drive implementation of combined assurance framework and increased reliance by AGSA on internal audit work
Execute proactive assurance reviews as mandated by management and board
Ensure that all assigned audits are executed as per the audit plan and agreed timelines
Develop risk-based audit programmes and evaluate the suitability of internal control design and make recommendations on findings.
Manage audits to ensure that they are conducted in line with applicable standards and within the time budgets and timelines determined as per the audit plan.
Suggest and perform consulting and advisory engagements to add value to the organization.


Audit project quality


Ensure that policies, procedures and guidelines, which impact on functional areas are in place, cascaded and are clearly understood, while determining the level of internal compliance (in terms of Quality Assurance standards (IIA) in line with Internal Audit methodology.
Maintain and provide recommendations to improve standard operation procedures for internal auditing.
Training and capacity building of audit team members.


Audit and management reporting


Validate the accuracy of findings and decide on severity of weaknesses • Recommend solutions for improvement of processes and controls.
Draft audit findings for improvements in the economy, efficiency, and effectiveness of controls, risk and governance of audit areas.
Coordinate activities and involvement with various internal stakeholders to finalise audit reports.
Provide feedback reports on status of projects highlighting significant weaknesses and suggested improvements.
Compile reports to management committees and the audit committee.


Project and Financial management


Responsible for managing allocated budget and assisting the Chief Audit Executive with internal audit budget and financial management of the internal audit function
Review and assess the effectiveness of financial controls within allocated centre and Internal Audit function.

Get Matched To Jobs You Qualify For, Automatically!