Information Systems Auditor | external
Full Time
Purpose of the Job
The IS Auditor will identify control weaknesses, evaluate risks, and recommend practical solutions to enhance the security posture and operational efficiency of ZINARA's information systems.
Responsibilities
-
Assist in developing comprehensive audit plans and programs for information systems, applications, infrastructure, and processes
-
Identify key risks and control objectives related to IT operations
-
Coordinate with IT management and other stakeholders to understand system landscapes and business processes
-
Conduct thorough reviews of IT general controls (e.g., access management, change management, backup and recovery, patch management, incident management)
-
Assess the effectiveness of application controls (e.g., input, processing, output controls)
-
Evaluate compliance with internal policies, industry standards (e.g., ISO 27001, NIST, COBIT), and regulatory requirements e.g
-
Cyber and Data Protection Act
-
Perform data analysis and utilize audit tools to identify anomalies, trends, and control deficiencies
-
Document audit findings, working papers, and evidence clearly and concisely
-
Prepare clear, concise, and well-supported audit reports detailing findings, risks, and recommendations to the Senior IT auditor for review
-
Clearly present draft audit results to IT management and relevant stakeholders, fostering constructive dialogue
-
Assist Senior IT Auditor with tracking and follow up on the implementation of audit recommendations to ensure timely remediation
-
Contribute to the IT risk assessment process, identifying emerging threats and vulnerabilities
-
Provide advisory support on IT control design and implementation for new systems and initiatives
-
Stay abreast of industry best practices, new technologies, and regulatory changes in information security and IT auditing
-
Participate in the development and refinement of audit methodologies, tools, and processes
-
Foster a culture of continuous improvement in IT controls and security.
Qualifications
-
5 O’ Levels including English and Maths /Accounts
-
2 A’ Levels or Equivalent
-
Bachelor's degree in Information Technology, Computer Science, or a related field
-
Certified Information Systems Auditor (CISA) - Highly preferred.
Experience
-
2-3 years experience in IT audit, information security, or technology risk advisory services
-
Experience with internal controls, risk management frameworks, and compliance standards (e.g
-
NIST, COBIT, ITIL)
-
Strong understanding of information systems, networks, databases, operating systems, and cloud environments
-
Proficiency in performing risk assessments and evaluating control effectiveness
-
Excellent analytical, problem-solving, and critical thinking skills
-
Exceptional written and verbal communication skills, with the ability to articulate complex technical issues to non-technical audiences
-
Ability to work independently and as part of a team, managing multiple priorities and deadlines
-
High level of integrity and professional ethics
-
Proficiency in using audit management software and data analytics tools (e.g., ACL, Tableau, SQL) is a plus
-
Knowledge of cybersecurity frameworks and penetration testing methodologies
-
Experience with agile methodologies and auditing agile development processes
-
Familiarity with GRC (Governance, Risk, and Compliance) platforms.
Competences
None
Job Summary
July 7, 2025, midnight
Vacancy: 1
Job Nature:
Full Time
Deadline: :July 21, 2025, midnight
About Zinara
The Zimbabwe National Road Administration (ZINARA) is a corporate body that was established in terms of the Road Act (Chapter 13:18).
The body was established in 2002 in line with Government’s commitment to develop a good road network system.
The mandate of ZINARA is to fix, collect and disburse road user fees to road authorities.
Zinara is also responsible for mobilizing revenue for roads development and maintenance.
The mandate of Zinara also include monitoring the usage of funds disbursed to road authorities to ensure that they are used for their intended purpose.
Our Core Values
Equity,Integrity,Transparency and Accountability