Internal Auditor – ICT job at CIC Insurance
New
Today
Linkedid Twitter Share on facebook
Internal Auditor – ICT
2026-08-24T09:17:45+00:00
CIC Insurance
https://cdn.greatkenyanjobs.com/jsjobsdata/data/employer/comp_7945/logo/CIC-Insurance.jpg
FULL_TIME
Nairobi
Nairobi
00100
Kenya
Insurance
Accounting & Finance, Computer & IT, Business Operations
KES
MONTH
2026-08-28T17:00:00+00:00
8

About the Role

Reporting to the Director Internal Audit, the role holder will provide independent and objective assurance and advisory services that strengthen governance, risk management and internal controls across assigned business units. The role supports delivery of the Internal Audit Strategy through risk-based auditing, data-driven assurance, continuous monitoring and practical recommendations that improve business performance and control effectiveness.

Key Responsibilities

  • Execute end-to-end risk-based ICT and technology audits in accordance with the approved Internal Audit Plan, Internal Audit methodology, professional standards, regulatory requirements and the organization’s ICT risk profile.
  • Participate in enterprise and ICT risk assessments and contribute to the development of the annual Internal Audit work plan, with consideration of emerging technology risks, cybersecurity threats and changes in the organization’s technology landscape.
  • Develop audit objectives, scope, risk and control matrices, audit programmes and testing strategies for assigned ICT audit engagements.
  • Conduct ICT audits covering IT governance, cybersecurity, information security, IT general controls, application controls, IT infrastructure, networks, databases, cloud services, system development, change management, access management, IT operations, data management, business continuity and disaster recovery, as applicable.
  • Assess the design and operating effectiveness of IT General Controls (ITGCs), including logical and physical access controls, privileged access, segregation of duties, change management, backup and recovery, incident management and IT operations.
  • Review the adequacy of controls over business applications and core systems, including system configurations, application controls, interfaces, automated controls, system-generated reports and data integrity.
  • Assess the governance, implementation and effectiveness of ICT projects, system implementations, system upgrades and technology transformation initiatives, including project governance, requirements management, testing, implementation and post-implementation controls.
  • Evaluate IT service management and operational controls, including incident management, problem management, service availability, capacity management, service-level agreements and IT support processes.
  • Assess the effectiveness of business continuity and disaster recovery arrangements, including adequacy of recovery strategies, backup arrangements, recovery testing, system resilience and alignment with critical business processes.
  • Review controls over third-party and outsourced technology services, including vendor due diligence, contractual obligations, service-level agreements, information security requirements, performance monitoring, access to organizational data and exit arrangements.
  • Develop data-driven audit tests to identify unauthorized access, unusual user activity, segregation-of-duties conflicts, dormant accounts, duplicate transactions, system overrides, control breaches, anomalies and other indicators of technology or fraud risk.
  • Use appropriate audit, data analytics and visualization tools, including advanced Excel, IDEA, Power BI, SQL and other relevant ICT audit or analytics tools, where applicable.
  • Contribute to the development and implementation of continuous auditing, continuous monitoring and automated control testing to improve audit efficiency, coverage and early identification of emerging technology risks.
  • Discuss audit observations with ICT and business process owners and management, provide practical recommendations and support timely resolution of identified technology and control weaknesses.
  • Follow up on agreed management actions and validate the implementation and effectiveness of corrective measures relating to ICT audit findings.
  • Support the preparation of Audit Committee and Board papers relating to ICT audits, cybersecurity, technology risk, data governance and other key technology control themes.
  • Assess the governance and control environment around emerging technologies, including Artificial Intelligence (AI), automation, cloud computing, digital platforms and other technology-enabled business solutions, where applicable.
  • Contribute to the continuous improvement of Internal Audit methodologies, ICT audit tools, data analytics, automation, continuous monitoring, knowledge resources and quality assurance practices.

Audit Quality, Professional Standards and Independence

  • Perform audit work in accordance with the Internal Audit Charter, approved methodology, policies and applicable professional standards.
  • Ensure audit assignments are completed to required quality standards and within agreed timelines.
  • Maintain complete, accurate and well-organized audit documentation to support review and quality assurance.

Stakeholder Engagement

  • Build effective working relationships with business and functional management while maintaining appropriate audit independence.
  • Communicate audit issues clearly and constructively to process owners and senior management.

Who We’re Looking For

Essential Knowledge/Skills and Experience Required:

  • Bachelor’s degree in a business-related field.
  • CISA
  • CPA/ACCA / CIA/ Computer Assisted Audit Techniques is desirable
  • Insurance Professional Qualification is desirable
  • 3-5 years’ experience. At least 2 years’ experience in the big 4 audit firms or an organization similar in size or larger than CIC Group is an added advantage
  • Knowledge of current technological developments/trends in area of expertise and knowledge of software requirements for audit of systems procedures
  • Basic knowledge of regulations by AKI and IRA
  • Excellent communication skills – written, oral, presentation and report writing
  • Ability to maintain highest levels of integrity and objectivity
  • Flexibility in mobility
  • Execute end-to-end risk-based ICT and technology audits in accordance with the approved Internal Audit Plan, Internal Audit methodology, professional standards, regulatory requirements and the organization’s ICT risk profile.
  • Participate in enterprise and ICT risk assessments and contribute to the development of the annual Internal Audit work plan, with consideration of emerging technology risks, cybersecurity threats and changes in the organization’s technology landscape.
  • Develop audit objectives, scope, risk and control matrices, audit programmes and testing strategies for assigned ICT audit engagements.
  • Conduct ICT audits covering IT governance, cybersecurity, information security, IT general controls, application controls, IT infrastructure, networks, databases, cloud services, system development, change management, access management, IT operations, data management, business continuity and disaster recovery, as applicable.
  • Assess the design and operating effectiveness of IT General Controls (ITGCs), including logical and physical access controls, privileged access, segregation of duties, change management, backup and recovery, incident management and IT operations.
  • Review the adequacy of controls over business applications and core systems, including system configurations, application controls, interfaces, automated controls, system-generated reports and data integrity.
  • Assess the governance, implementation and effectiveness of ICT projects, system implementations, system upgrades and technology transformation initiatives, including project governance, requirements management, testing, implementation and post-implementation controls.
  • Evaluate IT service management and operational controls, including incident management, problem management, service availability, capacity management, service-level agreements and IT support processes.
  • Assess the effectiveness of business continuity and disaster recovery arrangements, including adequacy of recovery strategies, backup arrangements, recovery testing, system resilience and alignment with critical business processes.
  • Review controls over third-party and outsourced technology services, including vendor due diligence, contractual obligations, service-level agreements, information security requirements, performance monitoring, access to organizational data and exit arrangements.
  • Develop data-driven audit tests to identify unauthorized access, unusual user activity, segregation-of-duties conflicts, dormant accounts, duplicate transactions, system overrides, control breaches, anomalies and other indicators of technology or fraud risk.
  • Use appropriate audit, data analytics and visualization tools, including advanced Excel, IDEA, Power BI, SQL and other relevant ICT audit or analytics tools, where applicable.
  • Contribute to the development and implementation of continuous auditing, continuous monitoring and automated control testing to improve audit efficiency, coverage and early identification of emerging technology risks.
  • Discuss audit observations with ICT and business process owners and management, provide practical recommendations and support timely resolution of identified technology and control weaknesses.
  • Follow up on agreed management actions and validate the implementation and effectiveness of corrective measures relating to ICT audit findings.
  • Support the preparation of Audit Committee and Board papers relating to ICT audits, cybersecurity, technology risk, data governance and other key technology control themes.
  • Assess the governance and control environment around emerging technologies, including Artificial Intelligence (AI), automation, cloud computing, digital platforms and other technology-enabled business solutions, where applicable.
  • Contribute to the continuous improvement of Internal Audit methodologies, ICT audit tools, data analytics, automation, continuous monitoring, knowledge resources and quality assurance practices.
  • Perform audit work in accordance with the Internal Audit Charter, approved methodology, policies and applicable professional standards.
  • Ensure audit assignments are completed to required quality standards and within agreed timelines.
  • Maintain complete, accurate and well-organized audit documentation to support review and quality assurance.
  • Build effective working relationships with business and functional management while maintaining appropriate audit independence.
  • Communicate audit issues clearly and constructively to process owners and senior management.
  • CISA
  • Computer Assisted Audit Techniques
  • Advanced Excel
  • IDEA
  • Power BI
  • SQL
  • Data analytics
  • Visualization tools
  • Excellent communication skills – written, oral, presentation and report writing
  • Ability to maintain highest levels of integrity and objectivity
  • Bachelor’s degree in a business-related field.
  • CISA
  • CPA/ACCA / CIA/ Computer Assisted Audit Techniques is desirable
  • Insurance Professional Qualification is desirable
bachelor degree
36
JOB-6a8c0c39745db

Vacancy title:
Internal Auditor – ICT

[Type: FULL_TIME, Industry: Insurance, Category: Accounting & Finance, Computer & IT, Business Operations]

Jobs at:
CIC Insurance

Deadline of this Job:
Friday, August 28 2026

Duty Station:
Nairobi | Nairobi

Summary
Date Posted: Monday, August 24 2026, Base Salary: Not Disclosed

Similar Jobs in Kenya
Learn more about CIC Insurance
CIC Insurance jobs in Kenya

JOB DETAILS:

About the Role

Reporting to the Director Internal Audit, the role holder will provide independent and objective assurance and advisory services that strengthen governance, risk management and internal controls across assigned business units. The role supports delivery of the Internal Audit Strategy through risk-based auditing, data-driven assurance, continuous monitoring and practical recommendations that improve business performance and control effectiveness.

Key Responsibilities

  • Execute end-to-end risk-based ICT and technology audits in accordance with the approved Internal Audit Plan, Internal Audit methodology, professional standards, regulatory requirements and the organization’s ICT risk profile.
  • Participate in enterprise and ICT risk assessments and contribute to the development of the annual Internal Audit work plan, with consideration of emerging technology risks, cybersecurity threats and changes in the organization’s technology landscape.
  • Develop audit objectives, scope, risk and control matrices, audit programmes and testing strategies for assigned ICT audit engagements.
  • Conduct ICT audits covering IT governance, cybersecurity, information security, IT general controls, application controls, IT infrastructure, networks, databases, cloud services, system development, change management, access management, IT operations, data management, business continuity and disaster recovery, as applicable.
  • Assess the design and operating effectiveness of IT General Controls (ITGCs), including logical and physical access controls, privileged access, segregation of duties, change management, backup and recovery, incident management and IT operations.
  • Review the adequacy of controls over business applications and core systems, including system configurations, application controls, interfaces, automated controls, system-generated reports and data integrity.
  • Assess the governance, implementation and effectiveness of ICT projects, system implementations, system upgrades and technology transformation initiatives, including project governance, requirements management, testing, implementation and post-implementation controls.
  • Evaluate IT service management and operational controls, including incident management, problem management, service availability, capacity management, service-level agreements and IT support processes.
  • Assess the effectiveness of business continuity and disaster recovery arrangements, including adequacy of recovery strategies, backup arrangements, recovery testing, system resilience and alignment with critical business processes.
  • Review controls over third-party and outsourced technology services, including vendor due diligence, contractual obligations, service-level agreements, information security requirements, performance monitoring, access to organizational data and exit arrangements.
  • Develop data-driven audit tests to identify unauthorized access, unusual user activity, segregation-of-duties conflicts, dormant accounts, duplicate transactions, system overrides, control breaches, anomalies and other indicators of technology or fraud risk.
  • Use appropriate audit, data analytics and visualization tools, including advanced Excel, IDEA, Power BI, SQL and other relevant ICT audit or analytics tools, where applicable.
  • Contribute to the development and implementation of continuous auditing, continuous monitoring and automated control testing to improve audit efficiency, coverage and early identification of emerging technology risks.
  • Discuss audit observations with ICT and business process owners and management, provide practical recommendations and support timely resolution of identified technology and control weaknesses.
  • Follow up on agreed management actions and validate the implementation and effectiveness of corrective measures relating to ICT audit findings.
  • Support the preparation of Audit Committee and Board papers relating to ICT audits, cybersecurity, technology risk, data governance and other key technology control themes.
  • Assess the governance and control environment around emerging technologies, including Artificial Intelligence (AI), automation, cloud computing, digital platforms and other technology-enabled business solutions, where applicable.
  • Contribute to the continuous improvement of Internal Audit methodologies, ICT audit tools, data analytics, automation, continuous monitoring, knowledge resources and quality assurance practices.

Audit Quality, Professional Standards and Independence

  • Perform audit work in accordance with the Internal Audit Charter, approved methodology, policies and applicable professional standards.
  • Ensure audit assignments are completed to required quality standards and within agreed timelines.
  • Maintain complete, accurate and well-organized audit documentation to support review and quality assurance.

Stakeholder Engagement

  • Build effective working relationships with business and functional management while maintaining appropriate audit independence.
  • Communicate audit issues clearly and constructively to process owners and senior management.

Who We’re Looking For

Essential Knowledge/Skills and Experience Required:

  • Bachelor’s degree in a business-related field.
  • CISA
  • CPA/ACCA / CIA/ Computer Assisted Audit Techniques is desirable
  • Insurance Professional Qualification is desirable
  • 3-5 years’ experience. At least 2 years’ experience in the big 4 audit firms or an organization similar in size or larger than CIC Group is an added advantage
  • Knowledge of current technological developments/trends in area of expertise and knowledge of software requirements for audit of systems procedures
  • Basic knowledge of regulations by AKI and IRA
  • Excellent communication skills – written, oral, presentation and report writing
  • Ability to maintain highest levels of integrity and objectivity
  • Flexibility in mobility

Work Hours: 8

Experience in Months: 36

Level of Education: bachelor degree

Job application procedure

Application Link: Click Here to Apply Now

All Jobs | QUICK ALERT SUBSCRIPTION

Job Info
Job Category: Accounting/ Finance jobs in Kenya
Job Type: Full-time
Deadline of this Job: Friday, August 28 2026
Duty Station: Nairobi | Nairobi
Posted: 24-08-2026
No of Jobs: 1
Start Publishing: 24-08-2026
Stop Publishing (Put date of 2030): 10-10-2076
Apply Now
Notification Board

Join a Focused Community on job search to uncover both advertised and non-advertised jobs that you may not be aware of. A jobs WhatsApp Group Community can ensure that you know the opportunities happening around you and a jobs Facebook Group Community provides an opportunity to discuss with employers who need to fill urgent position. Click the links to join. You can view previously sent Email Alerts here incase you missed them and Subscribe so that you never miss out.

Caution: Never Pay Money in a Recruitment Process.

Some smart scams can trick you into paying for Psychometric Tests.