About this role
Main purpose of job
To provide independent assurance over technology risks, IT governance and IT controls across Provident Europe and IPF Digital by planning and delivering risk-based IT internal audits, identifying control improvements and supporting the organisation in strengthening its technology control environment.
Key accountabilities
· Plan and deliver risk-based IT internal audits across Provident Europe and IPF Digital to provide independent assurance over the effectiveness of IT governance, IT risks and technology controls.
· Assess the design and operating effectiveness of IT General Controls, cybersecurity, cloud, third-party technology and technology governance processes to identify control weaknesses and opportunities for improvement.
· Prepare clear, evidence-based audit documentation, findings and reports to support management in implementing practical and sustainable control enhancements.
· Perform risk assessments and contribute to the annual audit planning process to ensure emerging technology risks and regulatory developments are appropriately reflected in the audit universe.
· Monitor and validate the implementation of agreed management actions to confirm that identified risks are adequately mitigated.
· Build effective working relationships with business and technology stakeholders across the Group to facilitate efficient audit delivery and promote a strong control culture.
· Maintain up-to-date knowledge of technology, cybersecurity, financial services regulations and industry best practices to ensure audit work remains relevant and aligned with evolving risks.
· Take ownership of assigned audit engagements, delivering high-quality outputs within agreed timelines while maintaining independence, objectivity and professional standards.
Knowledge, skills
• University degree in Information Technology, Computer Science, Information Systems, or another relevant discipline.
• Professional certifications such as CISA, CRISC, CISSP, CISM, or CIA represent an advantage.
• Good understanding of IT General Controls (ITGCs).
• Knowledge of IT governance frameworks and technology risk management.
• Understanding of cybersecurity principles and information security controls.
• Knowledge of cloud technologies and third-party technology risks.
• Understanding of financial services regulations affecting technology, including DORA and related ICT risk requirements.
• Knowledge of internal auditing principles, methodologies, and professional standards.
• Strong analytical and critical thinking skills.
• Ability to prepare concise, high-quality audit reports.
• Strong stakeholder management and influencing skills.
• Ability to work independently in an international environment.
• Strong organizational and prioritization skills.
Essential Functional / Technical Skills:
· IT Internal Audit.
· IT General Controls (ITGC) testing.
· Technology risk assessment.
· Cybersecurity control assessment.
· IT governance reviews.
· Third-party and cloud risk assessments.
· Audit documentation and report writing.
· Regulatory compliance reviews.
· Data analytics and audit tools (advantage).
Experience:
· 3–5 years' experience in IT Internal Audit, External IT Audit, IT Risk, IT Controls or IT Compliance.
· Experience within financial services is preferred.
· Experience working across multiple stakeholders and functions.
· Experience delivering audit assignments with limited supervision.
What’s in it for you?
- Annual bonus (depending on the business and individual performance)
- A medical subscription to one of our medical partners, Regina Maria or Medicover
- Meal vouchers of 30 lei per voucher
- Possibility to work in a hybrid system
- 21 days of vacation, plus 4 additional days of wellbeing
- Days off for seniority in the company
- A day off on your birthday
- Financial benefits for special events
- Discounts at various partners (Orange, Samsung, dental clinics, banking institutions)
- A welcoming and friendly office in the city center, near Parcul Tineretului
You will also enjoy personal and professional development programs:
- Induction program - 3 months of role-based learning, applied trainings and Buddy assigned for easy onboarding process
- Mentoring program - development sessions with relevant professionals in various areas of expertise
- Wellbeing program - networking and social events and actions
- Training and development opportunities - courses and learning opportunities on various topics through Provident Academy, technical trainings, talent growth and succession programs.