Internal Auditor - Digital Infrastructure
Job Description and Requirements
Internal Auditor - Digital InfrastructureJob Snapshot
Role: Internal Auditor - Digital Infrastructure
Location: Abu Dhabi Emirate, United Arab Emirates
Industry: Oil and Energy
Function: Accounting/Auditing
Experience: 8-10 years in D&T or IT internal auditing
Job Type: Full-time
Position Overview
Internal Auditor - Digital Infrastructure in Abu Dhabi Emirate, United Arab Emirates is an Oil and Energy hiring opportunity for an experienced technology audit professional with strong expertise in digital infrastructure, cybersecurity, network security, cloud security, vulnerability assessment, penetration testing, and IT governance. The role supports ADNOC Group by executing risk-based audit engagements, assessing critical infrastructure controls, reviewing emerging technology risks, and providing practical recommendations to strengthen digital resilience, security governance, and operational control across ADNOC and Group Companies.
Job Details
Country: United Arab Emirates
City: Abu Dhabi Emirate
Industry: Oil and Energy
Function: Accounting/Auditing
Salary: 32000-48000
Estimated salary range based on similar jobs in the
Gender: Any
Candidate Nationality: Any
Job Type: Full-time
Role Context
The Internal Auditor - Digital Infrastructure will perform end-to-end audit engagements covering digital infrastructure and cybersecurity risk areas, including networks, cloud platforms, systems, databases, infrastructure hosting environments, access controls, vulnerability management, penetration testing, disaster recovery, and technology governance. This role strengthens assurance across ADNOC Group by identifying control weaknesses, validating risk treatment, testing security effectiveness, and contributing specialist insight to the Digital and Technology audit universe, risk assessments, and risk-based work plans.
Key Responsibilities
* Perform assigned digital infrastructure audit engagements from pre-planning through fieldwork, reporting, wrap-up, and follow-up activities.
* Apply risk and control concepts to technology scenarios involving networks, cloud platforms, systems, databases, virtualization, cybersecurity operations, and infrastructure services.
* Identify potential control gaps, governance weaknesses, security risks, and operational issues across ADNOC and Group Companies.
* Contribute as a subject matter expert to periodic risk assessments and risk-based work plans focused on infrastructure security and digital technology risk.
* Support vulnerability assessments and penetration testing reviews at infrastructure, network, and system layers.
* Develop and maintain the audit universe for Digital Infrastructure and cybersecurity risks in coordination with other Digital and Technology risk areas.
* Ensure the audit universe covers relevant risks across digital governance, operational technology, processes, applications, technology interfaces, and emerging technologies.
* Review and update the Digital and Technology audit universe with specific focus on digital infrastructure, network environments, and cybersecurity exposure.
* Develop and support strategic audit initiatives such as infrastructure assurance plans that influence group-wide audit planning.
* Oversee or support execution of strategic technology audit initiatives to ensure planned objectives, risk coverage, and assurance outcomes are achieved.
* Perform audits, advisory engagements, and influencing activities in highly technical areas involving current and emerging digital technologies.
* Develop detailed audit programs and Risk and Control Matrix documents for assigned audits.
* Define audit objectives, potential risks, key controls, audit procedures, testing techniques, and audit tools required to assess governance, risks, and controls.
* Submit audit programs to management for review and approval before execution.
* Document adequate working papers, testing evidence, audit observations, and relevant information in the automated Audit Management System.
* Ensure audit documentation follows approved templates, audit procedures, and professional internal audit standards.
* Confirm that approved audit objectives are met with adequate coverage of relevant areas and sufficient audit evidence.
* Prepare audit conclusions based on evidence, control testing, risk assessment, and professional audit judgment.
* Draft audit reports that express professional opinions on the adequacy and effectiveness of risk management, control systems, and operating efficiency.
* Recommend practical improvement actions to address identified deficiencies in digital infrastructure governance, cybersecurity controls, and technology risk management.
* Provide recommendations that support business objectives, control maturity, operational resilience, and secure technology operations.
* Assist in periodic reporting to the Audit Committee and Senior Management on technology audit activities, audit performance, significant risks, control issues, and governance matters.
* Collect, analyze, and interpret complex technical and audit data using data analytics tools and structured evaluation methods.
* Review controls linked to business continuity, disaster recovery, enterprise architecture, infrastructure platforms, on-premises systems, cloud environments, access rights, change management, and DevOps.
* Assess technology-related risks in emerging areas such as cloud, Internet of Things, Zero Trust, defense-in-depth architecture, identity and access management, digitalization, and automation.
* Review infrastructure platforms hosting AI and machine learning solutions where required, including related risks, security controls, and governance across the AI technology stack.
* Support audit planning, time tracking, project management, stakeholder coordination, and progress reporting for internal audit activities.
* Maintain awareness of ERP and operational technology processes and systems where they connect with digital infrastructure and audit scope.
* Coordinate with management, technology owners, cybersecurity teams, infrastructure teams, Group Companies, and relevant stakeholders to obtain evidence and validate audit findings.
* Ensure audit work supports stronger technology governance, better cyber risk visibility, improved infrastructure assurance, and more resilient digital operations.
Ideal Profile
* Bachelor’s Degree in Computer Science, Technology, or an equivalent related discipline.
* 8-10 years of relevant experience in Digital and Technology or IT internal auditing.
* Minimum 5 years of work experience in digital infrastructure and cybersecurity domains.
* Mandatory CISA certification or willingness to obtain CISA within one year of joining.
* Additional certifications such as GIAC, CISSP, OSCP, CISM, CCNA, CCIE, Azure, CCSK, CCSP, or GPEN are preferred or desirable.
* Advanced technical knowledge of core infrastructure, network components, routers, switches, firewalls, cloud security, operating systems, databases, virtualization technologies, and security operations.
* Strong practical experience conducting or reviewing vulnerability assessments and penetration testing across infrastructure, network, and system layers.
* Bug bounty hunting experience would be an added advantage.
* Sound knowledge of technology risks in cloud, IoT, Zero Trust, defense-in-depth architecture, identity and access management, digitalization, automation, and emerging technologies.
* In-depth knowledge of digital processes including business continuity, disaster recovery, enterprise architecture, infrastructure review, access-right management, change management, and DevOps.
* Strong understanding of International Professional Practices Framework for IT Assurance, ITAF, COBIT, ITIL, ISO27000, ISO22301, NIST, and related frameworks.
* Ability to interpret and apply IT assurance frameworks and standards to IS and IT auditing practice.
* Exposure to reviewing infrastructure platforms hosting AI or machine learning solutions is an advantage.
* Experience collecting and analyzing complex data using data analytics tools and drawing logical, evidence-based conclusions.
* Strong understanding of audit planning, audit execution, audit reporting, project management, working papers, and control testing.
* Awareness of ERP and operational technology processes and systems is preferred.
* Strong communication, technical writing, analytical thinking, stakeholder management, and problem-solving skills.
* Ability to work in a complex Oil and Energy environment where cybersecurity assurance, infrastructure reliability, risk management, and audit quality are critical.
Skills Set
* IT internal audit
* Digital infrastructure audit
* Cybersecurity audit
* Accounting/Auditing
* Infrastructure security
* Network security
* Cloud security
* Systems audit
* Database audit
* Vulnerability assessment
* Penetration testing
* Risk and Control Matrix
* Audit Management System
* Working papers
* Technology governance
* Digital and Technology audit universe
* Risk-based audit planning
* Infrastructure assurance
* Routers
* Switches
* Firewalls
* Operating systems
* Databases
* Virtualization technologies
* Security operations
* Cloud computing
* Internet of Things
* Zero Trust architecture
* Defense-in-depth architecture
* Identity and access management
* Business continuity
* Disaster recovery
* Enterprise architecture
* Access-right management
* Change management
* DevOps
* AI infrastructure risk review
* Machine learning platform controls
* ERP awareness
* Operational Technology awareness
* Data analytics
* COBIT
* ITIL
* ISO27000
* ISO22301
* NIST
* ITAF
* CISA
* CISSP
* CISM
* OSCP
* GIAC
* CCNA
* CCIE
* Azure
* CCSK
* CCSP
* GPEN
Why Join Us
This role offers a strong opportunity for a technology audit specialist to work on critical digital infrastructure and cybersecurity assurance across a major Oil and Energy organization in Abu Dhabi Emirate. The position provides exposure to advanced infrastructure environments, cloud security, emerging technology risks, penetration testing reviews, audit committee reporting, and group-wide digital governance. It is an excellent fit for an auditor who wants to combine technical cybersecurity depth with professional audit discipline and contribute to stronger resilience across high-value energy operations.
About the Company
ADNOC Group is a leading diversified energy group wholly owned by the Abu Dhabi Government. Founded in 1971, the company operates across the energy value chain and supports responsible energy production, lower-carbon solutions, and long-term industrial development. ADNOC Group is investing in cleaner energy, decarbonization technologies, operational excellence, digital resilience, and sustainability while maintaining a strong focus on safety, governance, cybersecurity, technical reliability, and responsible energy delivery from Abu Dhabi Emirate to global markets.



