Amr Mohamed, Head of Internal Audit

Amr Mohamed

Head of Internal Audit

Fawaz Abdullaziz Al Hokair & Co.

Lieu
Arabie Saoudite
Éducation
Master, Information System Security
Expérience
23 years, 7 Mois

Partager Mon CV

Empêcher usager


Expériences professionnelles

Total des années d'expérience :23 years, 7 Mois

Head of Internal Audit à Fawaz Abdullaziz Al Hokair & Co.
  • Arabie Saoudite - Riyad
  • Je travaille ici depuis mai 2016

- Manage the Internal Audit & Advisory Services as integrated audit services includes IT, Financial and Operational audit services to within Al Hokair Retail group such as Retail Key activities (Sales to Cash), Procure to Pay (AP), Build to Retire (Fixed Asset), Plan to Build (Inventory Management); Hire to Retire (HR & Payroll) and Financial Reporting (GL).
- Develop three years Strategic Risk Based Audit Plan and Annual Audit Pan for the Group activities.
- Prepare the Audit Committee Quarterly Reports and Annual Internal Audit Report.
- Develop the Audit Risk Assessment (Audit Universe and Risk Universe).
- Develop Internal Audit methodology, Internal Audit Charter and Audit Committee Charter according to IIA standards.
- Perform Quality Assurance Review (QAR) for IA Function.
- Prepare the Audit Committee Quarterly Reports and Annual Internal Audit Report.
- Review of Group’s polices and procedure such as IT Policies, HR Policies, Retail Policies and Financial Policies and Performing Gap analysis.
- Implement Continues Auditing technology for Revenue Assurance and Retail Operations
- Using ACL (Audit Command Language), IDEA and Teammate Analytics for Technical Review of data integrity and analysis used within various application systems.
- Full responsible of CCH Teammate Audit Management System administration and implementation (Teammate champion).

Internal Audit Mnager à Mohamed Yousuf Naghi Group
  • Arabie Saoudite - Jeddah
  • octobre 2012 à avril 2016

- Managing IT, Financial & Assurance / Operational Audit activities for all NAGHI group's automotive sector operations such as Vehicle sales (New vehicles and Used cars), after sales (Workshop and Spare parts) and Financial Services (Leasing and Installment) processes to ensure acceptable performance and compliance levels within NAGHI group.
- Develop Internal Audit methodology and Audit Charter according to IIA standards.
- Develop the annual Risk Assessment and annual audit plan for all business activities.
- Developing Integrated Audit Programs for all types of audit assignments in the group's operations covers Financial, Operational and IT audit and related controls.
- Performing the investigation in case of fraud or irregularities.
- Review and evaluate the IT General Controls and Application System Controls for SAP ERP, ADP Autoline Dealer Management System and AS/400 applications.
- Finalize audit reports and perform Follow up Review for the implementation of corrective action.
- Develop audit staff through proactive career planning and performing staff evaluation.
- Coaching and mentoring the audit staff for developing proactive career path for all staff.

Deputy Manager – IT Advisory à KPMG Egypt
  • Egypte - Le Caire
  • février 2011 à octobre 2012

• IT Risk Consulting
• IT Internal Audit Co/Outsourcing
• IT General Controls Review
• IT Application Risks and Controls Assessment
• Data Analysis and Control Assurance using ACL and IDEA
• IT Compliance and ISMS Implementation (PCI, HIPAA, ISO 27001)
• Cyber Maturity Assessment and IT Capability Assessment (COBIT, KPMG CMA)
• IT Security Policies, Security Strategy and IT Governance
• Contingency planning for Disaster Recovery and Business Continuity Management planning
• Information Security Assessment (Vulnerability Scanning, Penetration Testing and Configuration Review) and Computer Forensics
• IT System Selection and Vendor Selection
• IT due diligence

Internal Audit Supervisor à Abdul Latif Jameel Ltd. Co.
  • Arabie Saoudite - Jeddah
  • mai 2006 à décembre 2010

- Performed various Financial Audit, IT audit and Operational audit assignments of various companies & operations of ALJ group such as new vehicle sales and after sales operations (service workshops and spare parts), retail centers, community services, or real estates.
- Reviewed and evaluate the Operating System Controls for Windows, Unix, Novel, OS/400.
- Reviewed the Application System Controls for Oracle Financials & Oracle HRMS and AS/400 application.
- Using ACL (Audit Command Language) and IDEA for Technical Review of data integrity and analysis used within various application systems.
- Involved in turning around the IAD scope from traditional control based to Risk based audit.
- Involved in managing and coordinating the External Quality Assurance Review (QAR) for the department (first time in ALJ history) performed by Deloitte - Dubai office.
- Full responsibility of TeamMate Audit Management System (Responsible for Administration and Technical Implementation).
- Was responsible of develop and manage the website for the IA department.

Auditor à KPMG Egypt
  • Egypte - Le Caire
  • octobre 2003 à mai 2006

•Provide risk based audit for KPMG Egypt Clients
•Performing risk-based IS audits, including
1.IT General Controls review to evaluate the design and implementation and test the operating effectiveness of the following:
Access to programs and data
Program Changes
Program Development
Computer Operations
End-User Computing
2.IT Application Controls review to test key application controls supporting business processes. This includes identifying key risks that may affect the business process and evaluate the design and implementation and test the operating effectiveness of the automated controls that mitigate these risks. Mainly we test the following automated controls related to a business application:
System Access and Authorization.
System Interface and Data Migration.
Edit/Exception Reports.
System Configurations and Account Mapping.

•Performing Security audit and evaluated Controls over operating systems, applications and databases

Information System Specialist à ITC
  • Egypte - Le Caire
  • octobre 2000 à septembre 2003

Information System administartor

Éducation

Master, Information System Security
  • à Cairo University
  • juillet 2010
Baccalauréat, High Diploma in Computer Science and Information Technology
  • à Cairo University
  • juin 2002
Baccalauréat, B.SC in Accounting
  • à Cairo University
  • juin 2000

Specialties & Skills

Langues

Arabe
Expert
Anglais
Expert

Formation et Diplômes

Certified Ethical Hacker (CEH) (Certificat)
Date de la formation:
March 2010
Governance, Risk Management and Compliance Auditor (GRCA) (Certificat)
Date de la formation:
August 2020
Governance, Risk Management and Compliance Professional (GRCP) (Certificat)
Date de la formation:
August 2020
Certified in Risk and Information Systems Control (CRISC) (Certificat)
Date de la formation:
June 2011
Certified Information Security Manager (CISM) (Certificat)
Date de la formation:
June 2010
Certified Information Systems Auditor (CISA) (Certificat)
Date de la formation:
December 2010
Certified Fraud Examiner (CFE) (Certificat)
Date de la formation:
June 2021