Muhammad Ahsan Malik, Senior IT Audit Manager

Muhammad Ahsan Malik

Senior IT Audit Manager

Tamer

Location
Saudi Arabia - Jeddah
Education
Bachelor's degree, Computer Sciences
Experience
15 years, 4 Months

Share My Profile

Block User


Work Experience

Total years of experience :15 years, 4 Months

Senior IT Audit Manager at Tamer
  • Saudi Arabia - Jeddah
  • My current job since September 2018

Responsible for the internal controls and risks of the company's technology assets. This role includes identifying the weaknesses in the system's network and creating an action plan to prevent security breaches in the technology.

Senior IT Audit Manager at TAMER Group
  • Saudi Arabia - Jeddah
  • My current job since January 2022

Senior IT Audit Manager with 14+ years of experience in managing and executing comprehensive IT audit programs for multinational organizations.

Proven track record of delivering high-quality audit services, identifying and mitigating IT risks, and enhancing internal controls.

Skilled in leading cross-functional teams, developing audit methodologies, and implementing best practices to ensure compliance with regulatory requirements and industry standards.

Strong expertise in assessing IT governance, IT infrastructure, cybersecurity, data privacy, and business continuity.

A strategic thinker with excellent communication and stakeholder management skills, driving organizational change and fostering a culture of continuous improvement.

Dedicated to driving efficiency, optimizing IT processes, and adding value through actionable recommendations.

ISACA Certified Information Systems Auditor (CISA)
ISACA Certified in risk and information system controls (CRISC).
ISACA Certified Data Privacy Solution Engineer (CDPSE).
Cybersecurity Audit Certificate.

Senior IT Auditor at Nahdi Medical Company
  • Saudi Arabia - Jeddah
  • September 2015 to September 2018

- CISA Certified
- IRCA Trained ISO 22301:2012 BCMS, Lead Auditor

- Responsible for the management and delivery of IT and business process audits to ensure business risks get identified and appropriately managed before the strategic objectives get adversely affected.

- Perform general and application control reviews for simple to complex computer information systems.

- Perform information control reviews to include system development standards, operating procedures, system security, programming controls, communication controls, backup and disaster recovery, and system maintenance.

Technical Consultant at Logici Information System
  • Pakistan - Karachi
  • December 2012 to October 2014

Being part of Technical Team of oracle retail implementation project for several sales corporations, major responsibilities included

 Integration of oracle retails with external systems.
 Identification, Analysis and design of integration points.
 Configuration and execution of integration methodology on Oracle Retail Integration Bus (ORIB).
 Developing PL/SQL Procedures and business logics on various customize modules.
 Development of custom API's and integration of custom modules with standard application modules through provided standards in ORIB for Oracle RETAILS.
 Development of custom shell programs.
 Development of custom pro*c programs.

System Analyst at Gull Ahmed Textile Mils Ltd
  • Pakistan - Karachi
  • January 2012 to December 2012

Job Period : From JAN. 2012 to date
Designation : System Analyst
Role : Techno-Functional
Responsibilities:

Part of Technical Team of an in-house ERP implementation project, providing support, report development and maintenance on SCM, OM, INVENTORY and HRMS modules
Implementing Order Management, Bills of Material, HRMS & Payrollin techno-functional role.
Leading a Team, integrating Order Management and Bills of Material with custom Discrete Manufacturing module, further
 Custom Form development in Oracle Application Framework (OAF).
 Developing PL/SQL Procedures and business logics on various customize modules.
 Development of custom API's and integration of custom modules with standard application modules through provided Interfaces and standard APIs for Oracle EBS R12.
 Report development.
 Personalization and Extension.
 EBS R12 Supply Chain Management
 HRMS
 Integration of Order Management & Bills of Material with custom discrete manufacturing application

Technichal Consaltant at Inbox Business Technologies
  • Pakistan - Karachi
  • February 2010 to December 2011

Was part of Technical Team of an ERP implementation project intended for a national defense organization, Phase 1 included locational implementation of SCM and EAM, which was successfully developed, major responsibilities included.

 Custom Form development in Oracle Application Framework (OAF).
 Developing PL/SQL Procedures and business logics on various customize modules.
 Development of custom API's and integration of custom modules with standard application modules through provided Interfaces and standard APIs for Oracle EBS R12.
 Preparing AS-IS, TOBEs and TDR for the implementation of ERP.
 Designing custom Workflow and personalization for EBS R12.

Software Engineer at Emmaculate
  • Pakistan - Karachi
  • March 2008 to February 2010

* Complete analysis, design and development of MCB E-payments system (online transfer and home remittance system).

* Complete analysis, design and development of KASB EnVoy System (home remittance system).

* Involved in analysis and development of enhancements for UBL’s CARS (credit analysis and reporting system) application.

* Provided support and involved in new developments for Bank Alfalah’s CARS application.

* Provided support and involved in new developments for I.G.I M.F.I.S (mutual fund investment system) application.

* Over all analysis, database designing and optimization of Sieman’s VMP(vehicle management portal) .

Education

Bachelor's degree, Computer Sciences
  • at Federal Urdu University of Arts, Science and Technology
  • December 2007

Specialties & Skills

Internal Controls
Cyber Security
IT Audit
Risk Management
Audit Command Language (ACL)
IT Risk Management
Data analysis
Business Continuity management
Data Modeling
SQL / PL SQL programing
IT Governance
IT Compliance Audit
IT Auditor
IT Infrastructure Audit

Languages

English
Expert

Memberships

ISACA
  • Professional Member
  • October 2019

Training and Certifications

CDPSE (Certified Data Privacy Solution Engineer) (Certificate)
Date Attended:
May 2020
ISACA Cybersecurity Audit Certificate (Certificate)
Date Attended:
April 2020
ISO 22301:2012 Business Continuity Management Lead Auditor (Training) (Certificate)
Date Attended:
December 2017
Valid Until:
December 2020
CRISC (Certified in Risk & Information System Controls) (Certificate)
Date Attended:
January 2020
CIA (Certified Internal Auditor) (Training)
Training Institute:
Power Resource Corporation
Date Attended:
November 2015
Duration:
40 hours
CISA (Certified Information System Auditor) (Certificate)
Date Attended:
August 2017
Valid Until:
January 2021

Hobbies

  • Reading, Writing and Exploring