Job Description
KenTrade is seeking to recruit a highly analytical, ethical, and results-oriented Senior Internal Auditor – Information Systems to strengthen the Agency's governance, accountability, and digital assurance framework. This position offers an excellent opportunity for an experienced information systems audit professional who is passionate about improving organizational performance through independent assurance, technology risk evaluation, and continuous process improvement. The successful candidate will support the Internal Audit function by delivering high-quality audit engagements that evaluate the effectiveness of information systems, internal controls, cybersecurity practices, governance structures, and enterprise risk management processes.
The role requires an individual capable of examining complex business systems, identifying operational and technological risks, and recommending practical solutions that enhance efficiency while safeguarding organizational assets. The successful officer will independently assess digital platforms, financial systems, ICT infrastructure, and automated business processes to ensure compliance with applicable legislation, internal policies, international auditing standards, and recognized information security frameworks. Working closely with management and various departments, the position contributes to strengthening transparency, accountability, and continuous improvement throughout the Agency.
The Senior Internal Auditor – Information Systems will participate in the preparation and execution of risk-based audit plans covering financial systems, operational processes, cybersecurity controls, data governance, business continuity arrangements, disaster recovery capabilities, system implementation projects, and regulatory compliance. The position also supports the monitoring of corrective actions arising from previous audit findings, ensuring that agreed recommendations are implemented effectively and within established timelines.
This role demands exceptional analytical thinking, professional judgment, integrity, and strong communication abilities. The successful candidate will prepare detailed audit reports supported by sufficient evidence, present findings to management in a professional manner, and provide practical recommendations that improve internal controls while supporting organizational objectives. The position further requires collaboration with departmental teams to promote awareness of risk management principles, strengthen governance practices, and encourage compliance with established procedures.
KenTrade offers a professional environment where innovation, accountability, and continuous learning are encouraged. Employees have the opportunity to contribute to nationally significant trade facilitation initiatives while developing expertise in information systems auditing, governance, enterprise risk management, and digital transformation oversight. The successful candidate will join a team committed to maintaining high professional standards and delivering independent assurance that supports strategic decision-making.
Applicants with a strong background in information systems auditing, excellent report writing skills, knowledge of information security principles, and experience evaluating ICT controls are encouraged to apply. Individuals who demonstrate professionalism, confidentiality, sound ethical judgment, and commitment to continuous improvement will find this position both rewarding and professionally fulfilling.
Key Responsibilities
- Develop and contribute to annual risk-based internal audit plans by evaluating organizational risks, emerging technology threats, operational priorities, and regulatory requirements.
- Execute information systems audits covering enterprise applications, ICT infrastructure, databases, cloud environments, cybersecurity controls, and digital services.
- Review system development projects to evaluate governance, project controls, implementation processes, testing procedures, and post-implementation performance.
- Examine information technology policies, standards, procedures, and operational practices to determine their effectiveness and compliance with organizational requirements.
- Assess cybersecurity safeguards including user access management, authentication mechanisms, network security, endpoint protection, vulnerability management, and incident response capabilities.
- Evaluate backup procedures, disaster recovery arrangements, and business continuity strategies to ensure critical systems remain available during disruptions.
- Perform comprehensive reviews of system-generated financial information to confirm reliability, completeness, confidentiality, and integrity of electronic records.
- Verify compliance with ICT governance frameworks, regulatory obligations, internal policies, and recognized professional auditing standards.
- Conduct operational, compliance, financial, and special-purpose audits assigned by management within approved audit schedules.
- Review automated controls embedded within enterprise applications to determine whether they effectively reduce operational and financial risks.
- Assess database administration practices including security, change management, access controls, monitoring, and maintenance procedures.
- Evaluate revenue and expenditure systems to confirm adequate safeguards exist for financial resources and transactions.
- Prepare detailed audit working papers containing sufficient evidence to support audit findings, recommendations, and professional conclusions.
- Analyze audit evidence objectively and document observations using recognized internal auditing methodologies.
- Prepare professional audit reports that clearly communicate identified risks, control weaknesses, root causes, business impacts, and practical recommendations.
- Present audit findings confidently during meetings with management, providing constructive guidance for corrective action.
- Monitor implementation of agreed audit recommendations and validate completion through follow-up reviews.
- Maintain accurate documentation throughout every audit assignment while observing confidentiality and data protection requirements.
- Collaborate with departmental teams to promote awareness of internal controls, governance responsibilities, and risk management practices.
- Identify opportunities for process improvement that strengthen efficiency without compromising compliance or accountability.
- Participate in reviews of new technologies, digital transformation initiatives, and system upgrades before implementation.
- Provide advisory support on information systems controls during organizational projects where independent guidance is appropriate.
- Evaluate third-party technology service providers and outsourced ICT services for compliance with contractual and security obligations.
- Remain informed about emerging cybersecurity threats, evolving audit methodologies, regulatory developments, and industry best practices.
- Uphold the highest standards of ethics, professionalism, independence, objectivity, and integrity while performing all assigned responsibilities.
Qualifications & Requirements
- Applicants should possess a Bachelor's degree in Finance, Accounting, Information Systems, Computer Science, Business Information Technology, or another closely related discipline from a recognized institution. Professional certification in Information Systems Auditing is required, while active membership in ISACA in good professional standing is essential. Possession of CPA(K), Certified Internal Auditor qualifications, or membership with IIA or ICPAK will provide an added advantage. Candidates should have a minimum of three years of practical experience conducting information systems audits, ICT control reviews, technology risk assessments, or related assurance assignments within a reputable organization. Completion of a recognized management or supervisory course will be beneficial.
- The ideal candidate should demonstrate excellent knowledge of information security principles, enterprise risk management, ICT governance, internal control frameworks, business continuity planning, disaster recovery, audit methodologies, and regulatory compliance. Strong analytical thinking, report writing, presentation, communication, investigation, stakeholder engagement, problem
- solving, planning, organization, and decision
- making skills are essential. Applicants should be capable of working independently while managing multiple assignments within strict deadlines. High ethical standards, confidentiality, objectivity, professional integrity, adaptability, attention to detail, and proficiency in modern audit software and Microsoft Office applications are highly desirable for success in this position.
How to Apply
Interested and qualified candidates should submit their applications through the official KenTrade online application portal before August 15, 2026. Applicants are encouraged to complete all required application details accurately and attach the necessary academic, professional, and supporting documents as instructed in the recruitment portal. Only shortlisted candidates will be contacted for the next stage of the selection process.