Job Description
Job Title:  D&T Manager - GRC
Posting Start Date:  7/19/26
Job Description: 

Purpose of the Job

The Manager – D&T GRC plays a critical role in Digital & Technology’s GRC department, to build and sustain trust in Aramex’s technology risk and control environment. This role leads assurance activities that give executives, the Board, and our auditors confidence that application, system, and ERP controls are operating effectively, and that when gaps arise, they are closed with rigor and accountability.

The role is accountable for:

  • Leading global Technology and Cyber audit engagements with statutory and internal auditors (including Big 4), ensuring prompt, accurate, and well-evidenced responses.
  • Owning the end-to-end remediation lifecycle for audit findings - from root cause agreement through to validated closure.
  • Building a sustainable, scalable audit coordination capability across a distributed, multi-regional team.
  • Improving risk control maturity across the D&T function through continuous improvement in methodology, tooling, and stakeholder capability.

Acting as the interface between D&T process owners and both internal and external audit functions.

Job Description

Customer:
•Serve as the interface between D&T process owners and both internal and external audit functions, ensuring auditor queries are addressed promptly, accurately, and with well-organised evidence.
•Build trust with the Board, Audit Committee, and financial auditors through transparent reporting on the effectiveness of application, system, and ERP (SAP) controls and the status of open risk items.
•Trusted partner to D&T process and system owners and business function leads globally; guide them through audit obligations without disrupting business-as-usual operations.
•Provide the CDTO and senior leadership with decision-ready GRC reporting: clear visibility of audit status, open observations, remediation progress, and residual risk exposure.
•Prepare and communicate audit calendars to enable effective planning and resource allocation across concurrent engagements.
•Support regional teams in responding to audit queries for global controls and interpretation of application of global controls to regional-level requirements, minimising duplication of regional effort across multiple simultaneous engagements.
•Communicate findings, root causes, and remediation recommendations with clarity and credibility, adapting depth and tone from technical process owners through to reporting for Excom and Audit Committee.
 
People:
•Demonstrate leadership, mentoring junior staff, and assist in the development of the GRC team under Head of GRC. Build a high-performing function capable of managing complex, multi-region audit programs.
•Lead and influence across distributed, matrixed, multi-regional teams spanning multiple time zones and cultural contexts, fostering consistent standards of delivery.
•Develop and embed standardized methodologies, audit response templates, and best practices across D&T. Build ITGC awareness and audit readiness across process owner communities.
 
Operations:
•Lead planning and execution of global Technology, ITGC, and Cybersecurity audit engagements internally and via external support partner; develop and maintain audit calendars, manage scheduling conflicts, and coordinate evidence gathering, stakeholder access, and fieldwork logistics.
•Monitor audit progress against plan; maintain status dashboards covering open requests, fieldwork progress, and resource allocation; escalate delays or emerging risks promptly.
•Own the governance of open audit observations — including ITGC, ICFR, ERP (SAP), infrastructure, cloud, logical access, SoD, and cybersecurity — ensuring root causes are agreed, management responses are fit-for-purpose, and remediation is validated and formally closed.
•Track remediation actions, owners, and due dates; coordinate validation testing and close-out; report progress and residual risks to senior stakeholders and audit committees.
•Drive GRC tooling improvements and adoption for assurance function; identify systemic control weaknesses and lead root-cause remediation initiatives.
•Support control self-assessment (CSA) program development, and drive testing of Internal Controls as per the risk control matrix and maintain awareness of emerging risk domains including AI governance and cloud security.
 
Financial Result:
•Ensure timely, accurate audit responses with proper classification of material and non-material risks, protecting the organization from audit qualification or adverse findings.
•Drive efficiency in audit delivery by reducing duplication, improving evidence of reuse, and shortening remediation cycles, minimizing the cost and disruption of audit activity across D&T.
•Contribute to risk-informed GRC investment prioritization and support vendor/tooling decisions for the assurance function, ensuring value for money.

Job Requirements - Experience and Education

  • Bachelors in computer science, information technology, or related field.
  • CISA required or strongly preferred
  • Minimum 10-12 years in IT with proven experience (6-8 years) leading technology audit, ITGC assurance, or IT GRC in a global organisation; prior Big 4 or internal audit experience highly desirable.
  • Proven track record managing statutory and internal audit engagements; hands-on ITGC experience across change management, logical access, computer operations, and SOX/ICFR controls.
  • Experience auditing ERP environments, particularly SAP (Basis security, role-based access, Segregation of Duties).
  • Demonstrated ability to coordinate audit and compliance activities across distributed, multi-regional teams and time zones.
  • Strong command of IT governance and risk frameworks (COBIT, ITIL, ISO 27001:2022); knowledge of SOX, IT general controls.
  • Excellent stakeholder management and communication skills — credible from process owners through to Board level.
  • Fluency in Arabic and English (written and spoken).
  • Industry acclaimed certifications: CISA / CISM /CISSP / CCSP/ LA or LI in ISO 27001:2022
  • Experience with enterprise GRC platforms and audit management tooling.
  • Candidates with experience in supporting / implementing SOC 2 Type II compliance will have added advantage.
  • Cybersecurity audit exposure: cloud infrastructure, network and endpoint security, application and web security.
  • Transformation portfolio management experience in complex matrix organizations; strong cross-cultural negotiation and conflict resolution skills.
  • Awareness of AI governance frameworks and enterprise AI risk considerations

Leadership Behaviors

Building Outstanding Teams
Setting a clear direction
Simplification
Collaborate & break silos
Execution & Accountability
Growth mindset
Innovation
Inclusion
External focus

Skills