PRAZ - Procurement Regulatory Authority of Zimbabwe

Internal Auditor

Accounting & Finance Jobs
Salary
TBA

Job Description

The Procurement Regulatory Authority of Zimbabwe (PRAZ) is inviting applications from suitably qualified and experienced candidates for the following positions that have arisen within the Authority.

INTERNAL AUDITOR
Job Purpose
To provide independent and objective assurance on the effectiveness of ICT governance, information security, e-procurement systems, data integrity, risk management, and internal controls to support PRAZ in achieving its strategic objectives and statutory mandate.

Duties and Responsibilities

Duties and Responsibilities
Evaluate electronic government procurement systems, other ERP and database systems to ensure data integrity, system availability, and fair processing.
Review IT infrastructure, applications, and networks to test the design and operational effectiveness of internal controls.
Assess and monitor the efficiency and effectiveness of ICT systems.
Assess and determine the appropriateness of the existing hardware and future systems.
Verify that information technology policies and operations comply with the Public Procurement and Disposal of Public Assets Act, make sure systems follow standards like SOX, GDPR, ISO and national ICT regulations.
Develop draft IT audit programmes in collaboration with relevant staff.
Execute assigned IT audit programmes, gather, and analyse audit evidence using data analytical tools.
Document audit findings and internal control weaknesses in well-structured work papers and present feasible recommendations to management.
Monitor the implementation of previous audit recommendations to ensure management addresses identified information technology security gaps.
Provide risk and control guidance during the implementation or upgrading of new information systems and digital projects.
Conduct data analytics to identify procurement irregularities, anomalies, fraud indicators and potential collusive practices within electronic procurement systems.
Assess cloud computing environments, configurations, access controls, data protection and related security controls.
Assess and monitor data integrity between the diverse systems, middleware and interfaces.
Assess the Authority's Data Protection control environment and ensure compliance with the Data Protection Act.

Qualifications and Experience

Required Qualifications
A degree in Information Systems, Computer Science, Information Technology or Business Studies and Computing Science.
Certified Information Systems Auditor (CISA) qualification (Mandatory).
International Professional Practices Framework (IPPF).
International Standards for the Professional Practice of Internal Auditing.
Risk-based auditing methodologies.
Professional Certifications
The following qualifications will be an added advantage:
CRISC / CISM: Certification in Risk and Information Systems Control.
Cybersecurity/Forensics Certification such as CEH (Certified Ethical Hacker).
Digital forensics training to effectively audit e-GP platforms.
CISSP.
CIA.
Experience and Professional Membership
At least 3–5 years of hands-on experience in information systems auditing, IT risk compliance, or systems security. Experience gained within the public sector, oversight body or a reputable audit firm is an added advantage.
Professional Affiliations: Active membership in recognised bodies like ISACA (Information Systems Audit and Control Association) or the Institute of Internal Auditors (IIA).

Key Technical Knowledge
- Proficiency in CAATs (Computer-Assisted Audit Tools), data analytics software (like ACL or IDEA), database management (SQL), and cybersecurity frameworks.

Key Competencies
Understanding operating systems, databases, network architecture, and cybersecurity basics.
Familiarity with systems concepts such as the Public Procurement and Disposal of Public Assets Act (Chapter 22:23), the Cyber and Data Protection Act (Chapter 12:07), Treasury ICT guidelines, and applicable international standards including ISO 27001 and COBIT.
Strong analytical thinking, objective problem-solving, and the ability to explain complex technical risks to non-technical business leaders.
Technical Competencies
ERP systems auditing.
Microsoft 365 security auditing.
Database auditing.
Vulnerability assessment and interpretation.
Identity and access management controls.

How to Apply

HOW TO APPLY
Candidates who meet the requirements of the above posts are invited to submit their application letters accompanied by detailed CVs and certified copies of academic and professional qualifications.
The Finance and Administration Director
Procurement Regulatory Authority of Zimbabwe
P.O. Box CY406
Causeway
Harare
Closing Date: Wednesday, 14 October 2026.
Note: The lower application instructions and contact details are small and partially blurred in the photograph. The application email address and any additional submission instructions could not be transcribed confidently.