Summary
Overview
Work History
Education
Skills
Affiliations
Software
Certification
References
Timeline
AdministrativeAssistant
Thandi Mokomane

Thandi Mokomane

Senior Specialist IT Auditor | Risk Assurance | Cybersecurity
Midrand

Summary

CISA-certified IT audit and risk assurance professional with over 10 years of experience across diverse sectors, including telecommunications, aviation, healthcare, and the public sector. Expertise in designing risk-based assurance plans, leading ITGC and cybersecurity reviews, conducting in-depth thematic audits, and driving remediation closure. Demonstrated ability to collaborate effectively with Internal Audit, IT Risk, and Security teams to enhance governance and combined assurance frameworks. Committed to delivering high-quality results that bolster organizational resilience and compliance.

Overview

13
13
years of professional experience
1
1
Certification
1
1
Language

Work History

Senior Specialist IT Audit

Vodacom Group
Midrand
08.2024 - Current
  • Managed multiple audit projects from inception to conclusion, delivering high-quality outcomes aligned with organizational objectives and stakeholder expectations across all Vodacom Markets.
  • Implemented continuous auditing strategies using automated tools for real-time monitoring of system activity and prompt identification of irregularities.
  • Evaluated internal controls and processes, streamlining workflows for increased efficiency and risk mitigation.
  • Identified opportunities for process improvements within the IT department by analyzing current operational structures and recommending strategic changes when necessary.
  • Collaborated with cross-functional teams to ensure adherence to industry best practices, resulting in improved cybersecurity posture.

Senior IT Auditor

Netcare Limited
09.2023 - 07.2024
  • Delivered on multiple finance, HR and medical systems' IT General Controls, application control and cybersecurity assurance across the Group.
  • Prepared Process Risk Control Matrix-style working papers and supported methodology enhancements.
  • Presented audit results to management and monitored remediation closure.
  • Participated in IT governance initiatives, contributing to the development of robust policies and standards for consistent information security management across the organization.
  • Identified opportunities for process improvements within the IT department by analyzing current operational structures and recommending strategic changes when necessary.
  • Developed detailed audit reports to assist management in implementing appropriate IT General controls measures.
  • Conducted thorough assessments of third-party vendors'' IT systems, safeguarding company data shared through business partnerships.

Internal Auditor

South African Civil Aviation Authority
Midrand
03.2022 - 08.2023
  • Executed risk-based audits, conducted walkthroughs and performed control testing.
  • Prepared audit pack for the audit committee.
  • Involved in the strategic planning for the audit plan.
  • Performed internal audits of financial and departmental operations, developing risk assessments and conducting process walkthroughs for compliance with documented processes.
  • Participated in special projects as requested by senior leadership, providing subject matter expertise on internal controls and risk management practices.
  • Reviewed and identified risks, analyzed controls and tested compliance.
  • Developed strong working relationships with external auditors, facilitating efficient communication during annual audits.
  • Maintained up-to-date knowledge of industry trends and emerging risks, ensuring relevance in audit approach and methodology.

Assistant Manager: Network Security Audit

Auditor General of South Africa
Pretoria
04.2016 - 02.2022
  • Managed multiple audit projects from inception to conclusion, delivering high-quality outcomes aligned with organizational objectives and stakeholder expectations.
  • Maintained confidentiality, handling sensitive information discreetly throughout all stages of the audit process.
  • Conducted risk assessments to determine areas requiring increased focus during subsequent audits.
  • Implemented continuous auditing strategies using automated tools for real-time monitoring of system activity and prompt identification of irregularities.
  • Enhanced IT security by conducting comprehensive audits and identifying potential risks within the organization.
  • Reviewed system configurations and access controls, strengthening overall network security and reducing unauthorized access incidents.

IT Auditor

Sekela Xabiso
Johannesburg
03.2014 - 03.2016

Conducted regular vulnerability assessments, proactively addressing weaknesses before they could be exploited by external threats.

  • Facilitated training sessions for staff members on cybersecurity best practices, promoting a proactive security culture throughout the company.
  • Evaluated internal controls and processes, streamlining workflows for increased efficiency and risk mitigation.
  • Recommend improvements in security systems and procedures.

Trainee IT Auditor

Ngubane & Co
Johannesburg
01.2013 - 03.2014
  • Attended training courses to build understanding of processes, techniques, and industry.
  • Participated in on-the-job training, working closely with supervisors and coworkers and asking appropriate questions.
  • Promoted positive collaboration among trainees, encouraging teamwork and problem-solving skills.
  • Filled out timesheets and paperwork according to identified requirements.
  • Participated in industry workshops and seminars, continuously expanding professional knowledge and skills.

Education

B-Tech - Internal Auditing

Tshwane University of Technology
Pretoria

Certificate - Computer Auditing

WITS Plus

Skills

Innovation management

Affiliations

Institute of Internal Auditors (IIA)

ISACA

Software

Teammate

Microsoft Word Excel PowerPoint Outlook OneNote Teams SharePoint OneDrive

PowerBI

Tenable Nessus

Qlik Sense

Certification

CISA – ISACA

References

To be provided on request.

Timeline

Senior Specialist IT Audit

Vodacom Group
08.2024 - Current

Senior IT Auditor

Netcare Limited
09.2023 - 07.2024

Internal Auditor

South African Civil Aviation Authority
03.2022 - 08.2023

Assistant Manager: Network Security Audit

Auditor General of South Africa
04.2016 - 02.2022

IT Auditor

Sekela Xabiso
03.2014 - 03.2016

Trainee IT Auditor

Ngubane & Co
01.2013 - 03.2014

B-Tech - Internal Auditing

Tshwane University of Technology

Certificate - Computer Auditing

WITS Plus
Thandi MokomaneSenior Specialist IT Auditor | Risk Assurance | Cybersecurity