Skip to main content


BAT is evolving at pace - truly like no other organisation.

To achieve the ambition, we have set for ourselves, we are looking for colleagues who are ready to live our ethos every day. Come be a part of this journey!


SENIORITY LEVEL: Non Management 

FUNCTION: Digital Business Solutions IT 

LOCATION: Bandar Sunway, Selangor, Malaysia


This role is part of GBS Corporate Finance Team. The main responsibility of the role is to proactively completes SOx Operating Efficiency testing, agreed test plans & undertake Internal Controls assurance activities and report findings using structured tools and techniques for internal control process.

Reports to: Manager

Reporting Level: Leads/Manage Others: Senior Analyst


Principal Accountabilities 

  • Support the development of the overall role as a second line of defense within BAT. 
  • Ensuring all work is fully detailed with the BCT Methodology and the SOx Testing process, reflecting current good practice in internal controls. 
  • Certain elements of Controls Advisory and Assurance work will need to be completed in line with Audit Standards to enable reliance from External Audit. 

Opportunity to participate in following business process reviews and control design advisory projects:

  • Perform SOx ITGC testing.
  • Communicate issues noted from SOx testing to key team members.
  • Support Control Owners to develop remediation plans and address issues in a timely manner. 
  • Track and report on outstanding actions relating to SOx findings. 
  • Support and participate in the delivery of training to Control Operators and Owners to support the efficiency of internal controls over financial reporting across the Group. 
  • Support the BCT team members (and globally) with GRC master data requirements 
  • the opportunity to develop continuous control monitoring and access monitoring using GRC solutions 
  • The candidate is encouraged to support in 1 to 2 projects around GRC each year and provide master data support to the wider global team throughout the year.  
  • The person is encouraged to be able to engage with global stakeholders and understand business requirements & solutions with minimal support. 
  • Part of Technology working group within Business Controls Team, responsible for maintaining controls master data, building and testing control monitoring scripts, and review user security reports


  • Degree educated or professional Internal Controls qualification (eg. CISA, CISSP, CIA, ACCA or equivalent).
  • 3-5 years, risk internal controls or audit experience with significant accounting firm or corporate industry experience.
  • Experience in global FMCG or similar dynamic operating environment is advantage.


  • Effective verbal and written communication skills with the ability to articulate control issues, risk, impact, and recommendations to management.
  • Good knowledge of internal controls practices, principles and procedures and corporate governance requirements for a global Group and knowledge in Internal Controls over Financial Reporting (ICoFR)
  • Critical problem solving, knowledge in analysing business data with attention to detail
  • Experience in internal or external audit, or other SOx testing of IT processes, and able to identify control gaps and provide recommendation to address the issue.
  • Experience in reviewing outsourced IT Operations and assessing various forms of Third-Party Assurance reports, e.g., SOC reports, for adequacy and impact on the services provided is a plus.
  • Controls related data analytics - in auditing context.
  • Experience with ERP systems such as SAP, and Salesforce, and GRC solutions would be a plus. 
  • Knowledge in data analytics/coding skills such as python, R or tools like Alteryx would be useful
  • Knowledge of SOx standard process, testing and reporting approaches would be an advantage.


  • Managing outcomes / support needed diplomatically
  • Ability to independently deliver projects and derive business value
  • Building good working partnerships with stakeholders (other functions within BAT example GRC team)
  • Liaison with third party SOx testing staff / IT support


At BAT we are committed to our Purpose of creating A Better Tomorrow. This is what drives our people and our passion for innovation. See what is possible for you at BAT.

  • Global Top Employer with 53,000 BAT people across more than 180 markets
  • Brands sold in over 200 markets, made in 44 factories in 42 countries
  • Newly established Tech Hubs building world-class capabilities for innovation in 4 strategic locations
  • Diversity leader in the Financial Times and International Women’s Day Best Practice winner
  • Seal Award winner – one of 50 most sustainable companies


Collaboration, diversity and teamwork underpin everything we do here at BAT. We know that collaborating with colleagues from different backgrounds is what makes us stronger and best prepared to meet our business goals. Come bring your difference!


A BAT está evoluindo em um ritmo totalmente
diferente de qualquer outra organização

Venha criar
“Um Amanhã Melhor” com a gente

Candidate-se hoje para nos ajudar a alcançar a neutralidade em carbono até 2030