
Internal IT Audit Manager
- London
- Permanent
- Full-time
- London Vicotria - 4 days in the office, 1 day of home office per week
- There may be a limited degree of travel required to both Europe and other jurisdictions.
- Lead End-to-End IT Audits: Plan, execute, and report on internal audits across infrastructure, cybersecurity, cloud platforms, and product led initiatives.
- Annual Risk Assessment & Planning: Partner with the Chief Internal Auditor and Head of Internal Audit in conducting the annual IT risk assessment and contribute to the development of the annual internal audit plan.
- Stakeholder Engagement: Build strong, trust-based relationships across business functions to ensure a collaborative and forward-looking audit practice.
- Technology Assurance Framework: Help define and enhance a technology assurance strategy aligned with IIA standards and industry best practices (e.g. ISO27001, NIST, COBIT).
- Regulatory Insight: Stay informed on evolving regulations (e.g. FCA PS21/3, DORA), and other industry developments impacting operational resilience and technology risk.
- Innovation & Curiosity: Proactively research emerging technologies, risks, and control solutions, maintaining a learning mindset and bringing new ideas to the audit approach.
- Proven experience managing and delivering IT internal audits in regulated industries or FinTech environments.
- Experience auditing or working in the First or Second Line of Defense IT, information security and operational risk functions.
- Knowledge of risk based auditing and risk management frameworks (e.g. ISO27001, NIST, COBIT, COSO).
- Able to work independently in a fast changing business environment and manage shifts in priorities.
- Ability to apply analytics, process automation and develop a data driven internal audit approach.
- Relevant professional certifications or industry accreditations (CISA, CISM, CIA, CISSP, AWS or GCP certifications etc.)
- Exposure to cloud environments (e.g. AWS, GCP), including knowledge of cloud security principles would be a plus.
- Demonstrated experience in third-party / vendor risk management and assurance reviews would be a plus.
- Degree qualified in computer science, information security, engineering or a quantitative discipline would be a plus.