IT Risk Advisory - Manager
Job description
About the role
You will manage the full lifecycle of IT risk and assurance engagements for a diverse portfolio that spans FTSE 100 and 250 enterprises, mid-cap organizations, and high-growth start-ups. In this capacity, you will act as a trusted advisor to senior management, guiding them through complex regulatory landscapes and emerging technology challenges. You will own the delivery of IT Internal Audit, SOX compliance testing, and attestation readiness activities, ensuring robust control environments. Furthermore, you will identify value-add opportunities within business processes and translate technical findings into clear, actionable recommendations. You will also prepare and present findings in a professional format and represent the firm in critical Audit Committee interactions. Developing and managing high-level client relationships will be central to your success, alongside driving business development within the risk advisory practice. Finally, you will contribute to the internal growth of the team by mentoring staff and participating in the continual improvement of delivery standards.
Key facts
What you'll do
Lead the scoping and planning of IT risk engagements, translating ambiguous business needs into structured audit and assurance approaches.
Perform detailed reviews of IT controls testing, process narratives, flow charts, and procedural documentation to assess design and operational effectiveness.
Evaluate and approve engagement scope, project plans, risk assessments, testing methodologies, and specific procedures in collaboration with senior team members.
Execute analytical procedures to identify control weaknesses, gaps, and opportunities for improvement that deliver tangible value to the client.
Prepare complex reports and professional presentations that articulate findings, root causes, and remediation strategies for diverse audiences.
Facilitate and participate in meetings with Audit Committees, executive leadership, and external auditors to discuss results and remediation plans.
Develop and manage strategic relationships with client management, ensuring clear communication and alignment on objectives and outcomes.
Manage the economics of the engagement, including resource allocation, time tracking, and profitability metrics for the engagement.
Proactively drive business development initiatives by building a pipeline of opportunities within existing and new client relationships.
Champion the development of junior team members through coaching, feedback, and practical guidance on technical and soft skills.
Own the implementation of continual improvement initiatives for the Risk Advisory practice, including updating methodologies and quality checks.
Ensure adherence to professional standards and regulatory requirements, such as GDPR and ISO 27001, throughout the lifecycle of the engagement.
Leverage frameworks like COSO, SOC 1, and SOC 2 to evaluate the design and operating effectiveness of controls in various environments.
Act as a liaison between internal teams and external stakeholders, including auditors and certification bodies, to ensure smooth execution.
Requirements
You must hold a professional certification such as Certified Public Accountant, Chartered Global Management Accountant, Certified Internal Auditor, Certified Information Systems Auditor, or Certified Information Security Manager.
You must bring a minimum of five years of progressive experience in audit, advisory, IT audit, systems implementations, or Information Security roles.
You must demonstrate excellent interpersonal, written, and oral communication skills that enable effective collaboration with senior stakeholders.
You must possess the ability to assimilate quickly into diverse teams and adapt to varying client cultures and expectations.
You must have strong technical skills and a working knowledge of SOX IT General Controls, COSO frameworks, SOC 1 reporting, and SOC 2 principles.
You must maintain awareness of ISO 27001 information security management, GDPR data protection regulations, and other relevant industry standards.
You must exhibit effective analytical and critical thinking abilities to assess complex problems and derive actionable insights.
You must have an entrepreneurial nature, be self-motivated, uphold the highest ethical standards, and be dependable in managing multiple priorities.
Nice to have
You may have prior experience in business process improvement projects focused on risk, control, and compliance objectives.
You may have exposure to preparing materials for external audits or assisting with certification readiness exercises.
You may have a working knowledge of audit management tools and evidence collection platforms used in assurance engagements.
Practical notes
This is a full-time role based in London, England.
The position requires travel to client sites as necessary, and candidates must be willing to travel domestically and internationally.
Visa sponsorship may be considered for eligible candidates depending on role and client requirements.
Candidates must meet the specified timelines for onboarding and project start dates where applicable.