Cyber Security Audit Manager leading audits in Group Audit function. Shape and manage audits, delivering high-quality independent assurance on effectiveness of cyber security controls.
Responsibilities
Audit Planning: planning a range of cyber security audits, requesting/selecting resources and liaising with stakeholders to discuss and propose scope and timelines.
Audit Execution: leading and managing audit delivery, delivering audits on time and within budget, ensuring quality of the audit file and coverage of agreed scope, ensuring compliance with audit methodology, and providing progress updates to the Portfolio Lead, Head of Audit and Audit Directors.
Taking the lead on audit report preparation and agreement with stakeholders.
Oversee the follow-up and subsequent remediation of audit issues identified.
Coaching and supporting colleagues.
Providing SME insights and support across the Audit function.
Driving personal growth and continuous improvement.
Requirements
Industry best-practices - Strong technical knowledge and experience of Information, Cyber and Physical Security best practices, threats, risks, frameworks and standards (e.g. NIST, MITRE and ISO27001).
Related cyber/ information security qualifications valued e.g. Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH).
Audit and/ or risk and controls experience – Practical experience of assessing cyber and technology risks and key controls (e.g. vulnerability management, network security, security operations, identity and access management), documenting appropriate test plans to deliver on audit objectives.
Curiosity and interest in new technology - Demonstrable curiosity and understanding of the emerging technologies shaping the risk landscape (inc. AI, Digital Ledger Technology, Quantum).
Data skills - Experience of data analytics tools and processes, ability to assimilate a range sources of data and complex information to effectively problem solve and draw relevant conclusions.
Stakeholder management - The ability, skill, and experience to effectively manage senior stakeholder relationships, building credibility and trust.
Project management – Solid project management skills and a focus on delivery of the audit plan are critical and applicants should be self-starting and proactive.
Team leadership – Leadership and collaboration skills are key to achieving the Group and function’s objectives. Applicants should be comfortable both leading and participating in teams, supporting team members and management to deliver on team and personal goals.
And any experience of these would be really useful: Technically proficient, with hands-on technology experience (e.g. security testing, ethical hacking).
Ability to use and/ or develop technical skills.
Solid understanding of technology infrastructure, networks, cloud technologies and related architecture and security frameworks.
Knowledge of software development and software engineering methods, practices, and tools across the software development lifecycle.
Experience and ability to develop innovative tools to support audit testing and continuous auditing, including the use of AI.
Benefits
A generous pension contribution of up to 15%
An annual performance-related bonus
Share schemes including free shares
Benefits you can adapt to your lifestyle, such as discounted shopping
30 days’ holiday, with bank holidays on top
A range of wellbeing initiatives and generous parental leave policies
Field Marketing Manager at Upwind Security leading regional marketing initiatives in the US. Responsible for planning events and collaborating with sales to enhance brand presence.
Senior Security Engineer securing cloud infrastructure, AI platforms, and applications for Medical Guardian. Leading security initiatives and incident response efforts in a hybrid work environment.
Business Consultant for Security Electronics focused on sales through active prospection and client engagement. Responsibilities include negotiations and collaboration with internal teams in Brazil.
Security Officer maintaining safety and security for Chicago Botanic Garden. Engaging with visitors and enforcing rules while providing assistance and emergency response.
Cybersecurity Generalist at CBTW in Berlin, handling security analyses and risk assessments. Collaborating on Security Governance and strategic projects with a highly motivated team.
Machine Learning Subject Matter Expert providing technical leadership in ML initiatives. Collaborating with teams to deliver scalable ML models and ensure best practices across the organization.
Enterprise Security Architect securing and modernizing our EHR platform. Collaborating with cross - functional teams to integrate security practices into development processes.
Director of Business Unit Security Officer leading risk assessments and safeguarding IT solutions across Canadian Technology Business Units. Collaborating with the Head of Information Security and Risk Management for compliance and security awareness.
Health and Safety Assistant responsible for analyzing workplace safety documentation and training service providers on compliance actions. This role involves direct training and guidance for clients.