About this role
This role within Risk, Audit & Assurance focuses on IT and operational audits to strengthen governance and regulatory compliance. It supports the development of audit plans across cybersecurity, data risk, and operational processes. The position partners with IT, Finance, and Operations teams to enhance enterprise risk resilience.
Day-to-day work includes planning and executing IT audits on system implementations, cybersecurity, artificial intelligence, and IT general controls. You will assess compliance with GDPR, NIS2, and the EU AI Act while identifying vulnerabilities and tracking remediation actions.
The team works closely with senior leadership to implement risk preparedness frameworks and embed mitigating controls across functions. Collaboration extends to third-party risk assessments and business continuity planning in a hybrid environment.
Professional development opportunities support growth in risk management practices and audit delivery. The role promotes a risk-aware culture while delivering high-quality insights to improve operational efficiency and control effectiveness.
Requirements
- Experience in IT audit, risk management, or internal audit within a complex organisation.
- Strong understanding of IT risk domains including cybersecurity, data governance, and IT controls.
- Knowledge of regulatory frameworks such as GDPR, NIS2, and EU AI Act is preferred.
- Proven ability to plan and execute audits independently and deliver high-quality insights.
- Strong analytical, problem-solving, and stakeholder management skills.
- Ability to influence and collaborate with cross-functional teams.
- Professional certifications such as CISA, CRISC, or CIA are advantageous.
- Fluent in English, both written and spoken.
Responsibilities
- Support the development and delivery of the annual IT and data risk audit plan.
- Plan and execute IT audits covering system implementations, cybersecurity, artificial intelligence, ITGCs, and third-party risk.
- Assess compliance with regulations including EU AI Act, NIS2, and GDPR.
- Identify system vulnerabilities and control gaps with actionable recommendations.
- Plan, lead, and deliver operational audits across manufacturing, security, data privacy, and support functions.
- Support implementation of a risk preparedness and resilience framework.
- Partner with stakeholders to enhance governance over cybersecurity, disaster recovery, and AI risk management.
Benefits
- Flexible benefits package
- Opportunities for learning and professional development
- Collaborative and inclusive working environment
- Hybrid working arrangement (3 days from office)
Similar roles

Senior IT Audit Manager
4d4 days agoVanguard
London, GB · Full-time · £85,000 – £115,000

Data & AI Risk Analyst
4d4 days agoQBE Insurance
London, GB · Full-time · £48,000 – £68,000

Technology Risk Analyst
1w1 week agoPacific Life Re
London, GB · Full-time · £42,000 – £55,000

IT Internal Auditor
3w3 weeks agoSumUp
London, GB · Full-time · £65,000 – £90,000
