We're partnered with a growing financial services organisation seeking an experienced Information Security Risk & Audit Consultant to support key risk, governance, audit, and third-party risk management initiatives.
This role is ideal for someone with a background in Information Security Governance, Technology Risk, IT Audit, Cyber GRC, or Third-Party Risk Management who enjoys working across a broad range of security and compliance activities within a regulated environment.
Responsibilities
- Support internal and external IT audits and regulatory reviews
- Gather, validate, and manage audit evidence and documentation
- Perform control assessments and assist with remediation activities
- Maintain and enhance information security policies, standards, and procedures
- Conduct third-party and vendor risk assessments
- Review security questionnaires, SOC reports, and supporting documentation
- Track security findings, risks, and remediation efforts
- Assist with risk assessments and control evaluations
- Produce reports, metrics, presentations, and management updates
- Partner with business and technology stakeholders to improve risk and control processes
- Contribute to ongoing information security governance and compliance initiatives
Required Experience
- Experience within Information Security, Technology Risk, IT Audit, Cyber GRC, Compliance, or Third-Party Risk Management
- Strong understanding of information security controls and risk management practices
- Experience supporting audits, control testing, or regulatory reviews
- Exposure to vendor risk assessments and third-party risk programmes
- Ability to review and assess security documentation and control environments
- Excellent communication, stakeholder management, and documentation skills
- Experience working within regulated industries such as financial services, fintech, insurance, or consulting environments
Preferred Experience
Knowledge of:
NIST Cybersecurity Framework (CSF)
NIST 800-53
SOC 1 / SOC 2
PCI-DSS
ISO 27001
SOX controls
Experience with Governance, Risk & Compliance (GRC) platforms
Background within financial services or highly regulated environments