Intenal Auditor
Internal Auditor – ISMS & BCMS
Location: Remote with occasional UK travel to visit clients in London
Contract: 4 months
Type: Contract / Consultancy
We are supporting a leading organisation with the appointment of an experienced Internal Auditor to provide independent assurance across its Information Security Management System (ISMS) and Business Continuity Management System (BCMS).
This is a defined 4-month project focused on developing a risk-based audit framework, delivering three internal audits and establishing a repeatable model for future audit cycles.
Key Responsibilities
- Develop a risk-based multi-year ISMS & BCMS internal audit plan.
- Create the detailed 2026 audit programme, including scope, objectives, methodology and timetable.
- Plan and conduct three independent internal audits.
- Review documentation, evidence and controls and conduct stakeholder interviews and walkthroughs.
- Identify and validate findings, risks and areas of non-conformity.
- Produce clear, evidence-based audit reports and prioritised remediation recommendations.
- Establish a repeatable annual audit model, including planning, methodology, reporting and remediation tracking.
- Develop supporting templates and documentation and provide knowledge transfer.
- Work independently while maintaining objectivity and professional challenge.
Essential Requirements
- ISO/IEC 27001:2022 Lead Auditor certification.
- ISO 22301:2019 Lead Auditor certification.
- Demonstrable experience conducting internal audits against both standards.
- Experience developing risk-based ISMS and BCMS audit programmes.
- Strong understanding of ISMS and BCMS governance, implementation and assurance.
- Excellent audit planning, reporting and stakeholder management skills.
Evidence of both current Lead Auditor certifications will be required.
Desirable
- Experience auditing complex or international organisations.
- Experience supporting ISO certification or surveillance audits.
- Information security and business continuity risk management experience.
- Experience with Microsoft 365, Azure and cloud environments.
- Consultancy, Big 4 or specialist assurance experience.
- Experience reporting to senior management, Risk Committees or Boards.
Key Deliverables
The successful contractor will deliver:
- Multi-year ISMS & BCMS audit plan.
- Detailed 2026 audit programme.
- Three completed internal audits and formal reports.
- Prioritised remediation recommendations.
- Repeatable annual audit framework, methodology and templates.
- Knowledge transfer and handover.
This is an excellent opportunity for an experienced ISO 27001 & ISO 22301 Internal Auditor to take ownership of a defined project and help establish a long-term assurance framework.
Please note: This is a 4-month project-based assignment with occasional travel to client locations in the UK.