Senior IT Risk & Cyber Audit Consultant

Required start date

ASAP

Duration

6-12 months (renewable)

Reason this role cannot be provided by off-shore resource

SC/DV Clearance required, on-site stakeholder engagement, European presence mandatory

Clearance level required: SC (Secret) or DV (Developed Vetting) depending on project scope

Hybrid - 60% on-site at client locations, 40% remote. Regular travel to UK financial services and regulated sector client sites.

Location/s to be visited if applicable: London, Manchester, Edinburgh, Dublin, Frankfurt, Milan (primary EMEA hubs)

Project name/description: DORA & Operational Resilience Programme - multi-site financial services cyber and operational risk audit engagement across UK and EMEA regulated clients

Deliverables - required for SoW and to measure fulfilment of role:

Design and execution of cyber audit engagements - assessing IT General Controls (ITGC), Identity & Access Management (IAM), Change Management, and Cyber Resilience frameworks

Technical ownership of cybersecurity governance assessments aligned with DORA, FINMA Circular 23/1, HKMA C-RAF, and ISO 27001 standards

Third-party risk assessment and vendor security dependency mapping for critical suppliers and ICT service providers

Cyber control assessments - process mapping, design effectiveness testing, operating model documentation for Firewall rule bases, VPN configurations, network segregation controls

Operational resilience reviews - identifying control weaknesses, resilience gaps, and compliance issues across critical IT domains

Senior technical escalation point for cybersecurity change management, incident response coordination, and remediation tracking

Client-facing reporting - translating complex technical findings into risk-focused, management-ready assessments aligned with regulatory expectations

Core competencies - Must Have

Demonstrated experience in IT Risk, Cyber Audit, and/or Operational Resilience projects for regulated financial services, banking, or insurance clients

Solid knowledge of cybersecurity governance frameworks: ISO/IEC 27001, NIST CSF, NIST 800-53, COBIT, and emerging regulatory standards (DORA, FINMA, HKMA, SWIFT CSCF)

Hands-on experience with IT General Controls (ITGC), Identity & Access Management (IAM), and Change Management processes

Experience in third-party risk assessment, vendor security management, and critical supplier dependency mapping

Strong ability to translate complex cybersecurity concepts into executive summaries and risk-focused client communication

UK or EU presence (for client engagement, travel, and time-zone alignment)

Core competencies - Nice to Have

CISA (Certified Information Systems Auditor) or CRISC certification

ISO 27001 Lead Auditor certification

Experience with cryptographic key management and network integrity/segregation testing

SWIF CSP or cyber resilience assessment background

Internal Audit function support or regulatory compliance experience

Big Four risk assurance background (PwC, Deloitte, EY, KPMG)

Job Details

Company
Saunders Scott
Location
London, United Kingdom
Employment Type
Contract
Salary
GBP Annual
Posted