Senior IT Risk & Cyber Audit Consultant
Required start date
ASAP
Duration
6-12 months (renewable)
Reason this role cannot be provided by off-shore resource
SC/DV Clearance required, on-site stakeholder engagement, European presence mandatory
Clearance level required: SC (Secret) or DV (Developed Vetting) depending on project scope
Hybrid - 60% on-site at client locations, 40% remote. Regular travel to UK financial services and regulated sector client sites.
Location/s to be visited if applicable: London, Manchester, Edinburgh, Dublin, Frankfurt, Milan (primary EMEA hubs)
Project name/description: DORA & Operational Resilience Programme - multi-site financial services cyber and operational risk audit engagement across UK and EMEA regulated clients
Deliverables - required for SoW and to measure fulfilment of role:
Design and execution of cyber audit engagements - assessing IT General Controls (ITGC), Identity & Access Management (IAM), Change Management, and Cyber Resilience frameworks
Technical ownership of cybersecurity governance assessments aligned with DORA, FINMA Circular 23/1, HKMA C-RAF, and ISO 27001 standards
Third-party risk assessment and vendor security dependency mapping for critical suppliers and ICT service providers
Cyber control assessments - process mapping, design effectiveness testing, operating model documentation for Firewall rule bases, VPN configurations, network segregation controls
Operational resilience reviews - identifying control weaknesses, resilience gaps, and compliance issues across critical IT domains
Senior technical escalation point for cybersecurity change management, incident response coordination, and remediation tracking
Client-facing reporting - translating complex technical findings into risk-focused, management-ready assessments aligned with regulatory expectations
Core competencies - Must Have
Demonstrated experience in IT Risk, Cyber Audit, and/or Operational Resilience projects for regulated financial services, banking, or insurance clients
Solid knowledge of cybersecurity governance frameworks: ISO/IEC 27001, NIST CSF, NIST 800-53, COBIT, and emerging regulatory standards (DORA, FINMA, HKMA, SWIFT CSCF)
Hands-on experience with IT General Controls (ITGC), Identity & Access Management (IAM), and Change Management processes
Experience in third-party risk assessment, vendor security management, and critical supplier dependency mapping
Strong ability to translate complex cybersecurity concepts into executive summaries and risk-focused client communication
UK or EU presence (for client engagement, travel, and time-zone alignment)
Core competencies - Nice to Have
CISA (Certified Information Systems Auditor) or CRISC certification
ISO 27001 Lead Auditor certification
Experience with cryptographic key management and network integrity/segregation testing
SWIF CSP or cyber resilience assessment background
Internal Audit function support or regulatory compliance experience
Big Four risk assurance background (PwC, Deloitte, EY, KPMG)