Lead IT Auditor & Tech Risk Expert reporting to the Group Risks & Control Department.
Conduct complex IT audits, advise on cybersecurity and compliance, and drive improvements in IT risk governance.
Responsibilities
As a Lead IT Auditor & Tech Risk Expert, you will play a pivotal role in strengthening the Group’s control environment and technology resilience.
Reporting to the Group Risks & Control Department, you will independently lead complex IT audit engagements while serving as a senior expert on technology risks, cybersecurity, compliance, and governance.
You will join a team that bridges Permanent Control (risk management, compliance, cybersecurity, data protection) and Periodic Control (internal audit), enabling cross-functional work and direct contributions to the Group’s risk governance and long-term stability.
Design, plan, and independently execute IT audit assignments covering the Group's critical systems, infrastructure, applications, cloud environments, and processes.
Assess the robustness of IT controls and test their application: access management, system security, backups and restoration, configuration, business continuity, change management, logging, and more.
Perform in-depth technical tests, analyze root causes, and challenge the operational effectiveness of control mechanisms.
Track the implementation of audit recommendations and remediation plans and evaluate their effectiveness over time.
Collaborate with cybersecurity, compliance, internal control, internal audit teams, and IT to ensure a comprehensive view of IT and operational risks.
Assess alignment of IT practices with internal policies, regulatory requirements (GDPR, NIS2, etc.), and recognized governance and control frameworks (ISO 27001, NIST, COBIT, ITIL).
Identify and analyze technology-related risks affecting data security, availability, integrity, and confidentiality.
Maintain a high level of expertise in technologies, architectures, cyber threats, standards, and audit methodologies.
Act as an internal expert on IT audit, technology security, and risk management topics.
Propose areas of innovation to modernize IT auditing and deepen analytical capabilities.
Requirements
5–8+ years of relevant experience in IT audit, cybersecurity, IT risk management, or technology assurance.
Strong knowledge of IT governance, risk management, and internal control frameworks (e.g., COBIT, ITIL, ISO 27001, NIST).
Solid understanding of IT infrastructure, networks, databases, cloud environments, and cybersecurity principles.
Ability to analyze complex IT systems and identify operational and security risks.
Proven experience conducting IT audits, including planning, testing, and reporting.
Familiarity with regulatory and compliance standards (e.g., GDPR, PCI DSS, NIS2).
Excellent analytical and problem-solving skills with a detail-oriented mindset.
Strong written and verbal communication skills for clear and effective reporting and presentation of audit results.
Ability to work independently while collaborating with IT and business teams.
Degree in Computer Science, Information Systems, Cybersecurity, Engineering, or a related field.
Benefits
Variable bonus
Employee profit-sharing & incentive schemes
Remote work available up to 2 days per week
Online language-learning platform
CSE (employee representative committee) benefits and related perks
CESU vouchers (employee service vouchers) and holiday vouchers
Access to company catering and connected fridges (Foodles, Kumo, Bolk)
Senior Clinical Quality Auditor performing internal audits, analyzing results, and collaborating with clinical operations teams at DaVita. Assisting leadership with daily operations of the Clinical Quality Auditing team.
Lead IT Auditor managing complex IT, information security, and integrated audits at Navy Federal. Collaborating with audit staff and stakeholders to ensure effective auditing practices.
Staff Auditor I executing financial, operational, compliance, and IT audits while improving risk management processes. Collaborating with stakeholders and reporting findings for enhanced effectiveness.
Internal Auditor for PromptCare Companies responsible for managing documents and audits. Ensuring compliance and communication with team, enhancing documentation processes.
Internal Staff Auditor conducting audits related to payments and the card industry at Fiserv. Collaborating with business departments to ensure compliance with policies and regulations.
Supplier Quality Audit Lead managing GMP and Quality Systems compliance audits for GSK manufacturing suppliers. Responsible for maintaining supplier compliance and effective communication with stakeholders.
Doc Auditor responsible for processing and reviewing closing - related documentation at ServiceLink. Supports Doc Auditors and ensures compliance with company and client requirements.
Conducting premium audits for various coverage lines including Workers Compensation and General Liability. Ensuring compliance and maintaining regulatory standards as part of the audit process.
Business Process Auditor Associate providing assurance and advisory services within a health plan environment. Gaining experience in evaluating governance, risks, and controls across health plan operations.