Overview
In this role you lead technology internal audit and risk engagements within Grant Thornton’s Business Risk Services. You will manage client portfolios, deliver high-quality insights, and develop staff while aligning with the firm’s growth and inclusive culture. You’ll drive planning, scope, and reporting for complex tech audits and cloud initiatives, coordinating with senior stakeholders. This is a chance to shape IT risk work, expand cloud assurance capabilities, and contribute to transformation in a collaborative environment. You’ll work with cross-functional teams to help clients survive in a changing tech landscape.
Pay / Benefits
- flexible working options
- work-life balance
- inclusive culture
- opportunities for secondments
- charity fundraising and social impact
- supportive leadership
Responsibilities
- Lead allocated assignments and manage staff development to exceed client expectations
- Oversee delivery of technology internal audit and technology risk engagements and manage client portfolios
- Support business development and upsell services to existing clients
- Lead planning discussions and draft audit planning documents
- Provide SME input on engagements and ensure testing is thorough and evidence supports decisions
- Oversee and review junior staff work and support their development
- Conduct closing meetings with clients and draft reports summarising observations
- Present findings to Audit Committees and senior management
- Support development of new tech audit/risk service lines with emphasis on Cloud assurance
- Assist financial management of client relationships (WIP, invoices, margins, budgets)
- Lead the development of annual audit plans
Key requirements
- Professional qualification (CISA, CCAK, CCSK, CCSP, etc.) with post-qualification experience
- Experience managing a large portfolio of internal audit clients
- Experience scoping, delivering, and reporting technology internal audits
- Experience auditing large companies with complex technical matters
- Broad experience across cyber, network security, IT resilience, IT transformations, data protection, supplier management
- Strong cloud governance experience and cloud topics (security, data protection/privacy, availability, resilience, DR, cost, third-party management, change management)
- Experience auditing public cloud (AWS, Azure, Google Cloud) and/or private cloud (VMware)
- Knowledge of CSA Cloud Controls Matrix, well-architected frameworks, and Agile methodologies
- Experience with DevSecOps/CICD pipelines auditing, including release management and automation
- Experience with audit software and Microsoft packages
- Extensive network-building across regions and client organizations
- proactive
- strong client relationship management
- leadership and people development
- cloud governance and cloud security
- cybersecurity and network security
- IT resilience and disaster recovery
…
