Overview
As Technology Risk Services Manager, you will lead cyber and information security engagements within Grant Thornton’s Business Risk Services. You’ll own assignments, manage staff, and nurture client relationships to strengthen controls and governance. You will plan, execute, and report on IT internal audits, ensuring rigor and alignment with GT methodologies. This role offers high impact across global clients, with flexible working and a culture that values collaboration and growth.
Pay / Benefits
- flexible working options
- work-life balance
- inclusive culture
- opportunities for secondments
- engagement in charitable activities
- professional development
Responsibilities
- Lead allocated cyber and information security IT internal audits and develop staff
- Manage client relationships and deliver engagements exceeding expectations
- Lead client planning discussions and draft audit planning documents
- Execute fieldwork with appropriate testing and evidence gathering
- Present close-out meetings, summarise observations, and obtain client agreement
- Assist with financial management of client relationships (WIP, invoicing, budgets)
Key requirements
- Professional qualification (CISA, CISM, CISP, or similar) with post-qualification experience
- Proven ability to manage a large internal audit portfolio
- Experience scoping, delivering, and reporting on cyber and information security audits
- Knowledge of testing security controls (firewalls, cloud configs, network monitoring, antimalware)
- Understanding of cyber security governance, incident response processes, and third-party assurance
- Strong report writing and interview skills for client deliverables
- Solid knowledge of cyber security controls and frameworks (NIST, CIS, GDPR, etc.)
- Desirable security certifications (CISSP or CISM)
- Experience with GDPR and data protection processes
- Extensive use of audit software and Microsoft packages
- Experience managing audits across geographical and client boundaries
- leadership
- communication
- stakeholder management
- cyber and information security internal audits
- security controls testing (firewalls, cloud configurations, asset hardening)
- incident response processes
…
