IT Risk and Cyber Controls specialist
Listed on 2026-08-30
-
IT/Tech
Cybersecurity, IT Business Analyst, Information Security & Data Protection, IT Consultant
- Birmingham office 3 days per week hybrid working model
- Unfortunately this role cannot sponsor at this time.
Audit and Risk Recruitment are delighted to be partnering with a FTSE 30 business to recruit an IT Risk and Cyber Controls advisor. This is a rare opportunity to join a high-performing, forward-looking organisation at a pivotal stage of its IT and governance evolution.
About the RoleWe're looking for a strategic and proactive IT Risk and Cyber Controls advisor help lead the development of a forward-thinking risk and controls framework. This role offers significant autonomy and influence and you’ll have rein to shape the direction of IT risk and controls across the organisation, aligned with regulatory expectations including Provision 29 of the UK Corporate Governance Code, working closely with the IT controls manager and advisor alongside senior stakeholders across the business.
You’ll be instrumental in embedding a strong IT controls and Cyber culture, collaborating across teams to build a resilient and secure technology environment that supports the business’s growth and governance ambitions. Backgrounds in IT SOX, ITGCs, IT Risk, IT controls and Cyber controls in a FTSE 250 business and/or professional services firm would be beneficial.
What You'll Be Doing- Lead the design and implementation of a fit-for-purpose IT Controls, Cyber controls and IT Risk framework from the ground up.
- Embed a risk culture aligned with Provision 29, ensuring robust internal controls for effective risk management.
- Strengthen governance through policies, standards, and control documentation
- Monitor control effectiveness and drive remediation of deficiencies
- Lead monthly IT control reporting and governance forums
- Provide oversight across key cyber domains (DR, BCP, vulnerability management, patching)
- Support Internal Audit and external assurance activity
- Deliver insight on emerging risks and continuous improvement opportunities
- Identify, assess, and mitigate IT risks, covering cybersecurity, data privacy, infrastructure, and operational technology.
- Work collaboratively with technology and business units to integrate risk considerations into all projects and operations.
- Stay ahead of evolving threats and industry best practices.
- Lead training and awareness initiatives across the organisation to strengthen understanding and ownership of IT risk.
- Experience in IT Risk, Audit, or Governance
- Knowledge of control frameworks (IT SOX, ICFR, UK Corporate Governance Code)
- Strong understanding of IT controls (access, change, operations)
- Cyber controls experience/exposure to cyber frameworks such as NIST, COBIT and ISO
27001 - Experience working in complex or decentralised environments
- Excellent communication and ability to challenge constructively
- SAP knowledge
- Experience with automation / AI tools (e.g. Copilot, ChatGPT)
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: