Associate Director – Interne Kontrollsysteme und Assurance; m/w/d
Verfasst am 2026-10-10
-
Management
Risiko-Analyst, Compliance Analyst
- Full-time
- Remote Type:
Internal Audit
About Redcare Pharmacy: As Europe's No.1 e-pharmacy Redcare Pharmacy is powered by passionate teams and cutting-edge innovation. We strive to create a healthy collaborative work environment where every employee feels valued and inspired to contribute to our vision "Until every human has their health". If you're seeking a career that offers purpose and aligns with your values join us and start your #Redcareer today.
Job DescriptionAbout the role
We are looking for a Director, Internal Controls & Assurance to establish and lead our newly created Internal Controls & Assurance (IC&A) function.
This is a rare opportunity to build a company-wide function from the ground up at a fast-growing, listed European e-commerce and healthcare company. Reporting to our Chief Audit Executive, you will own the enterprise Internal Control Framework, its methodology and governance model, and the annual assurance cycle across financial, operational, technology, compliance and reporting domains.
As a second-line leader, you will set the standards, challenge control design and remediation, and give Management documented, evidence-based assurance over whether key controls are designed appropriately and operating effectively. Your work will directly support the Managing Board's annual assessment of the control environment. You will have a high degree of autonomy, work with leading GRC software (Audit Board/Optro), and lead and develop a small team that is set to grow.
About your tasks:
Build & Lead the IC&A Function
- Establish and lead Redcare Pharmacy's Internal Controls & Assurance function, including its mandate, governance, operating model, annual priorities and team capabilities.
- Develop and lead the IC&A team, decide when specialist or co-sourced expertise is needed, and continuously improve the scalability, automation and quality of the assurance process.
Framework & Methodology
- Own and maintain the enterprise Internal Control Framework, ensuring one consistent methodology connects risks, processes, controls, evidence and assurance across the company.
- Define and approve the control taxonomy, minimum evidence standards, design-assessment criteria, operating-effectiveness testing methodology, sampling principles and deficiency-rating framework.
- Together with Enterprise Risk Management, oversee risk-to-control mapping and drive the framework's expansion into Finance, Technology, HR, Operations, Pharmacy, Quality, Compliance, Privacy, Security, Sustainability and other business areas.
Assurance & Challenge
- Set the annual assurance scope and assessment plan based on risk, maturity, regulatory requirements and Management priorities.
- Review and approve significant control-design conclusions and deficiency judgements, so that assessments are consistent and well supported.
- Challenge Directors, senior leaders and executives where control design, evidence, ownership or remediation falls short, and resolve significant disagreements over ratings and corrective actions.
Reporting & Stakeholder Management
- Own Management reporting on the control environment, including dashboards, deficiency reporting and the annual Management Assurance Report to the Managing Board.
- Lead senior engagement with business leadership, control coordinators, Enterprise Risk Management, Internal Audit and External Audit, while keeping first-, second- and third-line responsibilities clear.
- Substantial experience in internal controls, risk assurance, internal audit, SOX/ICFR or a comparable control-assurance environment, including ownership or leadership of an enterprise control framework.
- Proven track record of establishing, transforming or significantly maturing an Internal Control Framework across multiple business domains, not only Finance.
- Advanced practical knowledge of control design, walkthroughs, operating-effectiveness testing, evidence evaluation, deficiency assessment and remediation governance.
- Sound judgement in evaluating significant deficiencies and the confidence to challenge senior executives.
- Strong understanding of the Three Lines Model.
- Strong leadership and communication skills, including people management and clear written reporting for executive and Board-level audiences.
- Experience in a listed, regulated, international or similarly complex environment.
- CIA certification preferred; CPA, ACCA, CISA or equivalent are also welcome.
- Familiarity with COSO/SOX, experience working with External Audit, and hands-on use…
(Wenn dieser Job tatsächlich in Ihrem Zuständigkeitsbereich liegt, verwenden Sie möglicherweise einen Proxy oder VPN, um auf diese Seite zuzugreifen. Um weiterzukommen, sollten Sie Ihre Verbindung zu einem anderen Mobilgerät oder PC wechseln).