Audit Manager - Cyber Security
Listed on 2026-02-27
-
IT/Tech
Cybersecurity, IT Project Manager, IT Consultant, Data Security
Job Details
End Date: Thursday 05 March 2026
Salary Range: £89,739 - £99,710
Salary: £89,739 - £99,710 (salary range may vary according to location)
Flexible Working Options: Hybrid Working, Job Share
We support flexible working – for more information on flexible working options
Job DescriptionJob Title: Audit Manager - Cyber Security
Location(s): London, Bristol & Edinburgh
Hours: Full time
Working Pattern: Our work style is hybrid, which involves spending at least two days per week, or 40% of our time, at one of our office sites.
About this opportunityAn exciting opportunity has become available to join the Group Audit function and the Technology Risk audit team as a Cyber Security Audit Manager. This role provides the opportunity to shape as well as lead audits, harnessing a deep understanding of cyber security and technology risks to deliver high quality independent assurance on the effectiveness of controls.
Responsibilities- Audit Planning: planning a range of cyber security audits, requesting/selecting resources and liaising with stakeholders to discuss and propose scope and timelines.
- Audit Execution: leading and managing audit delivery, delivering audits on time and within budget, ensuring quality of the audit file and coverage of agreed scope, ensuring compliance with audit methodology, and providing progress updates to the Portfolio Lead, Head of Audit and Audit Directors.
- Audit Report Preparation: taking the lead on audit report preparation and agreement with stakeholders.
- Follow-up: overseeing the follow‑up and subsequent remediation of audit issues identified.
- Coaching & Support: coaching and supporting colleagues.
- SME Insights: providing SME insights and support across the Audit function.
- Continuous Improvement: driving personal growth and continuous improvement.
We’re on an exciting journey and there couldn’t be a better time to join us. The investments we’re making in our people, data, and technology are leading to innovative projects, fresh possibilities, and countless new ways for our people to work, learn, and thrive.
What you’ll need- Industry best‑practices: strong technical knowledge and experience of Information, Cyber and Physical Security best practices, threats, risks, frameworks and standards (e.g. NIST, MITRE and ISO
27001). Related cyber/ information security qualifications valued e.g. Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH). - Audit and/or risk and controls experience: practical experience of assessing cyber and technology risks and key controls (e.g. vulnerability management, network security, security operations, identity and access management), documenting appropriate test plans to deliver on audit objectives. Applicants should be able to identify control gaps and clearly articulate these to senior stakeholders.
- Curiosity and interest in new technology: demonstrable curiosity and understanding of the emerging technologies shaping the risk landscape (inc. AI, Digital Ledger Technology, Quantum).
- Data skills: experience of data analytics tools and processes, ability to assimilate a range sources of data and complex information to effectively problem solve and draw relevant conclusions.
- Stakeholder management: the ability, skill, and experience to effectively manage senior stakeholder relationships, building credibility and trust.
- Project management: solid project management skills and a focus on delivery of the audit plan are critical and applicants should be self‑starting and proactive.
- Team leadership: leadership and collaboration skills are key to achieving the Group and function’s objectives. Applicants should be comfortable both leading and participating in teams, supporting team members and management to deliver on team and personal goals.
- Technically proficient, with hands‑on technology experience (e.g. security testing, ethical hacking). Ability to use and/or develop technical skills.
- Solid understanding of technology infrastructure, networks, cloud technologies and related architecture and security frameworks.
- Knowledge of software development and software…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: