Information Security and IT Auditor Contractor
We're partnered with a growing financial services organisation seeking an experienced Information Security Risk & Audit Consultant to support key risk, governance, audit, and third-party risk management initiatives.
This role is ideal for someone with a background in Information Security Governance, Technology Risk, IT Audit, Cyber GRC, or Third-Party Risk Management who enjoys working across a broad range of security and compliance activities within a regulated environment.
Responsibilities
- Support internal and external IT audits and regulatory reviews
- Gather, validate, and manage audit evidence and documentation
- Perform control assessments and assist with remediation activities
- Maintain and enhance information security policies, standards, and procedures
- Conduct third-party and vendor risk assessments
- Review security questionnaires, SOC reports, and supporting documentation
- Track security findings, risks, and remediation efforts
- Assist with risk assessments and control evaluations
- Produce reports, metrics, presentations, and management updates
- Partner with business and technology stakeholders to improve risk and control processes
- Contribute to ongoing information security governance and compliance initiatives
Required Experience
- Experience within Information Security, Technology Risk, IT Audit, Cyber GRC, Compliance, or Third-Party Risk Management
- Strong understanding of information security controls and risk management practices
- Experience supporting audits, control testing, or regulatory reviews
- Exposure to vendor risk assessments and third-party risk programmes
- Ability to review and assess security documentation and control environments
- Excellent communication, stakeholder management, and documentation skills
- Experience working within regulated industries such as financial services, fintech, insurance, or consulting environments
Preferred Experience
- Knowledge of:
- NIST Cybersecurity Framework (CSF)
- NIST 800-53
- SOC 1 / SOC 2
- PCI-DSS
- ISO 27001
- SOX controls
- Experience with Governance, Risk & Compliance (GRC) platforms
- Background within financial services or highly regulated environments
FAQs
Congratulations, we understand that taking the time to apply is a big step. When you apply, your details go directly to the consultant who is sourcing talent. Due to demand, we may not get back to all applicants that have applied. However, we always keep your CV and details on file so when we see similar roles or see skillsets that drive growth in organisations, we will always reach out to discuss opportunities.
Yes. Even if this role isn’t a perfect match, applying allows us to understand your expertise and ambitions, ensuring you're on our radar for the right opportunity when it arises.
We also work in several ways, firstly we advertise our roles available on our site, however, often due to confidentiality we may not post all. We also work with clients who are more focused on skills and understanding what is required to future-proof their business.
That's why we recommend registering your CV so you can be considered for roles that have yet to be created.
Yes, we help with CV and interview preparation. From customised support on how to optimise your CV to interview preparation and compensation negotiations, we advocate for you throughout your next career move.