Your search query
Associate Director - IT Internal Audit Financial Services - (Banking, Insurance, Asset & Wealth Management)
Qualifications - CISA/CISM
Location - London hybrid working
Salary - £100,000-£110,000 base
Are you an IT auditor that focuses on Internal Audit? We have a brand new role due to business growth based in London.
Have you had experience with financial services and want to focus on more AI and data analytics driven work?
Want to be apart of a fast growing team, great culture and a team that is supportive and inclusive of one another?
If you said yes to the above, keep reading below.
The role requirements:
- Own and lead complex client engagements across data governance, AI governance, AI model testing, and analytics internal audit / risk within Financial Services, managing a significant portfolio of client relationships at senior stakeholder level.
- Lead strategic planning conversations with senior client stakeholders and audit committees, and oversee the preparation of terms of reference, audit plans, and engagement frameworks.
- Act as the firm's subject matter expert in data governance, AI governance, AI model testing, and data analytics- providing authoritative input into engagements, overseeing fieldwork performed by junior and mid-level team members, and ensuring all work is performed in accordance with the firm's methodologies, with sufficient and appropriate testing and evidence to support key decisions.
- Assist with the financial management of client relationships, including monitoring WIP, raising invoices, ensuring an adequate margin is achieved on engagements, and preparing budgets.
The right candidate will need:
- Come from a previous consulting background and have financial services experience with banking, insurance or asset management
- Be able to access the London office x3 per week
- Knowledge and some experience of AI, Data Governance, AI Assurance
- Lead large teams and inspire others
- Able to develop the business, previous experience of Business Development would be key.
Reach out to me at Sheena@astrumsearch.com to find out more!
Risk Assurance Manager
London
Hybrid Working
Market Value depending on experience!
ACA/ACCA/CIA/IIA Qualified - Essential
Right to work - Essential
Do you want to be apart of a fast growing practice that has an amazing team culture? Yes, I said it. You're in a place where you can have both! This firm is going through an fast growth phase and now is the time to join!
Sitting with the senior leaders, they are certain to maintain the culture of the team and business.
You will be client facing and expected to run a client portfolio as well as, lead a team!
Candidates must be qualified, have passion for wanting to grow their career and be proactive.
Candidates must hold the right to live and work in the UK as sponsorship is not on offer.
If you want to know more, reach out to me at Sheena@astrumsearch.com
Data, MI & Assurance Manager - Job Description
EAT | Enterprise Assurance Transformation
Data, MI & Assurance Manager | Job Description Page 1
Role Profile
JOB TITLE ICFR Lead
LOCATION United Kingdom
FUNCTION / DEPARTMENT Financ e | EAT – SOX Imple m e nta ti on
REPORTING TO Head of Risk, Control & Gover na nc e
DIRECT REPORTS Financ e Analyst / ICFR Analyst
KEY STAKEHOLDERS UK financ e and sector leader shi p; Corpor at e Gover na nc e ; proce ss and
control owner s across the busine ss; Group Financi al Control ; Internal Audit; External Audit; IT / ERP (CIO) teams
Role Overview
Compass Group aims to operate a robust UK Corporate Governance Code control environment and, as part of this, seeks to achieve control standards over its internal controls over financial reporting (ICFR) aligned with US SOX. The overall ICFR programme is led by Group Financial Control in a proportionate and scalable way, with this role responsible for driving its design, implementation and embedding across the UK business.
The ICFR Lead is a senior, hands-on leadership role responsible for driving the design, implementation and embedding of a SOX-standard ICFR framework across a large and complex UK business. Operating as part of the Second Line of Defence and working to the Group ICFR framework, the role leads the UK ICFR journey, from first-year implementation planning through to a mature, sustainable control environment, and is the UK business’s senior point of expertise and challenge on financial controls. As the framework matures, the role also improves the efficiency and effectiveness of the control environment through process improvement and automation, and provides a robust challenge and expertise on the design and implantation of controls.
This role calls for an individual who can make an immediate impact and deliver from the outset. The successful candidate will bring extensive, recent and hands-on experience of implementing SOX to a full 404 standard, including genuine in-house experience of running a first-year implementation, not solely an external audit or advisory perspective. They will have the calibre, gravitas and technical depth the programme demands, and the leadership presence to set direction, influence and challenge senior stakeholders, and support the business on the journey.
While building and leading a team, the ICFR Lead will remain willing to operate hands-on and engage directly in the detail of delivery, including walking processes, drafting control matrices, testing controls and remediating issues alongside the business.
Key Responsibilities
Leading the UK ICFR Journey
• Lead the delivery of the SOX-standard ICFR framework across the UK business, working to the Group ICFR programme and methodology and setting the local plan, milestones and priorities for the first-year implementation and beyond.
• Act as the senior point of expertise on ICFR for the UK business, providing a robust second-line opinion and expert direction, challenge and decision-making on control design, scoping and remediation.
• Drive efficiency and effectiveness in the control environment through process optimisation, standardisation and automation as the framework matures.
• Introduce and manage management self-assessment of key controls, building ownership and accountability across the first line.
• Set the tone and pace of the ICFR journey, building momentum, holding the business to account for delivery, and embedding a strong controls culture across a complex operating model.
• Partner with UK finance leadership and Group Financial Control to ensure the UK framework aligns with the Group ICFR programme, methodology, expectations and reporting.
EAT | Enterprise Assurance Transformation
Data, MI & Assurance Manager | Job Description Page 2
ICFR Finance Data & Governance
• Develop finance data structures, reporting models, ownership frameworks and supporting documentation. • Manage General Ledger mapping, rationalisation and ownership across accounts, cost centres, profit
centres, legal entities and reporting hierarchies. • Define data-quality measures, reporting controls and issue-resolution processes to improve the reliability
and accessibility of finance data.
ICFR Framework Design & Implementation • Lead risk assessments, scoping methodologies, materiality thresholds and control rationalisation to a SOX
404 standard. • Direct the development and maintenance of Risk and Control Matrices (RACMs) aligned to best practice /
SOX standards, supporting the largest and most complex parts of the business as they document and operate their RACMs.
• Drive consistent application of key controls, Information Produced by the Entity (IPE), IT-dependent and IT general controls (ITGCs), entity-level controls (ELCs) and management review controls (MRCs).
• Oversee end-to-end process documentation (walkthroughs and flowcharts) to support risk identification, control design, testing and audit requirements.
Embedding Controls & Business Partnering
• Work hands-on with UK finance and operational teams to understand processes, facilitate standardisation and embed SOX-style controls into end-to-end financial processes (Record to Report, Order to Cash, Procure to Pay, Hire to Retire).
• Provide expert challenge and guidance to process and control owners on control design, documentation and evidence standards.
• Identify and document best-practice controls and make these available across the business, together with practical guidance and job aids on documentation and evidence standards.
• Translate technical SOX requirements into clear, practical guidance suitable for a complex business. • Advise on the control impact of process changes, new systems and ERP / finance transformation initiatives
(e.g. SAP).
Testing, Deficiencies & Remediation
• Lead and coordinate testing during implementation and readiness, ensuring controls are appropriately evidence and deficiencies identified ahead of transition into the ongoing assurance model.
• Review testing performed by the business, ensuring alignment with SOX methodology. • Assess deficiencies, including severity evaluation (deficiency, significant deficiency, material weakness),
perform root cause analysis and design robust remediation plans. • Drive and track remediation progress through the implementation and readiness phases, supporting timely
and sustainable closure of control issues.
Leading & Developing the Team
• Lead and develop the UK ICFR implementation capability, directly managing the ICFR Analyst and coordinate wider finance, controls and specialists resources across the programme.
• Build strong control capability across the wider business through training, coaching and knowledge sharing.
• Balance leadership of the team with personal, hands-on delivery of the most complex or critical control work.
Audit, Governance & Reporting
• Act as the key UK liaison with Internal Audit and External Audit on ICFR matters, coordinating requests and managing readiness.
• Provide regular updates to UK and Group leadership on the effectiveness of the control environment and the progress of the ICFR journey.
• Contribute to bi-annual controls compliance reporting and review.
EAT | Enterprise Assurance Transformation
Data, MI & Assurance Manager | Job Description Page 3
Knowledge, Skills & Experience
Essential • Extensive, recent, hands-on SOX experience: significant experience (typically 7 to 10 years across financial
controls, internal audit, external audit or risk assurance) implementing, operating and testing SOX 404 internal controls in a large, complex business.
• In-house SOX implementation experience: demonstrable experience implementing and operating SOX from within a business (industry), not solely from an external audit or advisory perspective. This is essential.
• First-year implementation experience: a track record of leading a SOX / ICFR first-year implementation end to end (scoping, risk assessment, control design, documentation, testing and remediation).
• Senior Manager calibre with a strong leadership presence: the gravitas, resilience and strength of personality to lead the ICFR journey, set direction, and influence and challenge stakeholders up to and including senior leadership.
• Hands-on leadership: able to lead and develop a team while remaining personally engaged in the detail of delivery.
• Ability to operate in complexity: experience delivering controls in a large, complex, decentralised and/or multi-site business.
• Continuous-improvement mindset: experience enhancing control environments through process optimisation and automation.
• Systems and technical grounding: command of financial reporting systems, processes and control frameworks, and a solid understanding of IFRS and/or US GAAP.
• Professionally qualified accountant (ACA, ACCA, CIMA, CPA, CIA or equivalent). • Strong working knowledge of SOX methodology (scoping, risk assessment, key control identification, IPE,
sampling, testing and remediation) and of core financial processes (R2R, O2C, P2P, H2R). • Strong stakeholder management skills, with the ability to influence and challenge, and to translate rigour
into a proportionate, pragmatic approach.
Desirable
• Big 4 / professional services background combined with subsequent in-house experience. • Experience working with external auditors on controls audits or SOX readiness programmes. • Working knowledge of SOX / GRC tooling (Optro/AuditBoard), ERP environments (e.g. S/4 HANA) and
consolidation / reporting systems (HFM). • Experience contributing to Executive Committee, Audit Committee or Group-level controls reporting.
What This Role Offers • The opportunity to lead, shape and embed the ICFR journey for a major UK business within a FTSE-listed
global organisation operating to control standards aligned with US SOX. • The scope to modernise the control environment as it matures, through process improvement and
automation. • A high-profile role with significant visibility to UK and Group senior stakeholders. • The chance to build a framework and a team from a position of genuine influence. • Strong professional development and international exposure.
Data, MI & Assurance Manager - Job Description
EAT | Enterprise Assurance Transformation Internal | Compass UK & Ireland
Data, MI & Assurance Manager | Job Description Page 1
Role Profile
JOB TITLE Data, MI & Assur a nc e Mana ger
LOCATION United Kingdom
FUNCTION / DEPARTMENT Financ e | Enterpri s e Assur a nc e Transfor m a ti on (EAT)
REPORTING TO Head of Risk, Control & Gover na nc e
DIRECT REPORTS
Data & MI Analyst initially, with scope to expand the team as progr a m m e require m e nt s and organi sati on al needs evolve .
Role Purpose Establish and manage the data, management information, analytics and assurance reporting capability for the EAT Programme. Initially, the role will lead the reporting, data and analytics workstream for Balance Sheet Assurance, improving ownership, transparency and management insight across Finance. The capability will then scale across Corporate Governance, Risk & Control, Financial Control, SOX readiness and wider Finance Transformation priorities.
Key Responsibilities Balance Sheet Assurance • Lead delivery of the reporting, data and analytics workstream, including dashboards, KPIs and executive
reporting. • Provide clear insight on account ownership, reconciliation performance, aged items, exceptions, delivery
risks and actions. • Improve consistency, transparency and accountability across balance sheet processes and governance
reporting.
Finance Data & Governance • Develop finance data structures, reporting models, ownership frameworks and supporting documentation. • Manage General Ledger mapping, rationalisation and ownership across accounts, cost centres, profit
centres, legal entities and reporting hierarchies. • Define data-quality measures, reporting controls and issue-resolution processes to improve the reliability
and accessibility of finance data.
Management Information, Analytics & Assurance • Develop executive dashboards, scorecards and automated reporting solutions, including Power BI. • Standardise KPIs, metrics and reporting methods, reducing manual activity through automation and
process improvement. • Analyse financial trends, reconciliations and exceptions to identify risks, root causes and improvement
opportunities. • Translate complex financial and technical information into practical management insight and assurance
reporting.
Enterprise Reporting & Stakeholders • Create consistent reporting across EAT workstreams and support leadership forums, steering committees
and governance meetings. • Partner with Finance, Governance, Risk & Control, Financial Control, SOX, PMO, Change, IT, ERP and Data
teams. • Provide constructive challenge on data quality, ownership, reporting consistency and delivery.
EAT | Enterprise Assurance Transformation Internal | Compass UK & Ireland
Data, MI & Assurance Manager | Job Description Page 2
People & Capability Management • Lead, coach and develop the Data & MI Analyst, setting clear objectives, priorities and reporting standards. • Plan delivery across competing programme and stakeholder requirements while remaining hands-on in
complex reporting and analytics activity. • Build a scalable Data, MI & Assurance capability aligned to evolving programme and business needs.
Knowledge, Skills & Experience Essential • Qualified accountant (ACA, ACCA or CIMA), or equivalent relevant professional experience. • Strong knowledge of balance sheet accounting, financial reporting and General Ledger structures. • Experience developing finance MI, reporting, analytics, data models, metrics and dashboards. • Advanced Power BI and Excel capability, with experience handling complex finance datasets and data-
quality issues. • Experience improving reporting through standardisation, process improvement and automation. • Strong stakeholder management, analytical, problem-solving and communication skills in a large, complex
or decentralised organisation. • Ability to manage a small team while remaining personally engaged in delivery.
Desirable • SAP ECC and/or SAP S/4HANA; Alteryx or BlackLine experience. • SOX / ICFR, internal controls, Corporate Governance or Risk & Control knowledge. • Finance Transformation, programme delivery, data governance or master data experience.
Success Measures • Balance Sheet Assurance reporting and analytics are delivered and embedded. • Ownership and mapping across finance structures are accurate, sustainable and transparent. • Executive dashboards and management information are timely, trusted and decision-useful. • Data quality, reporting consistency and automation improve, with reduced manual reporting. • A scalable Data, MI & Assurance capability supports EAT and wider Finance priorities.
What This Role Offers • The opportunity to shape a specialist reporting, analytics and assurance capability within a major Finance
transformation programme. • High visibility across Finance Leadership, Governance and Transformation teams. • The scope to improve decision-making through better data, automation and meaningful insight.
- Role Profile
- Role Purpose
- Key Responsibilities
- Balance Sheet Assurance
- Finance Data & Governance
- Management Information, Analytics & Assurance
- Enterprise Reporting & Stakeholders
- People & Capability Management
- Knowledge, Skills & Experience
- Essential
- Desirable
- Success Measures
- What This Role Offers
CONFIDENTIAL
Job Title Group Internal Controls Manager Location Chertsey Head Office Reporting to Head of Financial & ESG Controls
Role Overview The Group Internal Controls Manager plays an important role in supporting the design, implementation and embedding of a robust SOX-like internal controls over financial reporting (ICFR) across Compass Group. Compass Group aims to operate a robust UK Corporate Governance Code control environment and as part of this seeks to achieve control standards aligned with US SOX over its ICFR. This role will be at the forefront of this ambition, supporting the evolution of the Group’s ICFR framework in a proportionate and scalable way. The successful candidate will bring recent, hands-on experience implementing, operating and/or auditing strong (including SOX) frameworks, and will apply this expertise to help elevate the Group’s internal control maturity across a large, decentralised global organisation. Operating as part of the Group Second Line of Defence, the role partners closely with countries, head office functions, Internal Audit and External Audit to ensure controls are appropriately designed, documented, tested, remediated and governed in line with UK Governance Code, SOX and ICFR expectations. Key Responsibilities ICFR Framework enhancement • Support the implementation and enhancement of financial controls to align with a SOX-style
ICFR framework across Compass Group. • Support the design of risk assessments, scoping methodologies, materiality thresholds and
control rationalisation. • Support the development and maintenance of Risk and Control Matrices (RACMs) aligned to
best practice (SOX standards). • Drive consistent application of best practice concepts such as key controls, Information
Produced by the Entity (IPE), IT-dependent controls, entity-level controls and management review controls (MRC).
• Document end-to-end process flows to support risk identification, control design, testing and audit requirements
Embedding Controls • Work hands-on with countries and head office functions to understand processes, facilitate
standardisation, and embed best practice (SOX style) controls into end-to-end financial processes.
• Provide expert challenge and guidance to process and control owners on design, documentation and evidence standards.
• Translate technical requirements into clear, practical guidance suitable for a decentralised operating model.
CONFIDENTIAL
• Build strong control capability across the business through training, coaching, sharing of best practice and knowledge sharing.
Testing, Deficiencies & Remediation • Perform testing of design and operating effectiveness of key controls. • Review testing performed by the business, ensuring alignment with best practice including
SOX methodology. • Assess deficiencies including severity evaluation (deficiency, significant deficiency, material
weakness). • Perform root cause analysis and support the design of robust remediation plans. • Track remediation progress and ensure timely and sustainable closure of control issues.
Audit & Governance • Act as a key UK Governance Code, SOX and ICFR liaison with internal audit and external
audit. • Contribute to bi-annual controls compliance reporting & review. • Support governance and controls reporting to key stakeholders.
Skills & experience • Recent, hands-on experience implementing, operating and/or auditing SOX 404 internal
controls. • Strong working knowledge of UK Governance Code and SOX methodologies including
scoping, risk assessment, key control identification, IPE, sampling, testing and remediation. • Experience working with external auditors on controls audits or readiness programmes. • Strong understanding of core financial processes (Record to Report, Order to Cash, Procure
to Pay, Hire to Retire). • Strong stakeholder management skills with the ability to influence and challenge
stakeholders. • Pragmatic mindset with the ability to apply rigour proportionately. • Professionally qualified accountant (ACA, ACCA, CIMA or equivalent). • Background in SOX compliance, Internal Audit, External Audit or Risk Assurance.
What This Role Offers • Opportunity to support the enhancement of a robust UK Corporate Governance Code
control environment to achieve control standards aligned with US SOX in a FTSE 20 global organisation.
• High visibility with senior stakeholders. • Ability to help shape the Group’s ICFR framework and long-term SOX roadmap. • International exposure and strong professional development opportunities.
- Group Internal Controls Manager
- Job Title
- Role Overview
- The Group Internal Controls Manager plays an important role in supporting the design, implementation and embedding of a robust SOX-like internal controls over financial reporting (ICFR) across Compass Group.
- Compass Group aims to operate a robust UK Corporate Governance Code control environment and as part of this seeks to achieve control standards aligned with US SOX over its ICFR. This role will be at the forefront of this ambition, supporting the evolu...
- The successful candidate will bring recent, hands-on experience implementing, operating and/or auditing strong (including SOX) frameworks, and will apply this expertise to help elevate the Group’s internal control maturity across a large, decentralise...
- Operating as part of the Group Second Line of Defence, the role partners closely with countries, head office functions, Internal Audit and External Audit to ensure controls are appropriately designed, documented, tested, remediated and governed in lin...
- Key Responsibilities
- ICFR Framework enhancement
- Embedding Controls
- Testing, Deficiencies & Remediation
- Audit & Governance
- Skills & experience
- What This Role Offers
Cyber Security Associate Director
London, Birmingham or Nottingham Location (salary will depend on experience and location)
£85,000 - £95,000 + benefits + bonus
Hybrid working
We're working on an exclusive project to recruit for an Associate Director in one of three locations. The ideal candidate will have experience with Cyber Security across NCSC, NIST and CAF frameworks and be a Cyber Specialist for leading teams! The ideal candidate will also come from some sort of consulting background and able to work on a hybrid-working basis!
The ideal candidate will also:
- Leading and coaching high performing teams, resource management, recruitment, and development for team members. You’ll make quality time and take an interest in the team.
- Providing high-value and quality delivery to clients by leading teams that provide specialist cyber services and advice
- Driving external market activities and identifying new business opportunities
- Developing client relationships by creating proposals that demonstrate our capability to meet new and existing client needs
- Being responsible for client relationships in conjunction with the Partners to ensure our work adds value and is delivered timely and profitability
- Responsible for the ongoing management of cyber services, including capability development and quality assurance of work and reporting
- This role is due to increased client demands and work across a wide range of clients across the FTSE market.
For more information, contact me at Sheena@astrumsearch.com
Cyber Security Senior Consultant
London, Birmingham or Nottingham Location (salary will depend on experience and location)
£53,000-£57,000 base + package
Hybrid working
We're working on an exclusive project to recruit for an Senior Consultant in one of three locations. The ideal candidate will have experience with Cyber Security across NCSC, NIST and CAF frameworks.
The ideal candidate will also:
- Hold an industry recognised certification including CompTIA PenTest+; CHECK, CREST; Offensive Security Certified Professional (OSCP) etc.
- Experience of offensive security and penetration testing
- Demonstrable experience in infrastructure and web application testing, experience in API testing is desirable.
- Demonstrable experience using common pen testing tools including Kali Linux, Burpsuite, Nessus and other industry standard tools.
- Keen to add value to clients and be a part of a growing business that runs nationally.
This role is due to increased client demands and work across a wide range of clients across the FTSE market.
For more information, contact me at Sheena@astrumsearch.com
Internal Audit & Risk Manager
London
20-30% global travel
£70,000 - £79,000 + 15% bonus
Astrum Search is working alongside a global commercial business to recruit an Internal Audit & Risk Manager.
Reporting to the Senior Internal Audit & Risk Manager, you'll play a key role in the ongoing development on the internal audit and risk function. The role has a global remit and requires 20-30% travel (one trip per quarter). This is a highly visible role that will give you the opportunity to deliver global audits, but also assist with ongoing ERM activities.
Key Responsibilities:
- Develop risk-based audit programs and execute both financial and non-financial audits globally
- Write concise and insightful audit reports that offer valuable recommendations to help the business manage risk
- Assist the Head of Audit in the ongoing development of the function and audit planning activities
- Coach more junior members of the team to ensure they deliver high quality work
- Contribute to the ongoing development of risk management at a global level
- Facilitate risk management workshops and work with leadership to continually review principle risk.
Skills & Experience:
- Hold a relevant professional qualification (ACA/ACCA/CIA or equivalent)
- Proven internal audit experience ideally gained in international organisation
- Experience of managing risk, through risk registers and working to ERM frameworks
- Excellent written and verbal communication skills with a strong attention to detail
- Strong stakeholder management and influencing skills.
This is a fantastic opportunity to join a truly global organisation and be part of a developing audit and risk function.
You'll have a high level of autonomy and be heavily involved in the evolution of the team as they continue to expand. The team is high performing with a fantastic culture.
The team is based in Central London and typically travel to the office 2 days per week.