← Back to job listings
M&
Principal Auditor of Technology and Security
M&G · Edinburgh, United Kingdom
About The Role
Join our Internal Audit team as a Principal Auditor of Technology and Security. In this key role, you will provide independent assurance over the effectiveness of technology security, cyber security, and infrastructure controls across the organization. You will work closely with Technology, Information Security, and business stakeholders to perform and support audits covering various critical technology areas. This position requires strong technical audit expertise and the ability to independently plan and execute audit fieldwork.
- Assurer l'efficacité des contrôles de sécurité technologique, de cybersécurité et d'infrastructure au sein de l'organisation.
- Planifier et exécuter de manière indépendante les travaux d'audit, diriger les discussions avec les parties prenantes et évaluer les contrôles.
- Produire des documents de travail de haute qualité et des preuves d'audit conformément aux normes d'audit interne.
- A collaborative working style and commitment to supporting team success; and
- An ability and willingness to leverage technology, data analytics and AI-enabled tools such as Microsoft Copilot to enhance audit effectiveness and efficiency
- Excellent written and verbal communication skills, with the ability to explain complex technical concepts to both technical and non-technical audiences
- A strong understanding of the workings of both a Financial Services Group and an Internal Audit function
- Strong technical understanding of networks, operating systems, databases, cloud platforms, identity and access management, infrastructure security and security monitoring capabilities
- The ability to independently lead walkthrough meetings and control discussions with technical stakeholders
- Strong analytical skills and attention to detail when evaluating control design and operating effectiveness
- Strong knowledge of Digital security and Technology resilience risks, controls and industry good practice
- The ability to identify root causes, security vulnerabilities, control weaknesses and associated business risks
- Strong stakeholder management and influencing skills
- Be highly motivated, proactive and capable of working independently
- Be a strong team player who contributes positively to team objectives and supports colleagues
- Challenge constructively whilst remaining open to alternative viewpoints; and
- Demonstrate strong analytical and problem-solving capabilities
- Be able to translate technical risks and control weaknesses into business-focused language
- Possess strong technical curiosity and a desire to remain current with evolving cyber threats and technology security developments
- Communicate technical matters clearly, concisely and confidently
- Have excellent attention to detail and a disciplined approach to audit execution
- Build trusted relationships with stakeholders across Technology and Information Security functions
- Demonstrate integrity, professionalism and sound judgement in all interactions
- Cloud Security (Azure)
- Professional certifications such as CISA, CISSP, CISM, CRISC, CCSP or equivalent would be highly advantageous
- Endpoint Security
- Windows, Linux and Unix Operating Systems
- Demonstrated ability to work independently whilst also contributing positively within a team environment
- Firewalls and Perimeter Security
- Infrastructure Security Controls
- Significant experience performing Technology Security Audits and Cyber Security Audits within Financial Services or similarly regulated environments
- Experience using data analytics and AI-enabled tools such as Microsoft Copilot to improve audit effectiveness and efficiency
- Database Security
- Good understanding of industry standards and frameworks such as ISO 27001, NIST Cybersecurity Framework, CIS Controls and COBIT
- Active Directory and Identity & Access Management
- Experience assessing control design and operating effectiveness across technology and security processes
- Strong technical knowledge of:
- Network Security and Network Architecture
- Strong report writing, communication and stakeholder management skills
- Proven ability to communicate highly technical matters in a simple, risk-focused manner
- Vulnerability Management
- Security Monitoring and SIEM Technologies
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring