Technology Risk Auditor - £650 per day

If you are interested in this candidate, please contact Andrew Wilson via email awilson@cerfinancial.co.uk or call on 0207 626 6065.

00260260

PROFILE:

I am an organised, motivated individual with a proven ability to prioritise, deliver, and excel under pressure, consistently maintaining excellent attention to detail and accuracy. Passionate and focused, I leverage exceptional communication and interpersonal skills to collaborate effectively with diverse teams and build lasting professional relationships. Proactive and dedicated to ongoing learning and development in both personal and professional spheres. My experience across public sector, consultancy, and global organisations enables me to approach IT audit challenges from multiple perspectives, driving impactful results.

SKILLS:

  • Extensive experience in cyber security and IT audit, including ISO 27001 standards, NIST, data protection, GDPR compliance, IT strategy, and governance
  • Advanced understanding of policies and procedures, with a track record of aligning these to controls and risks to strengthen organisational resilience
  • Applied sharp analytical skills to identify root causes of complex issues and deliver strategic recommendations for effective risk mitigation
  • Demonstrated leadership by managing and developing teams to optimise efficiency and achieve best outcomes consistently

CAREER HISTORY:

November 2025 – July 2026

Internal Audit Agency

Technology Risk Auditor – Contract Role

  • Carried out a variety of Cyber and Technology Risk Audits across a diverse client base within the Mersey region
  • Conducted audits aligned to the Cyber Assessment Framework (CAF), assessing organisational cyber resilience and identifying key risk areas
  • Performed DSPT (Data Security and Protection Toolkit) audits, evaluating compliance with NHS data security standards and providing actionable recommendations
  • Assessed controls across multiple compliance frameworks, identifying gaps and delivering best practice advice to improve service delivery and strengthen security posture
  • Produced clear, concise audit reports with prioritised findings and recommendations for senior stakeholders

February 2025 – July 2025

City Council Internal Audit Shared Service

IT Auditor – Contract Role

  • Conducted comprehensive Cyber Security Audits across four shared service partners, including two Fire and Rescue Partners, identifying and addressing critical risk gaps
  • Assessed risks using multiple compliance frameworks, such as Cyber Essentials self-assessment, NIST, ISO 27001, and IIA Topical Requirements for Cyber Security
  • Verified mitigation of previous recommendations, evaluated for further risks, and provided actionable best practice advice to improve service delivery

January 2024 – February 2025

Career Break

  • Explored new opportunities while travelling and gaining diverse experiences with family
  • Enhanced professional skillset through targeted research and completion of online courses

November 2020 – December 2023

Big 4

IT Assurance Manager

  • Set guidelines as a member of the IPCR Program team for the annual review, supporting successful Cyber Risk Insurance renewal for all member firms and sublicensees
  • Directed the IPCR Quality Assurance programme, overseeing quality assessments of all the firms IT Audits and presenting key quality enhancement focus points to senior stakeholders, including Directors and Partners
  • Developed and maintained the IPCR control framework based on ISO 27001, NIST, Cyber Essentials, and privacy requirements (GDPR/Schrems II)
  • Created and delivered training to over 100 senior member firm staff globally, strengthening knowledge in technology, risk, security, compliance, and privacy
  • Built, coached, and led a team of 8 offshore staff members in India, resulting in a 25% increase in audit efficiency over 12 months
  • Managed the programme budget, ensuring cost-effective operations
  • Acted as the primary point of contact for all IPCR programme enquiries, liaising with over 100 member firms as a subject matter expert in Information Protection and Privacy Controls
  • Oversaw the implementation of recommendations through the Risk Treatment Plan process
  • Handpicked for the firm’s global transformation programme (March – August 2023), initiating meetings with technical stakeholders to revise IPCR controls and testing requirements, resulting in 20–40% cost savings for the IPCR programme by leveraging additional security certifications (e.g., ISO 27001, SoQM)
  • Delivered proof of concept and proposals for entity grouping, combining smaller firms to reduce audit scope, increasing audit efficiency and resource utilisation across the firm.

September 2019 – August 2020

Accountants

IT Audit Manager & Operational Team Lead

  • Led an operational team with full responsibility for a diverse client portfolio
  • Scoped audits in line with client requirements, conducted needs assessments, and planned future audit viability
  • Analysed complex technology areas and delivered actionable insights for clients
  • Completed monthly audit budgeting and pipeline forecasting on schedule
  • Allocated resources effectively to ensure smooth departmental operations
  • Interviewed, coached, and onboarded new team members, enhancing team capability
  • Managed five new graduate staff, overseeing their performance management and professional development
  • Delivered a broad range of audits, including Financial Services internal audits, GDPR (Bank), Information Security (Insurance), Public Sector audits (NHS DSP Toolkit, Cloud Azure Back Up Controls, ITDR Assurance, Information Governance, Digital Content Management, Service Management - ITiL Compliance, Cyber Security, IT Policies Compliance, Account Security, Application Audits, IT Governance/IT Strategy), contributing to cost and risk reduction

June 2018 – September 2019

Accountants

IT Audit Assistant Manager

  • Executed day-to-day IT assurance reviews for a diverse UK client base
  • Led scoping reviews, outlined engagement objectives to the audit team, and communicated with department management and clients
  • Facilitated debrief meetings with senior stakeholders, identified risks, and agreed on mitigating actions
  • Presented at monthly team meetings for a UK team of 45, addressing operational updates, team activities, and engagement management, including finance training for managers
  • Streamlined the appraisal process for the team and management
  • Monitored timesheet allocations and provided senior management with insights on resource utilisation
  • Collaborated with HR and Professional Development Team to support graduate induction and development, doubling graduate team size from 24 to 48 in eight months

February 2004 – June 2018

Council

Senior Internal Auditor

  • Managed risk-based audits across the organisation, adapting to client needs and timelines
  • Led complex investigations into IT security breaches, delivering comprehensive findings
  • Performed External Audit ITGC testing for high-risk areas to ensure compliance
  • Conducted IT Security audits across multiple sites, strengthening organisational security posture
  • Deputised for the Head of Internal Audit, representing the team at Audit Committee meetings and demonstrating strong leadership
  • Provided independent assurance on internal controls to Audit Committees
  • Produced clear, concise reports and communicated audit findings effectively
  • Represented Internal Audit on various SBC stakeholder working groups, contributing to organisational improvement

EDUCATION:

  • 2017: CISA Certified Information Systems Auditor (ISACA)
  • 2012: ISO/IEC 27001 Registered Internal Audit Certification
  • 2006: Diploma in Public Audit (CIPFA DPA)
  • 2003: AAT Foundation Level (College)
  • 2001: Integrated Business Technology Level 2, Internet Technologies Level 1

CERTIFICATIONS:

  • Open University Qualifications – Information Security, Successful IT Systems, Introduction to Cyber Security, Learning from Major Cyber Incidents courses
  • British Red Cross Society Basic First Aid Certificate
  • Interests and Achievements
  • Enjoy travelling and exploring new cultures to broaden personal and professional perspectives
  • Raised £300 for Comic Relief in 2009 through a bake sale
  • Raised £1,500 for Great Ormond Street Hospital in 2015 by organising a charity auction

References Available Upon Request

If you are interested in this candidate, please contact Andrew Wilson via email awilson@cerfinancial.co.uk or call on 0207 626 6065.

To view other CV's please click here.