
IT Risk Advisory - Consultant
CFGI
🇬🇧 United Kingdom
Hybrid
24 months ago
- SOX
- CISA
- COSO
- SOC2
- ISO 27001
- NIST
- HIPAA
24 months ago
IT Risk Advisory – Consultant
Â
CFGI Consultants work as part of a team with other CFGI professionals, our clients, and their external auditors or other professional services firms across a variety of IT Risk Advisory engagements.
Â
Our work may include IT Internal Audit, SOX implementation and testing, attestation and certification readiness, business process improvement, compliance assessments, and other technology risk initiatives.
Â
Roles & Responsibilities:
As a Consultant, you will support project teams across all stages of client engagements. Responsibilities may include:
- Performing IT controls testing and documenting results.
- Preparing process narratives, flowcharts, and other documentation used in audit, compliance, and risk assessments.
- Drafting engagement scopes, project plans, risk assessments, testing approaches, and specific procedures.
- Analysing IT-related information and supporting documentation.
- Interviewing client contacts to understand processes, systems, risks, and controls.
- Identifying opportunities for process improvement and additional value for clients.
- Developing strong working relationships with client contacts.
- Assisting with engagement planning, delivery, and economics.
- Supporting internal training, team initiatives, and the continued development of CFGI’s Risk Advisory practice.
Â
What you must have:
- 3–5 years of experience in public accounting or industry performing IT audit, systems implementation, information security, or related technology risk work.
Â
What sets you apart:
- Experience performing IT controls testing and documenting IT processes, risks, and controls.
- Experience supporting IT audit, SOX, compliance, information security, or other technology risk assessments.
- Experience preparing risk assessments, testing approaches, project plans, or related audit and advisory documentation.
- Experience working with IT General Controls and technology-related control environments.
- Experience participating in client interviews and developing findings or recommendations from assessment results.
- Experience supporting multiple workstreams, deliverables, or project activities within an audit or advisory environment.
Â
Nice to have:
- Progress toward CISA, CIA, or another recognised audit, risk, or information security certification is preferred.
- Experience with SOX IT General Controls, COSO, SOC 1, or SOC 2 is preferred.
- Exposure to ISO 27001, NIST, HIPAA, FAIR, or other relevant information security, risk, or compliance standards is advantageous.
- A university degree is preferred; significant progress toward an appropriate professional certification may be considered in lieu of a degree.
Â
Who thrives here:
- Strong interpersonal, written, and verbal communication skills.
- Effective analytical and critical-thinking abilities.
- Strong organisational and project-management skills.
- A proactive, entrepreneurial, and self-motivated approach.
- Dependable and committed to high-quality client service.
- Comfortable collaborating in a team-oriented environment.
IT Risk Advisory - Consultant · CFGI