Work on IT internal audit, SOX implementation and testing, attestation readiness, and compliance assessments. Perform IT controls testing, create process narratives and flowcharts, draft scope and test plans, analyze IT data, interview clients, identify improvements, support engagement economics, and help build internal training and team processes.
IT Risk Advisory – Consultant
CFGI Consultants work as part of a team with other CFGI professionals, our clients, and their external auditors or other professional services firms across a variety of IT Risk Advisory engagements.
Our work may include IT Internal Audit, SOX implementation and testing, attestation and certification readiness, business process improvement, compliance assessments, and other technology risk initiatives.
Roles & Responsibilities:
As a Consultant, you will support project teams across all stages of client engagements. Responsibilities may include:
- Performing IT controls testing and documenting results.
- Preparing process narratives, flowcharts, and other documentation used in audit, compliance, and risk assessments.
- Drafting engagement scopes, project plans, risk assessments, testing approaches, and specific procedures.
- Analysing IT-related information and supporting documentation.
- Interviewing client contacts to understand processes, systems, risks, and controls.
- Identifying opportunities for process improvement and additional value for clients.
- Developing strong working relationships with client contacts.
- Assisting with engagement planning, delivery, and economics.
- Supporting internal training, team initiatives, and the continued development of CFGI’s Risk Advisory practice.
What you must have:
- 3–5 years of experience in public accounting or industry performing IT audit, systems implementation, information security, or related technology risk work.
What sets you apart:
- Experience performing IT controls testing and documenting IT processes, risks, and controls.
- Experience supporting IT audit, SOX, compliance, information security, or other technology risk assessments.
- Experience preparing risk assessments, testing approaches, project plans, or related audit and advisory documentation.
- Experience working with IT General Controls and technology-related control environments.
- Experience participating in client interviews and developing findings or recommendations from assessment results.
- Experience supporting multiple workstreams, deliverables, or project activities within an audit or advisory environment.
Nice to have:
- Progress toward CISA, CIA, or another recognised audit, risk, or information security certification is preferred.
- Experience with SOX IT General Controls, COSO, SOC 1, or SOC 2 is preferred.
- Exposure to ISO 27001, NIST, HIPAA, FAIR, or other relevant information security, risk, or compliance standards is advantageous.
- A university degree is preferred; significant progress toward an appropriate professional certification may be considered in lieu of a degree.
Who thrives here:
- Strong interpersonal, written, and verbal communication skills.
- Effective analytical and critical-thinking abilities.
- Strong organisational and project-management skills.
- A proactive, entrepreneurial, and self-motivated approach.
- Dependable and committed to high-quality client service.
- Comfortable collaborating in a team-oriented environment.
Similar Jobs
Financial Services
Leads complex technology programs from planning through delivery, managing technical requirements, resources, budgets, timelines, risks, and cross-functional stakeholders. Applies Agile practices and analytical reasoning to improve program performance, drive continuous improvement, and align initiatives with business objectives. Uses and validates enterprise-authorized AI capabilities for program planning, risk synthesis, governance, and reporting while following data-sensitivity requirements.
Top Skills:
AI
Financial Services
Develops and maintains secure, scalable Java applications and services within an agile team. Responsibilities include software development, troubleshooting, production coding, data analysis, system visualization, debugging, operational stability, and improving software architecture and coding practices. The role requires collaboration across business domains and emphasizes application resiliency, security, continuous integration and delivery, and reliable system performance.
Top Skills:
Apache KafkaCi/CdGrafanaJavaRestSplunkSpringSpring BootUnix/Linux
Artificial Intelligence • Cloud • Information Technology • Security • Software • Cybersecurity • Data Privacy
Own Snyk’s UK and Ireland partner strategy, business plans, pipeline, and revenue performance. Recruit and onboard regional security partners, embed Snyk into partners’ DevSecOps strategies, align partners with sales teams, and lead business reviews. The role requires channel sales experience within the security partner ecosystem, solution and value-based selling skills, strong communication, and travel to partner events and activities.
Top Skills:
DevsecopsSnyk
What you need to know about the Edinburgh Tech Scene
From traditional pubs and centuries-old universities to sleek shopping malls and glass-paneled office buildings, Edinburgh's architecture reflects its unique blend of history and modernity. But the fusion of past and future isn't just visible in its buildings; it's also shaping the city's economy. Named the United Kingdom's leading technology ecosystem outside of London, Edinburgh plays host to major global companies like Apple and Adobe, as well as a growing number of innovative startups in fields like cybersecurity, finance and healthcare.


