At a Glance
- Tasks: Conduct risk-based internal audits and enhance security culture across global offices.
- Company: Join Arup, a leader in sustainable development and innovative project delivery.
- Benefits: Remote work flexibility, inclusive culture, and opportunities for personal growth.
- Other info: Be part of a supportive network that values diversity and inclusion.
- Why this job: Make a meaningful impact while working on ambitious projects with diverse teams.
- Qualifications: Experience in ISO 27001 audits and strong communication skills required.
The predicted salary is between 51750 - 63250 Β£ per year.
Dedicated to sustainable development, Arup is a collective of designers, consultants and experts working globally.
At Arup you will have the opportunity to collaborate on ambitious projects - delivering remarkable outcomes for clients and communities, and to do socially useful work that has meaning.
We help organisations adapt, grow, and thrive in an ever-evolving world by building, shaping, and optimising diverse talent strategies.
Acting as an extension of their recruitment teams, we connect them with skilled interim and temporary professionals, fostering workplaces where everyone can contribute and succeed.
On Behalf of Arup, we are looking for a ISO 27001 Internal Auditor for a 12 Month contract based in either the London office or from one of Arups other UK locations.
The role plans and delivers risk-based internal audits against ISO/IEC 27001 requirements, internal information security policies, client commitments, legal and regulatory obligations, and good-practice security controls.
The postholder works collaboratively with stakeholders across Digital Services, business leadership, project teams, People, Legal, Procurement, Risk and Compliance to support continual improvement and strengthen security culture across Arup's global offices.
Develop and maintain a risk-based ISO 27001 internal audit programme covering global offices, regional operations, shared services and project delivery environments.
Plan, scope and conduct internal audits of the ISMS, security governance processes, risk management activities and control operation.
Assess conformance with ISO/IEC 27001, internal policies, procedures, standards, contractual obligations and applicable regulatory expectations.
Perform audits remotely and, where appropriate, onsite across multiple geographies, time zones and operating contexts.
Evaluate the effectiveness of controls relating to access management, asset management, supplier security, incident management.
Practical experience planning and conducting ISO 27001 internal audits in a complex organisation.
Strong understanding of ISMS principles, security governance, control testing and risk management.
Ability to review evidence, analyse root causes and communicate findings in business-focused language.
Excellent report writing, interviewing, stakeholder management and facilitation skills.
Experience in professional services, engineering, consultancy or project-based environments.
Arup's internal employee networks support their inclusive culture: from race, ethnicity and cross-cultural working to gender equity and LGBTQ+ and disability inclusion - creating a space for everyone to express themselves and make a positive difference.
Interim Internal Auditor - Remote working in London employer: Arup CWS
Arup is an exceptional employer that champions sustainable development and fosters a collaborative work culture, allowing employees to engage in meaningful projects that positively impact communities. With a strong commitment to diversity and inclusion, Arup provides ample opportunities for professional growth and development, ensuring that every team member can contribute to ambitious goals while enjoying a supportive environment. Working remotely in the UK, with occasional travel, offers flexibility and the chance to be part of a global team dedicated to embedding critical risk controls and assurance practices across projects worldwide.