At a Glance
- Tasks: Design and oversee IT controls to ensure financial governance and compliance.
- Company: Join SumUp, a global leader empowering small businesses with innovative financial tools.
- Benefits: Enjoy competitive pay, generous leave, health insurance, and a stake in the company's success.
- Other info: Be part of a diverse team in a vibrant Covent Garden office with excellent growth opportunities.
- Why this job: Make a real impact on financial governance while working with cutting-edge technology.
- Qualifications: Experience in IT audit or technology risk, with strong knowledge of IT General Controls.
The predicted salary is between 70000 - 90000 £ per year.
SumUp’s Internal Controls function sits at the heart of our financial governance, responsible for the programmes that give regulators, auditors, and leadership confidence in how we operate. As SumUp grows, robust and scalable technology controls are increasingly important to the strength of our financial governance and wider control environment. This is a newly created role, and it's a genuinely important one. You will take ownership of the technology side of our ICFR and Provision 29 (P29) programmes. You'll be the person who builds it: designing the control framework, running the IT ICFR assurance programme, and making sure our IT general controls can stand up to external audit scrutiny.
What you'll do
- Design, document, test, and oversee remediation of IT General Controls (ITGCs), automated controls, and key system-generated financial reports across SumUp’s ICFR and P29 programmes.
- Build and maintain a complete IT risk and control matrix (RCM) covering all in-scope control domains, and produce audit-quality evidence packs.
- Act as the primary point of contact between the Internal Controls team and SumUp’s Engineering and IT functions, coordinating evidence, managing auditor requests, and tracking deficiencies through to remediation.
- Identify and implement automation opportunities across the controls lifecycle, including evidence collection workflows, access review sampling, and change management evidence extraction.
- Advise the business on IT risk identification and control design to support compliance and broader risk management requirements.
You’ll be great for this role if…
- Strong hands-on experience in IT audit, ITGC testing, or technology risk, whether from an internal or external audit background.
- Solid knowledge of IT General Controls domains: logical access, change management, computer operations, and SDLC.
- Familiarity with ICFR, SOX, or equivalent regulatory frameworks, including experience managing IT PBC requests with external auditors.
- A good understanding of IT risk and the ability to link IT controls activities with broader assurance programmes (such as ISO and other existing frameworks) to avoid duplication and drive efficiency.
- Ability to document and maintain risk and control matrices to a standard that holds up under audit scrutiny.
- Comfort working across multi-jurisdictional environments and influencing technical teams without direct authority.
- Intellectual curiosity about automation and AI — and a genuine interest in applying both to make controls programmes more efficient.
Why you should join SumUp
- Opportunity to work with a truly global, multicultural team from our central Covent Garden location, wrapped in historic charm and modern flair. This involves an office-first setup.
- Commitment to Diversity and Inclusion: be part of a workplace that values and promotes diversity, fostering an inclusive environment where everyone's perspectives are respected and embraced.
- Enrollment onto our Virtual Stock Option programme: you will own a stake in SumUp’s future success.
- Generous time off: enjoy 28 days of paid leave, plus bank holidays and special leaves.
- A dedicated annual L&D budget for attending conferences and/or advancing your career through further education.
- Health matters: private health insurance, including optical and dental.
- Life made easier: salary-sacrifice commuter benefits via Gogeta.
- Financial security: retirement scheme (SumUp matches 7% when you contribute 5%).
- Peace of mind: life insurance from MetLife for 2× your salary.
- Break4me: 1-month sabbatical after 3 years of service.
- Referral Bonus: earn additional rewards by referring talented individuals to join the SumUp team.
About SumUp
Be empowered to do more that matters. At SumUp, we're on a mission to empower small businesses across the globe by providing simple and affordable tools that allow them to thrive. Today, over 4 million businesses in 37 markets rely on SumUp as their financial partner to manage payments, finance and customer relationships. Our commitment to small businesses is reflected in our diverse team of over 3,000 SumUppers from over 90 nationalities, united by global collaboration and an innovative mindset. Our core values lay the foundation for who we are and what we stand for, shaping our work culture and driving our success. We foster inclusivity and a continuous learning culture, providing a safe space for personal and professional growth. Our differences make us unique and strong as we strive to create an environment where everyone belongs and feels supported, no matter how they identify.
SumUp is proud to be an Equal Employment Opportunity employer, actively seeking and embracing diversity in our workforce. We don't make hiring or employment decisions based on race, colour, religion or religious belief, ethnic or national origin, nationality, sex, gender, gender identity, sexual orientation, disability, age or any other basis protected by applicable laws or prohibited by company policy. Our commitment extends beyond recruitment to creating a safe and respectful workplace where harassment of any form is strictly prohibited.
IT Controls Specialist in London employer: Atlas Metrics
At SumUp, we pride ourselves on being an exceptional employer, offering a vibrant work culture in the heart of Covent Garden that celebrates diversity and inclusion. With generous benefits such as 28 days of paid leave, private health insurance, and a dedicated learning budget, we empower our employees to grow both personally and professionally while contributing to our mission of supporting small businesses globally.
StudySmarter Expert Advice🤫
We think this is how you could land IT Controls Specialist in London
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Atlas Metrics, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Atlas Metrics
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Atlas Metrics. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace IT Controls Specialist in London
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Atlas Metrics insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Atlas Metrics that you’re committed to staying ahead in the game.
How to prepare for a job interview at Atlas Metrics
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Atlas Metrics to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Atlas Metrics.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.