Risk & Audit Lead

Risk & Audit Lead

Full-Time 59400 - 72600 Β£ / year (est.) On-site
K

At a Glance

  • Tasks: Lead the risk and audit function, ensuring enterprise-wide compliance and security.
  • Company: Join a forward-thinking company focused on security and innovation.
  • Benefits: Competitive salary, flexible working hours, and opportunities for professional growth.
  • Other info: Dynamic role with a chance to work in fintech and payment sectors.
  • Why this job: Make a real impact by shaping risk management across the entire organisation.
  • Qualifications: 8+ years in risk, audit, or cybersecurity with strong stakeholder management skills.

The predicted salary is between 59400 - 72600 Β£ per year.

Risk & Audit Lead

Department

Security & Platforms

Employment Type

Full Time

Location

  • London
  • Description

We're looking for a Risk & Audit Lead to build and own an independent risk and audit function across KAST.

This is an enterprise-wide remit covering risk across the whole organisation, not just technology.

  • What You'll Be Doing
  • Build and run an independent, enterprise-wide risk and audit function across KAST.
  • Own the enterprise risk framework: identify, assess, and track risks across all business areas, not just technology.
  • Define and drive risk management activities, including Risk and Control Self Assessment (RCSA) and Key Risk Indicators (KRIs).
  • Drive internal audit activities enterprise-wide and across the full audit lifecycle, including management reporting and closure of audit findings.
  • Provide neutral, independent validation of controls and compliance work already underway rather than duplicating it.
  • Review and assess security and technology controls, systems, policies and processes, including data access, data sharing, system access workflows and other high-risk processes.
  • Assess cybersecurity practices and identify potential risks and gaps; ensure appropriate penetration testing, vulnerability assessments, and remediation are in place.
  • Own enterprise resilience practices such as business continuity and disaster recovery (BCP/DR) and business impact assessments.
  • Conduct annual BCP and DR exercises
  • Partner with Engineering, Security, Legal, Compliance, Finance, and other teams to address identified risks and improve controls, while remaining independent of them.
  • Develop and maintain risk and audit frameworks, policies, and processes across the org.
  • Provide regular risk and audit updates to the leadership team.
  • What You'll Bring
  • 8+ years of experience in risk, audit, cybersecurity, or controls, with an enterprise-wide, not purely technical, lens.
  • Strong understanding of enterprise risk management alongside information security and technology risk.
  • Experience auditing across business and technology environments and identifying control gaps.
  • Has led or managed organisations through compliance certification projects (ISO and others) and/or technology compliance certifications such as SOC 2 and PCI DSS.
  • Good understanding of access management, data controls, secrets/API keys, and security testing.
  • Strong stakeholder management skills and the ability to work with senior technical, business leaders, external auditors and regulators while holding an independent line.
  • Experience in fintech or payment companies is a big plus.
  • #J-18808-Ljbffr

Risk & Audit Lead employer: kast.xyz

KAST is an exceptional employer that fosters a culture of independence and collaboration, making it an ideal place for a Risk & Audit Lead to thrive. Located in the vibrant city of London, employees benefit from a dynamic work environment that encourages professional growth through diverse risk management activities and cross-departmental partnerships. With a strong focus on employee development and a commitment to maintaining high standards of compliance and security, KAST offers a rewarding career path for those looking to make a meaningful impact.

K

Contact Details:

kast.xyz Recruitment Team

We think you need these skills to ace Risk & Audit Lead

Risk Management
Audit Lifecycle Management
Risk and Control Self Assessment (RCSA)
Key Risk Indicators (KRIs)
Cybersecurity Practices
Penetration Testing
Vulnerability Assessments