Principal Auditor of Technology and Security

Principal Auditor of Technology and Security

Full-Time Home office (partial)
M&G

At a Glance

  • Tasks: Lead audits on technology security and cyber security, ensuring robust controls across the organisation.
  • Company: Join a forward-thinking financial services group committed to innovation and security.
  • Benefits: Enjoy 30 days holiday, flexible working, and a strong focus on health and wellbeing.
  • Other info: Collaborative environment with opportunities for professional growth and mentoring.
  • Why this job: Make a real impact by safeguarding technology and enhancing security measures.
  • Qualifications: Experience in technology security audits and strong analytical skills required.
  • Internal Audit is an independent, objective assurance function that is critical to meeting our business ambitions whilst also protecting the interests of our customers by ensuring that the internal control, risk and governance frameworks are always fit for purpose
  • We look beyond financial risks and statements to consider wider issues such as the organisation’s reputation, growth, its impact on the environment and the way we treat our customers and employees
  • As a Principal Information Technology Auditor, you will be responsible for providing independent assurance over the effectiveness of technology security, cyber security and infrastructure controls across the organisation
  • Working closely with Technology, Information Security and business stakeholders, you will perform and support audits covering areas such as network security, cloud security, identity and access management, infrastructure security, vulnerability management, security operations, databases, operating systems and other critical technology platforms
  • This is a key role within the Internal Audit function for an experienced technology security professional with strong technical audit expertise
  • The successful candidate will be capable of independently planning and executing audit fieldwork, leading walkthrough discussions with stakeholders, assessing controls and identifying risks and control weaknesses with minimal supervision
  • Supporting the planning and scoping of technology security audits
  • Identifying key cyber security, infrastructure and technology risks relevant to audit objectives
  • Reviewing documentation, architectures, standards, procedures and control frameworks
  • Developing audit testing approaches for complex technical environments
  • Leveraging data analytics, automation and AI-enabled tools where appropriate to enhance audit activities
  • Independently performing audit testing across technology security, cyber security and infrastructure domains
  • Leading walkthrough meetings with Technology and Information Security stakeholders to understand processes, controls and technologies
  • Assessing the design and operating effectiveness of security controls across networks, databases, operating systems, cloud platforms and infrastructure services
  • Reviewing controls relating to identity and access management, privileged access, vulnerability management, security monitoring, incident management and infrastructure hardening
  • Evaluating technical evidence to determine whether controls are appropriately designed and operating effectively
  • Producing high-quality workpapers and audit evidence in accordance with Internal Audit standards
  • Delivering assigned work to agreed quality standards and timelines with minimal supervision
  • Translating complex technical findings into clear business-focused risk and control observations
  • Drafting high-quality audit observations that clearly articulate risks, impacts, root causes and recommendations
  • Communicating findings professionally and constructively with stakeholders
  • Presenting technical issues in a clear and simple manner that can be understood by business management
  • Supporting audit managers in the preparation of audit reports and stakeholder communications
  • Building effective relationships with Information Security, Technology Infrastructure, Engineering and Cyber Security stakeholders
  • Establishing credibility through technical expertise, professionalism and constructive challenge
  • Maintaining an understanding of key technology initiatives, security programmes and emerging risks
  • Providing objective and balanced challenge whilst maintaining positive working relationships
  • Contributing positively to a collaborative and inclusive team environment
  • Supporting junior auditors through coaching, knowledge sharing and informal mentoring
  • Sharing technical expertise and industry good practice across the Internal Audit function
  • Working effectively with colleagues across multiple audit assignments and initiatives
  • Supporting the continuous improvement of technology audit methodologies and practices
  • Sharing knowledge relating to cyber security, technology security and infrastructure risk management
  • Promoting the effective use of data analytics, automation and AI-enabled tools such as Microsoft Copilot
  • Contributing to audit innovation and continuous improvement initiatives

Benefits

  • 8% non-contributory pension plus up to 5% matching
  • Life Assurance & Death in Service
  • Support, feedback and development programmes to help you reach your full potential
  • Flexible culture and ways of working
  • Focus on health & wellbeing
  • 30 days holiday as standard (excluding bank holidays), with the ability to purchase an additional 5 days
  • Time off when you need it includes carer’s leave, faith leave, grandparent leave and career breaks
  • New parents receive up to 26 weeks of full pay while on leave
  • 4-week back-to-work transition for new parents: work 80% of your contractual hours, be paid for 100%
  • New parents can take family leave in flexible blocks within the first year of birth/adaoption

A collaborative working style and commitment to supporting team success; andAn ability and willingness to leverage technology, data analytics and AI-enabled tools such as Microsoft Copilot to enhance audit effectiveness and efficiencyExcellent written and verbal communication skills, with the ability to explain complex technical concepts to both technical and non-technical audiencesA strong understanding of the workings of both a Financial Services Group and an Internal Audit functionStrong technical understanding of networks, operating systems, databases, cloud platforms, identity and access management, infrastructure security and security monitoring capabilitiesThe ability to independently lead walkthrough meetings and control discussions with technical stakeholdersStrong analytical skills and attention to detail when evaluating control design and operating effectivenessStrong knowledge of Digital security and Technology resilience risks, controls and industry good practiceThe ability to identify root causes, security vulnerabilities, control weaknesses and associated business risksStrong stakeholder management and influencing skillsBe highly motivated, proactive and capable of working independentlyBe a strong team player who contributes positively to team objectives and supports colleaguesChallenge constructively whilst remaining open to alternative viewpoints; andDemonstrate strong analytical and problem-solving capabilitiesBe able to translate technical risks and control weaknesses into business-focused languagePossess strong technical curiosity and a desire to remain current with evolving cyber threats and technology security developmentsCommunicate technical matters clearly, concisely and confidentlyHave excellent attention to detail and a disciplined approach to audit executionBuild trusted relationships with stakeholders across Technology and Information Security functionsDemonstrate integrity, professionalism and sound judgement in all interactionsCloud Security (Azure)Professional certifications such as CISA, CISSP, CISM, CRISC, CCSP or equivalent would be highly advantageousEndpoint SecurityWindows, Linux and Unix Operating SystemsDemonstrated ability to work independently whilst also contributing positively within a team environmentFirewalls and Perimeter SecurityInfrastructure Security ControlsSignificant experience performing Technology Security Audits and Cyber Security Audits within Financial Services or similarly regulated environmentsExperience using data analytics and AI-enabled tools such as Microsoft Copilot to improve audit effectiveness and efficiencyDatabase SecurityGood understanding of industry standards and frameworks such as ISO 27001, NIST Cybersecurity Framework, CIS Controls and COBITActive Directory and Identity & Access ManagementExperience assessing control design and operating effectiveness across technology and security processesStrong technical knowledge of:Network Security and Network ArchitectureStrong report writing, communication and stakeholder management skillsProven ability to communicate highly technical matters in a simple, risk-focused mannerVulnerability ManagementSecurity Monitoring and SIEM Technologies

#J-18808-Ljbffr

Principal Auditor of Technology and Security employer: M&G

M&G is an excellent employer, offering a dynamic work culture that values diversity and inclusion while fostering collaboration across geographically distributed teams. With a strong focus on employee growth and development, the company provides ample opportunities for professional advancement in the vibrant city of Edinburgh, making it an ideal place for those seeking meaningful and rewarding employment in technology delivery.

M&G

Contact Details:

M&G Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Principal Auditor of Technology and Security

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including M&G, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through M&G

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at M&G. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Principal Auditor of Technology and Security

Technology Security Audits
Cyber Security Audits
Network Security
Cloud Security (Azure)
Identity and Access Management
Vulnerability Management
Security Monitoring

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at M&G insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to M&G that you’re committed to staying ahead in the game.

How to prepare for a job interview at M&G

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at M&G to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at M&G.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.