SA

IT Risk and Assurance Specialist

Saol Assurance d.a.c.
Posted 7 hours ago
IrelandHybridLegal & Compliance
Is this job info correct?

Location: Hume Street/Central Park/Remote (Hybrid working)


Who are we?


We’re Saol Assurance. We’re a Life Assurer offering protection, pensions and investment products. We are a progressive and purposeful business that aims to have a positive impact on society. We are reshaping the Irish financial industry, and our focus is on building a life insurance company that provides relevant, quality solutions that empower customers to take control of their financial wellbeing.


Trading as AIB life, we help AIB customers prepare for retirement, protect their loved ones and invest in a flexible way


We’re on a mission to make financial security easier, by simplifying our products and by building smart financial tools that live on the AIB app, that help AIB customers stay on track.


We’re a joint venture between two firms with a deep history: AIB and Great-West Lifeco.


Why work with us?


We are striving to create an environment where each of us feels like we belong, can be at our best and is valued for our unique perspectives and talents.


With an opportunity to be part of building a brand-new life insurance company we offer flexible working and excellent benefits along with a strong and supportive team culture


About the role:


This role is suited to someone with experience in cyber security assurance, technology risk, IT audit, or control testing who can review how technology and security controls are designed, implemented, and evidenced. The successful candidate will work across cloud platforms, Microsoft 365, suppliers, applications, identity, data protection, and incident response to support an assurance programme that is practical, risk-based, and aligned with regulatory expectations.


Reporting to the Cyber Security & Technology Assurance Manager and Head of Cyber Security, Infrastructure and Service Management


Does this sound like something that you want to be part of?


Accountabilities will include:


Technology & Security Assurance

  • Support the delivery of the Cyber Security and Technology Assurance Programme, reviewing whether controls across infrastructure, cloud, applications, identity, suppliers, and data are appropriately designed, implemented, and evidenced.
  • Conduct risk-based assurance reviews across change and run activities, including SaaS partners, technology change delivery, access management, vulnerability management, configuration management, resilience, and operational security controls.
  • Assess technical and procedural control gaps, documenting findings, risks, and recommend remediation actions.
  • Track remediation activity with internal teams and third-party providers to ensure risks are addressed promptly.



Risk & Compliance Oversight

  • Assist in maintaining alignment with regulatory and industry frameworks such as ISO 27001, NIST CSF, CIS Controls, ITIL and DORA.
  • Evaluate new and evolving risks across cloud platforms such as Azure and AWS, Microsoft 365, key enterprise systems, and emerging technologies such as Generative AI.
  • Support policy and standards reviews to ensure operational practices reflect best practice and current threat landscape.
  • Contribute to the preparation of audit responses, assurance attestations, and oversight reporting for governance forums.


Security Operations Support

  • Review and validate security incidents and events escalated from monitoring tools (SIEM, EDR, DLP), ensuring appropriate incident handling and documentation.
  • Participate in incident response exercises, helping to assess readiness and identify improvements in processes and controls.
  • Provide assurance over third‑party managed services, ensuring agreed controls and SLAs are consistently met.


Collaboration & Communication

  • Work closely with application owners, infrastructure teams, and external partners to promote strong security practices.
  • Communicate technical assurance findings in a clear, structured manner for both technical and non‑technical stakeholders.
  • Support the development of security awareness and secure‑by‑design guidance across the organisation.


Continuous Improvement & Security Initiatives

  • Recommend enhancements to improve the maturity of the organisation’s security and overall technology control environment.
  • Contribute to the refinement of assurance methodologies, tooling, and reporting processes.
  • Maintain awareness of evolving control frameworks, regulatory requirements, and industry standards, ensuring technology assurance activities remain aligned with best practice.


What You Will Bring


  • 3+ years’ experience in cyber security assurance, technology risk, IT audit, cloud security, supplier security assurance, or security operations, ideally within a regulated financial services or enterprise technology environment.
  • Bachelor’s degree in Computer Science, Engineering, Cyber Security, Information Systems, or equivalent professional experience.
  • Relevant industry certifications are advantageous, including CISSP, SSCP, CISA, CISM, or similar.
  • Strong understanding of key security and risk frameworks such as ISO 27001, NIST, CIS Controls
  • Experience working with enterprise cloud platforms (Azure, AWS) and Microsoft 365 security capabilities.
  • Familiarity with commonly used enterprise security tools including SIEM, EDR, and DLP.
  • Ability to translate technical control issues into clear findings, risk statements, and practical remediation actions for both technical and non-technical stakeholders.
  • Knowledge of core security domains including:

-vulnerability management

-identity & access management

-network and cloud security principles

-security monitoring and incident handling

-data protection and DLP



Similar jobs