We're looking for a Risk & Audit Lead to build and own an independent risk and audit function across KAST. This is an enterprise-wide remit covering risk across the whole organisation, not just technology. What You’ll Be Doing Build and run an independent, enterprise-wide risk and audit function across KAST. Own the enterprise risk framework: identify, assess, and track risks across all business areas, not just technology. Define and drive risk management activities, including Risk and Control Self Assessment (RCSA) and Key Risk Indicators (KRIs). Drive internal audit activities enterprise-wide and across the full audit lifecycle, including management reporting and closure of audit findings. Provide neutral, independent validation of controls and compliance work already underway rather than duplicating it. Review and assess security and technology controls, systems, policies and processes, including data access, data sharing, system access workflows and other high-risk processes. Assess cybersecurity practices and identify potential risks and gaps; ensure appropriate penetration testing, vulnerability assessments, and remediation are in place. Own enterprise resilience practices such as business continuity and disaster recovery (BCP/DR) and business impact assessments. Conduct annual BCP and DR exercises Partner with Engineering, Security, Legal, Compliance, Finance, and other teams to address identified risks and improve controls, while remaining independent of them. Develop and maintain risk and audit frameworks, policies, and processes across the org. Provide regular risk and audit updates to the leadership team. What You'll Bring 8+ years of experience in risk, audit, cybersecurity, or controls, with an enterprise-wide, not purely technical, lens. Strong understanding of enterprise risk management alongside information security and technology risk. Experience auditing across business and technology environments and identifying control gaps. Has led or managed organisations through compliance certification projects (ISO and others) and/or technology compliance certifications such as SOC 2 and PCI DSS. Good understanding of access management, data controls, secrets/API keys, and security testing. Strong stakeholder management skills and the ability to work with senior technical,business leaders, external auditors and regulators while holding an independent line. Experience in fintech or payment companies is a big plus.
ISO Lead Auditor / ISO Consultant
IMSM
Digital Trust Lead Auditor (London and Southeast)
Bsigroup
Lead Auditor - Home Claims
Hastingsdirect
Audit Data & Innovation Lead
Sumer
Lead Auditor - Home Claims
Hastingsdirect
Corporate Lawyer (PSL)
Jobs.co.uk