Jobiglo

No results.

Risk & Audit Lead

kastcard · London

New
Senior 🇬🇧 English
ISO SOC 2 PCI DSS access management data controls secrets/API keys penetration testing vulnerability assessments disaster recovery RCSA KRIs

Job description

Key responsibilities

  • Build and run an independent, enterprise‑wide risk and audit function across KAST.
  • Own the enterprise risk framework: identify, assess and track risks across all business areas.
  • Define and drive risk management activities such as Risk and Control Self‑Assessment (RCSA) and Key Risk Indicators (KRIs).
  • Lead internal audit activities across the full audit lifecycle, including reporting and closure of findings.
  • Provide neutral, independent validation of existing controls and compliance work.
  • Review and assess security and technology controls, data access, data sharing and high‑risk processes.
  • Assess cybersecurity practices, ensure penetration testing, vulnerability assessments and remediation.
  • Own enterprise resilience practices including business continuity and disaster recovery planning and exercises.
  • Partner with Engineering, Security, Legal, Compliance, Finance and other teams to address identified risks while remaining independent.
  • Develop and maintain risk and audit frameworks, policies and processes, and report regularly to leadership.

Required profile

  • 8+ years of experience in risk, audit, cybersecurity or controls with an enterprise‑wide perspective.
  • Strong understanding of enterprise risk management combined with information security and technology risk.
  • Proven experience auditing business and technology environments and identifying control gaps.
  • Led or managed organisations through compliance certification projects such as ISO, SOC 2 or PCI DSS.
  • Experience in fintech or payment companies is a strong plus.

Required skills

  • ISO certification frameworks.
  • SOC 2 compliance.
  • PCI DSS compliance.
  • Access management and data controls, including secrets/API keys.
  • Penetration testing and vulnerability assessments.
  • Business continuity planning and disaster recovery.
  • Risk and Control Self‑Assessment (RCSA) and Key Risk Indicators (KRIs).

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec kastcard.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.
Source : ats:pinpoint

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in the United Kingdom.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

Apply now →

By continuing, you accept our terms of use.

Already have an account? Login

A question about this job?

Ask it here: you will get the full job summary by e-mail, right away.

💬 Chat with us on Telegram

Published 2 hours ago

Expires 1 month from now

1 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

kastcard

London