Job description:
IT Risk Control Testing Specialist Flexible on Location London â EC2R 7HJ, Staines - TW18 3DZ, Manchester â M50 3SP Hybrid (3 to 4 days working from home) Permanent £49,000 - £61,000 plus fantastic benefits Full time â 37.5 hrs We make health happen At Bupa, weâre passionate about technology. With colleagues, customers, patients and residents in mind youâll have the opportunity to work on innovative projects and make a real impact on their lives. Right from the start youâll become part of our digital strategy, joining us on our journey and developing yourself along the way. The IT Risk and Controls Testing Specialist will be part of a team of four working under the guidance of IT Risk and Control Manager with the primary purpose of testing the IT controls that are applied to business applications and to the processes, services and infrastructure that support them. The Testing Analyst will cover all types of Information Technology (IT) and Information Security (IS) controls, and taking a risk-based approach will test the set of controls. This includes controls related to cyber security (modelled on the NIST, ISO, CIS-20 CCM frameworks) as well as general IT controls aligned to the COBIT and ITIL frameworks. Youâll help us make health happen by: Improve the design and operation of the IT controls by working closely with the control owners to develop remediation plans where deficiencies are found. In some cases, a special version of a control may be needed, and the IT Controls Specialist will help design a suitable variant or develop compensating controls to mitigate the risk. Work with the process and control owners to develop a set of process, risk and control metrics to allow the processes and systems to be continuously monitored through a trusted and robust set of metrics. Act as a champion for good control design and operation by providing coaching and training to control owners and encouraging a culture of continuous improvement. Build a trusted relationship with IT Risk Process and IT Control owners. Work with the Risk, Process and Control owners to improve Processes and Controls Support the planning of the control assurance plan. Co-ordinate a team of testing colleagues to perform Risk based control testing. Co-ordinate risk and control self-assessments on all IT Controls Provide guidance to the control owners on best practice. Provide âaudit qualityâ independent testing of IT processes and controls. Oversee the remediation of any defects identified by the RCSA process. Perform ad hoc deep-dive reviews of IT processes and controls, specifically where repeated incidents have occurred. Adopt a continuous improvement mentality. Document and Report control deficiencies and recommend improvements to process and control design and operation. Conduct onsite or desk-based risk assessments of third parties during the onboarding or tender process to identify risks and weaknesses in the supplierâs systems prior to commencing services with them. Assist other members of the team by providing guidance around risks and best practices in areas where the candidate has specialist knowledge. Key Skills / Qualifications needed for this role: Formal training and hands-on experience of designing, operating, or auditing IT Controls. Experience of IT in a regulated financial services company would be useful but is not essential. Experience in auditing cloud service and deployment models would be useful but not essential. Demonstrable experience in Information Technology audits or IT Assurance (e.g. CISSP, CISM, CISA, CRISC, CCAK) A sound understanding of British and International Security Standards (e.g. ISO/IEC 27001, ISO/IEC 27002, NIST, CIS-20, PCIDSS) and the UK regulatory environment (e.g. ICO, FCA, PRA and CQC). Strong interpersonal, communication and influencing skills with the confidence and ability to operate effectively at all levels including third parties and external customers. Professional experience in carrying out IT control reviews in a 1s, 2nd or 3rd line of defence position. Ability to work under pressure maintaining tight deadlines, high concentration levels and keeping up with workflow requirements. Benefits Our benefits are designed to make health happen for our people. Viva is our global wellbeing programme and includes all aspects of our health â from mental and physical, to financial, social and environmental wellbeing. We support flexible working and have a range of family friendly benefits. Joining Bupa in this role you will receive the following benefits and more: 25 days holiday, increasing through length of service, with option to buy or sell Bupa health insurance as a benefit in kind An enhanced pension plan and life insurance Annual performance-based bonus Onsite gyms or local discounts where no onsite gym available Various other benefits and online discounts Why Bupa? Weâre a health insurer and provider. With no shareholders, our customers are our focus. Our people are all driven by the same purpose â helping people live longer, healthier, happier lives and making a better world. We make health happen by being brave, caring and responsible in everything we do. We encourage all of our people to âBe you at Bupaâ, we champion diversity, and we understand the importance of our people representing the communities and customers we serve. Thatâs why we especially encourage applications from people with diverse backgrounds and experiences. As a Disability Confident employer, we offer a guaranteed interview for every disabled applicant who meets the minimum criteria for the job. Weâll make sure you are treated fairly and offer reasonable adjustments as part of our recruitment process to anyone that needs them. If you would like more information on the role, require an alternative format, or would like to discuss other opportunities suited to your skills and experience, please contact the recruiter directly. #LI-SB1 Time Type: Full time Job Area: