Senior Internal Auditor - IT and Operational Audit

Mundipharma
London, UK
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Languages
English
Job source

Tech stack

Artificial Intelligence Cyber Security Data Governance Disaster Recovery Information Technology Audit IT Management IT General Controls (ITGC) Information Technology

Job description

Join us and make a difference when it matters most!

We are committed to strengthening risk management, safeguarding data, and enhancing operational resilience. This role offers the opportunity to shape audit strategies and partner with the business to ensure robust controls across IT, data, and operational risk landscapes.

The Team

This role sits within the Risk & Audit function and works closely with IT, Finance, Operations, and senior leadership teams. The position plays a key role in strengthening governance, ensuring regulatory compliance, and supporting enterprise risk resilience.

Role and Responsibilities

IT Audits

  • Support the development and delivery of the annual IT and data risk audit plan.
  • Plan and execute IT audits across key areas including:
  • IT system implementations
  • Cybersecurity and IT resilience
  • Artificial Intelligence
  • IT General Controls (ITGCs)
  • IT governance frameworks
  • Critical third-party/vendor risk assessments
  • Assess compliance with relevant regulations and standards, including EU AI Act, NIS2, and GDPR.
  • Identify system vulnerabilities and control gaps, providing actionable recommendations to mitigate risks.
  • Ensure timely and robust follow-up of audit findings and remediation actions.

Operational Audits

  • Plan, lead, and deliver operational audits across areas such as:
  • Manufacturing and production processes
  • Security and access controls
  • Data privacy
  • Back-office and support functions
  • Provide insights to improve efficiency, strengthen controls, and reduce operational risks.
  • Monitor and track implementation of agreed audit actions.

Risk Resilience

  • Support implementation of a risk preparedness and resilience framework across the organisation.
  • Assist in identifying, documenting, and assessing functional risks, ensuring appropriate mitigating controls are defined and embedded.
  • Partner proactively with IT and business stakeholders to enhance governance over key risk areas, including:
  • Cybersecurity
  • IT disaster recovery and business continuity
  • Artificial Intelligence risk management
  • Promote a risk-aware culture and continuous improvement in risk management practices

Requirements

Do you have experience in IT auditing?, * Experience in IT audit, risk management, or internal audit within a complex organisation.

  • Strong understanding of IT risk domains, including cybersecurity, data governance, and IT controls.
  • Knowledge of relevant regulatory frameworks (e.g., GDPR, NIS2, EU AI Act) is preferred.
  • Proven ability to plan and execute audits independently and deliver high-quality insights.
  • Strong analytical, problem-solving, and stakeholder management skills.
  • Ability to influence and collaborate with cross-functional teams.
  • Professional certifications (e.g., CISA, CRISC, CIA, or equivalent) are advantageous.
  • Fluent in English, both written and spoken.

Benefits & conditions

  • Flexible benefits package
  • Opportunities for learning and professional development
  • Collaborative and inclusive working environment
  • Full ownership of the project

Diversity and inclusion

We are committed to creating an inclusive workplace where everyone feels valued, respected, and empowered to reach their full potential.

About the company

We are a forward-looking organisation focused on strong governance, innovation, and resilience. Our goal is to ensure sustainable growth while maintaining the highest standards of risk management and compliance.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:53 min

Managing infrastructure limitations with managed Amazon Aurora databases

Dharin Shah Dharin Shah · WWC 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

1:53 min

Reinventing data governance as a collaborative business foundation

Farooq Sheikh Farooq Sheikh +3 · WWC 2025

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · WWC Europe 2026

5:00 min

Managing complex state with scope-based resource management

Bjarne Stroustrup · WWC 2022

4:37 min

Strengthening cross-functional controls and risk management

Seppe Housen Seppe Housen · Europe 2026 Virtual

Videos

See all

Related articles

See all