IT Risk & Control Testing Analyst

Bupa, City of Westminster

IT Risk & Control Testing Analyst

Salary not available. View on company website.

Bupa, City of Westminster

  • Full time
  • Permanent
  • Remote working

Posted today, 29 Nov | Get your application in now to be one of the first to apply.

Closing date: Closing date not specified

job Ref: d24ab770bde1418bad4b04ee2accd673

Full Job Description

At Bupa, we're passionate about technology. With colleagues, customers, patients and residents in mind you'll have the opportunity to work on innovative projects and make a real impact on their lives.

Right from the start you'll become part of our digital strategy, joining us on our journey and developing yourself along the way.

The IT Risk and Controls Testing Analyst will be part of a team of four working under the guidance of IT Risk and Control Assurance Manager with the primary purpose of testing the IT controls that are applied to business applications and to the processes, services and infrastructure that support them.

The Testing Analyst will cover all types of Information Technology (IT) and Information Security (IS) controls, and taking a risk-based approach will test the set of controls. This includes controls related to cyber security (modelled on the NIST, ISO, CIS-20 & CCM frameworks) as well as general IT controls aligned to the COBIT and ITIL frameworks.

You'll help us make health happen by :

Collaborate with a team of testing colleagues to perform Risk based control testing.

Execute the control testing activities in line with the guidance provided by the IT Risk and Control Assurance Managers and IT Risk and Control Testing Specialists

Facilitate risk and control self-assessments.

Provide "audit quality" independent testing documentation of IT processes and controls

Track the remediation of any defects identified by the RCSA process.

Support the IT Risk & Control Assurance Managers and IT Risk & Control Testing Specialists in ad hoc deep-dive reviews of IT processes and controls, specifically where repeated incidents have occurred

Document and report control deficiencies and capture recommended improvements to process and control design and operation.

Conduct onsite or desk-based control assessments of third parties during the onboarding or tender process under the guidance of the IT Risk & Control Assurance Managers and IT Risk & Control Testing Specialists

Build a trusted relationship with IT Risk Process and IT Control owners.

Work with the Process and Control owners to improve Processes and Controls

Formal training and hands-on experience of designing, operating or auditing IT Controls.

Experience of IT in a regulated financial services company would be useful but is not essential

Experience in auditing cloud service and deployment models would be useful but not essential

Demonstrable experience in Information Technology audits or IT Assurance (e.g. CISSP, CISM, CISA, CRISC, CCAK)

A sound understanding of British and International Security Standards (e.g. ISO / IEC 27001, ISO / IEC 27002, NIST, CIS-20, PCIDSS) and the UK regulatory environment (e.g. ICO, FCA, PRA and CQC).

Strong interpersonal, communication and influencing skills with the confidence and ability to operate effectively at all levels including third parties and external customers

Professional experience in carrying out IT control reviews in a 1s, 2nd or 3rd line of defence position

Ability to work under pressure maintaining tight deadlines, high concentration levels and keeping up with workflow requirements

We're a health insurer and provider. With no shareholders, our customers are our focus. Our people are all driven by the same purpose - helping people live longer, healthier, happier lives and making a better world. We make health happen by being brave, caring and responsible in everything we do.

Our benefits are designed to make health happen for our people. Viva is our global wellbeing programme and includes all aspects of our health - from mental and physical, to financial, social and environmental wellbeing. We support flexible working and have a range of family friendly benefits.

Joining Bupa in this role you will receive the following benefits and more :

25 days holiday, increasing through length of service, with option to buy or sell

Bupa health insurance as a benefit in kind

An enhanced pension plan and life insurance

Annual performance-based bonus

Onsite gyms or local discounts where no onsite gym available

Various other benefits and online discounts

Relevant jobs