FDM is a global business and technology consultancy seeking IT Controls Testers to work for our global systems
integrator client, to support our
client's Group Digital function within a delivery‑focused financial
controls programme. You’ll play a key role in executing IT General Controls
(ITGC) testing across a defined portfolio of finance-related applications,
helping to ensure the ongoing effectiveness of our client's Financial Controls
Framework. This
is initially a 6‑month assignment starting as soon as possible, with
a predominantly remote, UK‑based working arrangement and occasional travel to the client/supplier sites if required.
We are seeking an IT
Controls Tester to plan, execute, and document ITGC testing activity in line
with the approved Risk and Controls Matrix (RACM) and test methodology. You’ll
work closely with Group Finance, system owners, and technology support teams to
coordinate access, obtain evidence, and complete testing activity within agreed
timelines. The
role is delivery‑focused, scoped to complete the planned controls
testing programme, identify and document deficiencies, and support remediation
tracking. You’ll also review SOC1 reports for supplier‑managed
applications and highlight any control gaps for further action.
You’ll
operate under the direction of the Group Director – Governance & Portfolio
Compliance, contributing to audit‑ready documentation and clear, concise reporting to
the IT Risk Manager.
Responsibilities:
- Planning and scheduling IT
controls testing across an agreed application estate
- Coordinating with system
owners and support teams to arrange access, evidence, and testing windows
- Executing ITGC testing in
line with the approved RACM and test methodology
- Documenting completed
testing, including sampling approaches and retained audit evidence
- Identifying and documenting
control deficiencies, including agreed remediation actions, owners, and
timelines
- Reviewing SOC1 reports for
supplier‑managed systems and
identifying control gaps
- Updating control descriptions
where processes or technology have changed
- Reporting control
deficiencies to the IT Risk Manager for inclusion in the risk register
- Providing progress updates
and completing assigned testing activity within the six‑month term