FDM is a
global business and technology consultancy seeking an ITGC Manager to lead and
manage the organisation's IT General Controls (ITGC) framework for our Systems
Integrator/Consultancy client. This is initially a 4 month contract with very good prospects to extend and will be a mostly remote role with 1 day per month in their London office. This role will take ownership of the planning,
coordination, oversight, and continuous improvement of ITGC activities across a
portfolio of finance-related applications, ensuring controls are designed,
documented, tested, and remediated in line with regulatory and audit
requirements.
Working
closely with Group Finance, system owners, technology support teams, Internal
Audit, and external auditors, you will drive the effective operation of the
controls framework, oversee testing activities, monitor remediation progress,
and provide clear reporting on control effectiveness and risk exposure. You
will also lead the review SOC1 Type 2 reports for supplier-managed
applications, ensuring third-party controls are appropriately assessed and any
gaps are identified and addressed.
Operating
under the ultimate direction of the Group Director- Governance & Portfolio
Compliance, you will act as the primary point of contact for ITGC matters,
providing leadership, guidance, and assurance across the controls environment
while supporting the organisation's wider risk and governance objectives.
Responsibilities
- Lead the delivery and ongoing
development of the IT General Controls framework across the agreed
application estate
- Own the planning, scheduling,
and oversight of ITGC testing activities, ensuring delivery against agreed
timelines
- Act as the primary point of
contact for ITGC matters across Group Finance, Technology, Risk, and Audit
stakeholders
- Coordinate system owners and
support teams to secure access, evidence, and support for controls testing
and assurance activities
- Oversee the execution and
quality assurance of ITGC testing in line with the approved RACM and
testing methodology
- Review and approve testing
outputs, sampling approaches, and retained audit evidence to ensure audit
readiness
- Assess, document, and
communicate control deficiencies, including risk impacts and recommended
remediation actions
- Drive and monitor remediation
plans, ensuring actions are owned, tracked, and delivered within agreed
timescales
- Review SOC1 Type 2 reports
for supplier-managed applications and assess control effectiveness,
coverage gaps, and associated risks
- Ensure control descriptions
and documentation remain accurate and aligned with changes in technology,
systems, and business processes
- Maintain reporting on control
effectiveness, remediation progress, and key risk themes for senior
stakeholders
- Promote best practice in IT
controls and contribute to the continuous improvement of the
organisation's risk and controls environment