FDM is a global business and technology consultancy seeking an IT Controls Tester to work for our global systems
integrator client, to support our
client's Group Digital function within a delivery‑focused financial
controls programme. You’ll play a key role in executing IT General Controls
(ITGC) testing across a defined portfolio of finance-related applications,
helping to ensure the ongoing effectiveness of Serco’s Financial Controls
Framework.
This
is initially an assignment until the end of the year, starting as soon as possible, with
a predominantly remote, UK‑based working arrangement and occasional travel to client site in London as required. This
is an excellent opportunity for an experienced IT audit or controls
professional who enjoys hands‑on delivery, strong stakeholder engagement, and
working within a structured governance environment.
About the Role
We are seeking an IT
Controls Tester to plan, execute, and document ITGC testing activity in line
with the approved Risk and Controls Matrix (RACM) and test methodology. You’ll
work closely with Group Finance, system owners, and technology support teams to
coordinate access, obtain evidence, and complete testing activity within agreed
timelines.
The
role is delivery‑focused, scoped to complete the planned controls
testing programme, identify and document deficiencies, and support remediation
tracking. You’ll also review SOC1 reports for supplier‑managed
applications and highlight any control gaps for further action.
You’ll
operate under the direction of the Group Director- Governance & Portfolio
Compliance, contributing to audit‑ready documentation and clear, concise reporting to
the IT Risk Manager.
Key Responsibilities
- Planning and scheduling IT
controls testing across an agreed application estate
- Coordinating with system
owners and support teams to arrange access, evidence, and testing windows
- Executing ITGC testing in
line with the approved RACM and test methodology
- Documenting completed
testing, including sampling approaches and retained audit evidence
- Identifying and documenting
control deficiencies, including agreed remediation actions, owners, and
timelines
- Reviewing SOC1 reports for
supplier‑managed systems and
identifying control gaps
- Updating control descriptions
where processes or technology have changed
- Reporting control
deficiencies to the IT Risk Manager for inclusion in the risk register
- Providing progress updates
and completing assigned testing activity within the six‑month term