Supporting the business and our divisional offices, our Head Office functions cover all departments from our Executive Board through to our support functions such as Group Design and Technical, HR, Health and Safety, IT, Sales and Marketing, Commercial, Procurement, Group Finance, Corporate Affairs, as well as Legal and Company Secretariat. We also have a specialised function – Barratt Partnerships.
While the work varies from team to team, our key requirements don’t: you must be well organised, extremely helpful and resourceful, and able to use your initiative. You’ll understand that what you do is important, and impacts on your team, the department, and the wider business.
The Group IT Auditor will plan and perform basic to complex IT operational and regulatory audits, to include an annual assurance review against the NIST Cybersecurity Framework, in line with the annual IT audit plan. Identify internal control weaknesses, assessing risk exposure and significance, proposing value-added recommendations, and preparing internal audit reports reflecting the results of the work performed. Provide technology or data assurance on major business change programmes as directed by the Head of Internal Audit.
The role will act as team-player to support the wider Audit and Risk function, as directed by the Director of Audit and Risk, in Group audits or investigations, and to support other members of the divisional audit team to deliver the Audit and Risk Committee approved internal audit plan.
You will be expected to:
- Conducting independent third line IT audits in line with the annual IT audit plan, documenting audit evidence to support opinions and conclusions;
- Writing formal IT audit reports, with minimal supervision or revision required, identifying internal controls and control weaknesses, and providing value-added recommendations for improvement to management;
- Evaluate the design of Barratt Redrow’s IT policies, processes and controls to ensure they adhere to relevant legislation, regulation and appropriate standards (such as ISO and NIST);
- Evaluate the implementation and operation of IT Controls, assessing the operating effectiveness of ITGCs and ITACs;
- Identify current and emerging IT risks to support in developing the annual IT audit plan;
- Recommend and agree change actions for management to implement to mitigate audit findings/risks and drive improvement of the IT control environment.Track and report the progress/closure of change actions; and
- Collaborate and engage with stakeholders across Group IT and the business to communicate findings and translate complex technical terminology into clear terms for management.