Internal Control Support
act digital
Job Description
What You'll Be Doing
As an Internal Controls & Risk Consultant, you'll play a key role in ensuring that business processes and controls operate effectively and comply with internal policies, regulatory requirements, and industry best practices.
Assess & Test Internal Controls
- Perform design and operating effectiveness testing of key business and technology controls.
- Evaluate control implementation against internal policies, governance frameworks, and regulatory requirements.
- Review and analyze evidence provided by control owners to validate control execution and effectiveness.
- Conduct walkthroughs with First Line of Defense (LOD1) teams to understand processes, identify risks, and assess control maturity.
Strengthen Governance & Compliance
- Contribute to the continuous improvement of the organization's Internal Control Framework.
- Support the assessment of controls against recognized governance and security frameworks, including:
- COSO
- ISO 27001
- ISO 22301
- NIST Cybersecurity Framework
- CIS Controls
- DORA
- NIS2
- Help ensure that governance processes remain aligned with evolving regulatory and business requirements.
Reporting & Risk Management
- Document testing activities, assessment results, identified risks, and recommendations with clarity and consistency.
- Produce high-quality testing workpapers, control assessment reports, and governance documentation.
- Monitor findings and remediation plans, following up with stakeholders to ensure timely resolution.
- Support the preparation of reports and presentations for senior management and governance committees, providing clear visibility into control maturity and risk exposure.
🤝 Collaborate Across the Organization
- Partner with business, technology, risk, compliance, and security teams to coordinate testing activities and facilitate evidence collection.
- Build strong relationships with stakeholders across multiple functions, acting as a trusted advisor on internal control best practices.
- Contribute to a culture of continuous improvement by identifying opportunities to enhance processes, controls, and governance practices.
🛠️ What We're Looking For
Required Experience
✔️ Experience in one or more of the following areas:
- Internal Controls
- Internal Audit
- External Audit
- Risk Management
- Compliance
- Information Security
- IT Audit
- Governance, Risk & Compliance (GRC)
✔️ Strong understanding of internal control principles and governance frameworks.
✔️ Hands-on experience performing:
- Control Testing
- Design Effectiveness Assessments
- Operating Effectiveness Testing
- Evidence Review
- Walkthroughs
- Risk Assessments
- Audit Documentation
✔️ Experience preparing reports, documenting findings, and tracking remediation actions.
Technical Knowledge
Governance & Risk
- Internal Control Frameworks
- COSO
- Governance, Risk & Compliance (GRC)
- Operational Risk
- Control Design & Effectiveness
- Risk Assessment
- Compliance Monitoring
Security & Regulatory Frameworks
Experience with one or more of:
- ISO 27001
- ISO 22301
- NIST Cybersecurity Framework
- CIS Controls
- DORA
- NIS2
Deliverables
You'll contribute to the delivery of:
- Control Testing Workpapers
- Walkthrough Documentation
- Control Assessment Reports
- Findings & Remediation Tracking
- Executive Reporting
- Governance Committee Materials