About this role
Senior Attestations and Client Audit Manager (D&A DORA)
ROLE SUMMARY
As the DORA Risk Assurance Manager you will be meeting the new demand from clients as a result of European DORA legislation to deliver new attestations and client audit.
WHAT YOU'LL BE DOING: Leadership & Culture:
- Lead the day-to-day management and scheduling of the DORA Customer Audit program, ensuring that all internal partners are briefed, logistics organized and evidence collated, being the Customer Audit representative with the client.
- Champion integrity, transparency, and continuous learning.
- Mentor junior members of staff, encourage growth, through real-time feedback and collaborative learning.
- Support the team in adapting to new auditing standards and digital transformation initiatives.
Audit and Attestations:
- Own the planning and execution of attestation programs (e.g. SOC 2, ISAE 3000).
- Maintain a library control narrative, process flows, and risk/control matrices.
- Prepare and deliver responses to findings.
- Own the end-to-end governance process across the department.
- Deputize for the leadership team, delegate and manage workload across the team, provide mentorship and career counselling to members of the team.
Control framework:
- Support the design and implementation of control frameworks over technology platforms from each Business Unit.
- Present the control framework, objectives, and provide advice to product managers, engineers, architects and other partners in embedding controls for attestations.
- Lead the end-to-end risk control self-assessment and maturity reviews.
Client Engagement:
- Work directly with customers and account teams to proactively address queries based on trends and common themes observed in assigned requests.
- Act as primary point of contact or escalation for Business Unit Product Managers, Business Control Owners, Architects and others.
- Educate business leaders and technical teams on attestation readiness and control framework.
- Maintain and collaborate with partners – including Legal, Compliance, Infrastructure & Cloud, D&A Tech Services teams, product teams, customer facing teams and external auditors.
Risk and Compliance:
- Collaborate with Information Security, Privacy, Legal, and other internal Program teams to align on regulatory expectations.
- Monitor emerging standards in financial market infrastructure assurance and recommend adoption where required.
WHAT YOU'LL BRING:
- Proven track record in audit, attestation, or risk assurance in a Big 4, consulting or financial services environment.
- Solid understanding of DORA, SOC, ISAE3402/3000 and IT Risk control frameworks.
- Experience in assessing technology, data, or market infrastructure environments.
- Excellent documentation skills (process maps, RCMs, audit reports etc.)
- Good interpersonal skills with the ability to influence collaborators at all levels.
- Understanding of risk management and effective Information Security strategy, practices, technologies and controls frameworks.
Desirable Criteria:
- Professional qualifications (CISA, CRISC, CISM, CISSP, CIA etc.)
- Exposure to regulatory audits (FCA, SEC, ESMA) and other operational resilience requirements.
Career Stage: Manager