FDM is a global business and technology consultancy seeking an ITGC Manager to lead and manage the organisation's IT General Controls (ITGC) framework for our Systems Integrator/Consultancy client. This is initially a 4 month contract with very good prospects to extend and will be a mostly remote role with 1 day per month in their London office. This role will take ownership of the planning, coordination, oversight, and continuous improvement of ITGC activities across a portfolio of finance-related applications, ensuring controls are designed, documented, tested, and remediated in line with regulatory and audit requirements.
Working closely with Group Finance, system owners, technology support teams, Internal Audit, and external auditors, you will drive the effective operation of the controls framework, oversee testing activities, monitor remediation progress, and provide clear reporting on control effectiveness and risk exposure. You will also lead the review SOC1 Type 2 reports for supplier-managed applications, ensuring third-party controls are appropriately assessed and any gaps are identified and addressed.
Operating under the ultimate direction of the Group Director- Governance & Portfolio Compliance, you will act as the primary point of contact for ITGC matters, providing leadership, guidance, and assurance across the controls environment while supporting the organisation's wider risk and governance objectives.
Responsibilities
- Lead the delivery and ongoing development of the IT General Controls framework across the agreed application estate
- Own the planning, scheduling, and oversight of ITGC testing activities, ensuring delivery against agreed timelines
- Act as the primary point of contact for ITGC matters across Group Finance, Technology, Risk, and Audit stakeholders
- Coordinate system owners and support teams to secure access, evidence, and support for controls testing and assurance activities
- Oversee the execution and quality assurance of ITGC testing in line with the approved RACM and testing methodology
- Review and approve testing outputs, sampling approaches, and retained audit evidence to ensure audit readiness
- Assess, document, and communicate control deficiencies, including risk impacts and recommended remediation actions
- Drive and monitor remediation plans, ensuring actions are owned, tracked, and delivered within agreed timescales
- Review SOC1 Type 2 reports for supplier-managed applications and assess control effectiveness, coverage gaps, and associated risks
- Ensure control descriptions and documentation remain accurate and aligned with changes in technology, systems, and business processes
- Maintain reporting on control effectiveness, remediation progress, and key risk themes for senior stakeholders
- Promote best practice in IT controls and contribute to the continuous improvement of the organisation's risk and controls environment