About the Role
The IT Audit Manager will report into and be responsible for working with the LME Senior IT Audit Manager in the execution of the annual internal audit plan, as well as contributing to the assessments of risks within the IT and related functions. This role will have regular liaison with HKEX Group Internal Audit (GIA), especially regarding IT audit work, as LME Internal Audit forms part of GIA.
Responsibilities
- Independently manage and lead IT audits from planning risk-based audit scope, through fieldwork execution, to reporting in accordance with GIA’s audit methodology.
- Critically assess processes and develop testing strategies to evaluate design and effectiveness of key controls.
- Articulate potential control gaps and risk exposures to stakeholders.
- Leverage innovation/automation audit techniques to increase effectiveness and efficiency of the audit program.
- Independently conduct continuous risk monitoring and assessments of IT operations to identify emerging/high-risk areas.
- Manage stakeholder relationships and proactively provide risk and control advice.
- Challenge and influence management to implement effective controls.
- Develop sound knowledge of the Group’s strategy, products, risk management processes and operating platforms.
- Consider broader enterprise risks and LME’s strategic objectives.
- Stay current with industry developments, business and IT trends.
- Conduct research on industry and risk topics.
- Engage in ad-hoc audit activities such as review of key firmwide change initiatives and regulatory requests.
- Validate remediation of audit issues effectively and timely.
- Participate and contribute to departmental initiatives such as continuous improvement of GIA’s audit methodology.
- Support the preparation of materials for senior management, Audit Committee and regulators.
Requirements
- University degree, preferably in Information Systems or other related subject.
- Relevant professional qualifications, such as Certified Information Systems Auditor (CISA) or Certified Information Systems Security Professional (CISSP) or Certified Internal Auditor (CIA), etc preferred.
- At least 3 to 10 years of work experience in internal or external audit, risk management, compliance, cybersecurity, preferably with professional firms or financial institutions.
- Strong understanding of industry cybersecurity standards such as National Institute of Standards and Technology (NIST) Cybersecurity Framework, ISO 27001, CIS, etc.
- Strong understanding of the underlying IT risks, application controls, assessment practices and various IT security software, operating systems, databases, telecommunication and networking technologies.
Skills
- Team-oriented with a strong sense of ownership and individual accountability.
- Agility and ability to drive and adapt to changes in a fast-changing environment.
- Strong communication and relationship management skills.
- Experience in leveraging data and technology.
- Highly motivated self-starter with the ability to multi-task and remain organised.
- Ability to demonstrate sound judgment and professionalism.
- Interest in developing commercial awareness.
- Good report writing and presentation skills.
- Integrity
- Independent
- Proactive
- Strong analytical skills
- Build partnerships across the Group
Location
- UK-London
Work Type
- Permanent
- Standard 40 Hour Week
Experience Level
- 3 to 10 years
Education Level
- University degree
- CISA
- CISSP
- CIA
About the Company
- The London Metals Exchange (LME) is the largest metal exchange in the world and is a wholly owned subsidiary of Hong Kong Exchanges and Clearing Limited (HKEX), one of the world’s largest publicly listed securities exchanges.
- LME Clear (LMEC) provides clearing services to all LME’s clearing participants. LMEC launched in September 2014.
Equal Opportunity
- The LME is committed to creating a diverse environment and is proud to be an equal opportunity employer.
- In recruiting for our teams, we welcome the unique contributions that you can bring in terms of education, ethnicity, race, sex, gender identity, expression & reassignment, nation of origin, age, languages spoken, colour, religion, disability, sexual orientation and beliefs.
- In doing so, we want every LME employee to feel our commitment to showing respect for all and encouraging open collaboration and communication.
