Hiring.Camp

IT Risk & Control Testing Analyst

Bupa Careers

·

Yesterday

Salary
£40k – £60k
Location
Central London, United Kingdom · Salford Quays · Staines
Workplace
Hybrid
Type
Full-time
Closing date
Today
Source
Workday

Description

Job Description:

Risk & Controls Analyst

Primary Location: London (EC2R 7HJ), Staines (TW18 3DZ) or Manchester (M50 3SP)

Flexible / Hybrid Working Options

Permanent

£40,000 - £60,000 (Depending on experience)

Full Time | 37.5 Hours per Week

We Make Health Happen

At Bupa, we're passionate about technology and the important role it plays in delivering exceptional experiences for our customers, patients, residents and colleagues.

As a Risk & Controls Analyst, you'll help strengthen and maintain our Technology and Cyber control environment. Working closely with the Senior Controls Manager and control owners across Technology, Cybersecurity and Operational Risk teams, you'll support control design, assessment, testing, reporting and continuous improvement activities that help Bupa manage risk effectively and meet regulatory expectations.

This is an excellent opportunity to develop expertise in Technology Governance, Risk and Compliance (GRC) while contributing to key strategic initiatives across a global organisation.

How You'll Help Us Make Health Happen

  • Support the operation and continuous improvement of Bupa's Technology and Cyber control framework.

  • Assist control owners in documenting processes, risks, controls, evidence requirements and testing approaches.

  • Perform first-line control testing and quality assurance reviews to assess control effectiveness.

  • Capture and analyse testing results, identifying themes, emerging risks and control weaknesses.

  • Track control deficiencies, agreed remediation actions and management responses through to closure.

  • Prepare governance packs, dashboards and reports for senior stakeholders highlighting risk and control performance.

  • Support internal audit, external audit and regulatory engagements by coordinating evidence requests and responses.

  • Maintain risk and control inventories, ensuring documentation remains accurate and up to date.

  • Assist with control assessments relating to cloud technologies, cybersecurity, identity and access management, change management and third-party risk.

  • Partner with Technology, Cyber and Operational teams to promote control awareness and good risk management practices.

  • Contribute to thematic reviews, deep dives and maturity assessments across key risk domains.

  • Support the implementation of new controls within transformation programmes and technology change initiatives.

  • Help identify opportunities to improve reporting, automation and control monitoring through data analytics.

Key Skills / Qualifications Needed For This Role

We're looking for someone who is analytical, organised and passionate about risk and controls. You'll bring:

  • Experience in Technology Risk, Operational Risk, Internal Controls, Audit, Information Security, Compliance or Governance.

  • Understanding of risk and control concepts, including design effectiveness and operational effectiveness.

  • Strong analytical and problem-solving skills with the ability to interpret complex information and identify meaningful insights.

  • Excellent written and verbal communication skills.

  • Strong attention to detail and the ability to manage multiple priorities effectively.

  • Experience creating reports and dashboards using Excel, Power BI or similar tools.

  • Ability to build positive working relationships across technical and non-technical teams.

  • Knowledge of control frameworks and standards such as ISO 27001, NIST, COBIT, ITIL, CIS Controls or PCI DSS.

  • Understanding of technology environments including infrastructure, cloud computing, cybersecurity and technology operations.

Desirable Skills

  • Experience performing controls testing, assurance reviews or audit activities.

  • Knowledge of cloud security frameworks such as CSA CCM and cloud-specific NIST or ISO controls.

  • Experience supporting regulatory, audit or compliance activities.

  • Understanding of risk methodologies and the Three Lines Model.

  • Exposure to technology transformation programmes and change initiatives.

  • Experience using governance, risk and compliance (GRC) tools.

  • Basic data analysis and visualisation skills.

Qualifications (Desirable but Not Essential)

  • Degree in Information Technology, Business, Cybersecurity, Risk Management, Audit or a related discipline.

Relevant professional qualifications or certifications, such as:

  • CISA

  • CRISC

  • ISO 27001 Foundation / Lead Auditor

  • CISSP

  • CISM

  • GRCP

  • ITIL Foundation

Success Measures

  • In this role, success will be demonstrated through:

  • Timely completion of control testing and assurance activities.

  • High-quality risk and control reporting delivered to stakeholders.

  • Effective tracking and closure of control remediation actions.

  • Positive audit and assurance outcomes.

  • Increased control maturity and improved compliance across Technology and Cyber functions.

  • Strong stakeholder engagement and collaboration across teams.

Career Progression

This role provides a pathway into:

  • Senior Risk & Controls Analyst

  • Technology Controls Manager

  • Technology Risk Manager

  • Cyber Risk Manager

  • Governance, Risk & Compliance (GRC) Lead

  • Senior Controls Manager

The position is designed to develop future control leaders by building expertise across risk management, controls assurance, audit engagement, governance and regulatory compliance.

Benefits 

Our benefits are designed to make health happen for our people. Viva is our global wellbeing programme and includes all aspects of our health – from mental and physical, to financial, social and environmental wellbeing. We support flexible working and have a range of family friendly benefits.
 

Joining Bupa in this role you will receive the following benefits and more: 

• 25 days holiday, increasing through length of service, with option to buy or sell

• Bupa health insurance as a benefit in kind

• An enhanced pension plan and life insurance

• Onsite gyms or local discounts where no onsite gym available

• Various other benefits and online discounts

  

Why Bupa? 

We’re a health insurer and provider. With no shareholders, our customers are our focus. Our people are all driven by the same purpose – helping people live longer, healthier, happier lives and making a better world. We make health happen by being brave, caring and responsible in everything we do. 


We encourage all of our people to “Be you at Bupa”, we champion diversity, and we understand the importance of our people representing the communities and customers we serve.  That’s why we especially encourage applications from people with diverse backgrounds and experiences.  


Bupa takes pride in being a Level 2 Disability Confident Employer and will aim to offer an interview/assessment to disabled applicants who best meet the minimum criteria for the role. We’re committed to ensuring you’re treated fairly during the recruitment process and offer reasonable adjustments to anyone who may benefit from accommodations to the recruitment process. 

Time Type:

Full time

Job Area:

Legal, Risk & Audit

Locations:

Angel Court, London, Bupa Place, Staines - Willow House

Skills

ExcelPower BICybersecurityRisk ManagementComplianceChange ManagementITILISO 27001CISSP

Similar Jobs

30

IN-Specialist 3– IT Risk– GCC - Advisory- Bangalore

Pwc · Bengaluru Millenia, India

Yesterday

IN-Specialist 3– IT Risk– GCC - Advisory- Bangalore

Pwc · Bengaluru Millenia, India

Yesterday

Associate Director - IT Risk Management

Mmc · Pune - Panchshil, India · Hybrid

2 days ago

IT Risk Analyst

Hiwin · Huntley, IL

2 days ago

Team Lead-IT Risk

Ameriprise Financial · 11073 Ameriprise India - Noida - Embassy Oxygen Business Park +1 · Hybrid

3 days ago

PCI Compliance & IT Risk Management People Leader

Global Payments · GSC Vertis North, Philippines · Hybrid

3 days ago

IT Risk Analyst II

Western Governors University · Salt Lake City Office, United States of America

4 days ago

Staff Engineer, ServiceNow IT Risk & Compliance

TJX · USA Home Office Framingham MA 770 Cochituate Rd, United States of America +2

4 days ago

IT Security Manager - Third-Party IT Risk Manager

Wk · USA - Riverwoods, IL, United States of America +4 · Hybrid

1 week ago

Senior Associate - IT Risk Services

Pwc · Ho Chi Minh City, Vietnam +1

1 week ago

Manager - IT Risk Assurance

Pwc · Ho Chi Minh City, Vietnam +1

1 week ago

Associate - IT Risk Services

Pwc · Hanoi, Vietnam +1

1 week ago

IT Risk & Compliance Engineer (DevOps/Agile)

Ing · Katowice (Zabrska 19), Poland +1 · Hybrid

1 week ago

IT Risk & Compliance Engineer (DevOps/Agile)

Ing · Katowice (Zabrska 19), Poland +1 · Hybrid

1 week ago

Sr. Lead, IT Risk and Controls – KRI Development, Metrics & Automation

NT Careers · Chicago, IL, United States of America · Hybrid

2 weeks ago

Senior Analyst, IT Risk Analytics & Reporting (Global Security)

Rbc · 16 YORK ST:TORONTO, Canada

2 weeks ago

Senior IT Risk Analyst

Wintrust · Rosemont - WTFC - 9801 W Higgins Rd. (0444), United States of America · Hybrid

2 weeks ago

Senior IT Risk & Compliance Analyst

Rbc · RBC WATERPARK PLACE, 88 QUEENS QUAY W:TORONTO, Canada

2 weeks ago

IT Risk & Compliance Analyst

Trinity Church NYC · New York, NY

2 weeks ago

IT Risk & Compliance Officer for Cloud

Urban Connect · Bucharest · Hybrid

2 weeks ago

Senior Director, Vendor IT Risk Management (Global Security)

Rbc · 16 YORK ST:TORONTO, Canada

2 weeks ago

IT Risk Director, Technology Risk Management Resiliency & Business Continuity

Huntington · One South Charlotte Nc, United States of America +5 · Onsite

2 weeks ago

Principal/Senior IT Risk Analyst

Berkshire Hathaway Specialty Insurance · Boston, MA

3 weeks ago

IT Risk Administrator - Hybrid

Revera · Support Office - Ontario, Canada · Remote, Hybrid

3 weeks ago

IT Risk Technical Lead

Freddiemac · Headquarters 1, United States of America

3 weeks ago

IT Risk Senior

Freddiemac · Headquarters 1, United States of America

3 weeks ago

Senior IT Risk Manager (m/w/d)

Creditplus · Stuttgart, Baden-Württemberg

3 weeks ago

IT Risk & Compliance Analyst

Watts Water · No. Andover, MA Chestnut St., United States of America · Remote

3 weeks ago

Auditor, IT Risk and Compliance - Corporate Information Systems Group

Canadian Bank Note Company · Ottawa, ON, Canada · Remote

3 weeks ago

Senior Manager, IT Risk, Data Privacy & Security

EisnerAmper is one of the · Baton Rouge, United States of America

1 month ago
IT Risk & Control Testing Analyst at Bupa Careers • £40k – £60k | Hiring.Camp