Walkers Global
ISO 27001 Internal Auditor

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Overview of Role
Office: London (hybrid 50% required)
An opportunity has arisen for an Internal Auditor to join the firm’s Internal Audit function, with primary responsibility for providing independent assurance over the firm’s Information Security Management System (ISMS) and its alignment with ISO 27001 requirements. The role will plan and perform risk-based audits of the ISMS and applicable Annex A controls, assessing both their design adequacy and operating effectiveness through interviews, process walkthroughs, evidence review and control testing. The successful candidate will produce clear, timely reports setting out audit conclusions, control observations and practical recommendations to support the effective implementation, maintenance and continual improvement of the ISMS. While the role will principally focus on ISO 27001, the Internal Auditor may also support other audits across the Internal Audit plan, including regulatory, financial crime, governance and terms of engagement reviews.
Duties, Responsibilities & Person Specification
- Plan and deliver risk-based internal audits of the ISMS in accordance with the approved Internal Audit plan and established audit methodology.
- Assess the ISMS against the requirements of ISO/IEC 27001, relevant internal policies and procedures, and the firm’s defined information security objectives.
- Evaluate the design adequacy and operating effectiveness of applicable Annex A controls and requirements of the ISO 27001 Standard, including whether controls are appropriately documented, implemented and maintained.
- Perform audit fieldwork through stakeholder interviews, process walkthroughs, document and evidence review, control testing, data analysis and sample-based testing, using both remote and in-person approaches where appropriate.
- Maintain clear and comprehensive audit working papers that accurately document the scope, methodology, evidence reviewed, testing performed, conclusions reached and supporting rationale.
- Identify control weaknesses, non-conformities and opportunities for improvement, assessing their associated risks and potential impact on the effectiveness of the ISMS.
- Prepare clear, concise and balanced audit reports setting out the audit scope, overall conclusions, strengths, findings, root causes, risks and practical recommendations.
- Present and discuss audit findings with relevant stakeholders, constructively challenging management responses and supporting the agreement of proportionate and achievable remedial actions.
- Monitor and validate the implementation of agreed management actions, including reviewing supporting evidence and reporting overdue or insufficiently addressed actions through the appropriate governance channels.
- Support the development of the annual Internal Audit plan by contributing information security insight, identifying emerging risks and recommending areas for future assurance activity.
- Maintain current knowledge of ISO 27001 requirements, information security risks, relevant regulatory developments and industry good practice, incorporating relevant developments into audit planning and testing.
- Support other assignments across the Internal Audit plan, where required, including financial crime, sanctions, governance, operational and terms of engagement audits, and contribute to the continued development of the Internal Audit function.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Education, Skills & Experience


Get help with your application
Your very own career expert that helps elevate your application to the next level.
- ISO 27001 Internal Auditor or ISO 27001 Lead Auditor qualification.
- Experience of auditing remote or geographically dispersed operations.
- Practical experience of auditing an ISMS or testing information security and technology control.
- Working knowledge of ISO 27001 and its Annex A controls.
- Experience of preparing audit working papers and communicating findings to management.
- Ability to work independently and manage multiple assignments and stakeholders across different jurisdictions.
- Strong analytical, problem-solving and risk-assessment skills.
- Sound professional judgement, scepticism and attention to detail.
- Excellent written and verbal communication skills, with the ability to explain technical matters clearly.
- Strong stakeholder management skills and confidence in providing constructive challenge.
- High standards of integrity, objectivity, confidentiality and professionalism.
- Well organised and able to manage multiple assignments, priorities and deadlines.
- Commercially aware, with a willingness to support audits outside the ISO 27001 remit.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London