CFGI
IT Risk Advisory - Consultant

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
IT Risk Advisory – Consultant
CFGI Consultants work as part of a team with other CFGI professionals, our clients, and their external auditors or other professional services firms across a variety of IT Risk Advisory engagements.
Our work may include IT Internal Audit, SOX implementation and testing, attestation and certification readiness, business process improvement, compliance assessments, and other technology risk initiatives.
Roles & Responsibilities:
As a Consultant, you will support project teams across all stages of client engagements. Responsibilities may include:
- Performing IT controls testing and documenting results.
- Preparing process narratives, flowcharts, and other documentation used in audit, compliance, and risk assessments.
- Drafting engagement scopes, project plans, risk assessments, testing approaches, and specific procedures.
- Analysing IT-related information and supporting documentation.
- Interviewing client contacts to understand processes, systems, risks, and controls.
- Identifying opportunities for process improvement and additional value for clients.
- Developing strong working relationships with client contacts.
- Assisting with engagement planning, delivery, and economics.
- Supporting internal training, team initiatives, and the continued development of CFGI’s Risk Advisory practice.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
What you must have:
- 3–5 years of experience in public accounting or industry performing IT audit, systems implementation, information security, or related technology risk work.
What sets you apart:
- Experience performing IT controls testing and documenting IT processes, risks, and controls.
- Experience supporting IT audit, SOX, compliance, information security, or other technology risk assessments.
- Experience preparing risk assessments, testing approaches, project plans, or related audit and advisory documentation.
- Experience working with IT General Controls and technology-related control environments.
- Experience participating in client interviews and developing findings or recommendations from assessment results.
- Experience supporting multiple workstreams, deliverables, or project activities within an audit or advisory environment.
Nice to have:
- Progress toward CISA, CIA, or another recognised audit, risk, or information security certification is preferred.
- Experience with SOX IT General Controls, COSO, SOC 1, or SOC 2 is preferred.
- Exposure to ISO 27001, NIST, HIPAA, FAIR, or other relevant information security, risk, or compliance standards is advantageous.
- A university degree is preferred; significant progress toward an appropriate professional certification may be considered in lieu of a degree.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Who thrives here:
- Strong interpersonal, written, and verbal communication skills.
- Effective analytical and critical-thinking abilities.
- Strong organisational and project-management skills.
- A proactive, entrepreneurial, and self-motivated approach.
- Dependable and committed to high-quality client service.
- Comfortable collaborating in a team-oriented environment.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location