Head of Internal Audit

Iris Software
United Kingdom
Last week
Job Type
Permanent
Work Pattern
Full-time
Work Location
On-site
Seniority
Director
Education
Degree
Posted
22 May 2026 (Last week)

Head of Internal Audit

UK Based (travel occasionally required)

Competitive Salary

Permanent Full Time Position

About the Role

IRIS Software Group is establishing its first in-house Internal Audit function following two successful years of a fully outsourced model.

As Head of Internal Audit, you will build and lead a modern, insight-led assurance capability across IRIS’s multi-product SaaS portfolio, including accountancy, payroll/HCM, and education, as well as core group functions and processes.

This role combines Third Line (Internal Audit) leadership with support from a co-sourced partner providing internal audit, IT audit, and risk expertise, including specialist areas such as Cyber, Cloud, and Data Privacy.

This is a strong opportunity for a high-performing No.2 ready to step up into their first Head of role, with direct exposure to the Audit & Risk Committee and a clear mandate to build the function.

Key Responsibilities

*

Own and deliver a dynamic, risk-based internal audit plan aligned to strategic objectives, major change, and principal risks, while establishing the Internal Audit Charter, methodology, and quality framework in line with IIA Global Internal Audit Standards

*

Lead end-to-end audits across operational, financial, compliance, product/technology, and change domains, directing co-sourced SMEs where required, and introducing agile, data-enabled auditing techniques to increase coverage and reduce cycle time

*

Report impactful findings to management and the Audit & Risk Committee, driving timely action closure with a root-cause focus, and plan for an External Quality Assessment (EQA) within 3–5 years

*

Develop an analytics roadmap and implement dashboarding (e.g. Power BI) to support continuous auditing, action tracking, audit KPIs, and risk/trend insights

*

Manage the co-sourced model, working with external partners to flex capability (Cyber, Cloud, Data, Privacy, Regulatory), setting SoWs and SLAs, ensuring quality standards, and enabling knowledge transfer

*

Partner with the Second Line to map and enhance financial, operational, IT (including cyber), and compliance controls, promoting control rationalisation, automation, and over time establishing a control testing programme

*

Provide independent assurance over major change programmes (e.g. product launches, cloud migrations, ERP/HRIS upgrades) and support M&A integration reviews in line with the IRIS M&A Playbook

*

Perform or support internal investigations, drawing on co-sourced expertise as required

*

Facilitate risk-based BCM/DR testing and oversee post-incident reviews to capture control learnings across cyber, technology, and operations

What we're looking for:

Experience

*

10–15+ years in Internal Audit, ideally within SaaS/technology, payroll, or fintech/payments environments

*

Proven track record leading complex audits end-to-end

*

Exposure to technology and cyber risks (hands-on or via SMEs)

*

Experience working in co-sourced and high-change environments

*

M&A integration experience desirable

Qualifications

*

Professional: CMIIA/CIA and/or ACA/ACCA

*

Desirable: CISA, CRISC, ISO 27001 Lead Auditor/Implementer; PRINCE2/AgilePM/Scrum

*

Familiarity with IIA Global Standards (2024), ISO 31000, and UK GDPR

Skills & Attributes

*

Clear, confident communicator with strong executive-level presentation skills

*

Builder’s mindset with a pragmatic, outcome-focused approach

*

Strong understanding of current technology risks and ability to direct SMEs effectively

*

Excellent planning, prioritisation, and vendor/contract management skills

*

Independent and confident in challenging where needed, with a collaborative approach

*

Experience working with US regulated companies or within US jurisdiction is highly desirable

Related Jobs

View all jobs

Technology Governance Lead - GRC

Intec Select London, City And County Of the City Of London, United Kingdom
£65,000 – £80,000 pa Hybrid

Field Marketing Specialist, EMEA

Palo Alto Networks London, UB8 1LQ, United Kingdom

Head of Cyber Security

Hays Technology Glasgow, City Of Glasgow, G2 1AL, United Kingdom
£80,000 – £89,000 pa

Professor and Head of Department of Computing, Security and Mathematics

Royal Holloway University of London Egham, London, United Kingdom
£85 pa On-site

Lecturer/Senior Lecturer in Computer Science (Cyber and Networking)

Oxford Brookes University Oxford, South East England, United Kingdom
£41 – £58 pa On-site

Security Architect (we have office locations in Cambridge, Leeds and London)

Genomics England London, United Kingdom
On-site Clearance Required

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Where to Advertise Cyber Security Jobs in the UK (2026 Guide)

Where to advertise cyber security jobs UK in 2026: the specialist boards, communities and channels that reach offensive, defensive and GRC security talent. The candidate pool is small, heavily vetted and in high demand across government, financial services, critical national infrastructure and the private sector simultaneously. Many of the strongest candidates hold active security clearances, are not actively job-searching through general platforms, and move primarily through specialist networks and trusted referrals. General job boards reach a broad audience but lack the specificity that security professionals expect. Specialist platforms, government-affiliated channels and cleared candidate networks each serve a different part of the market. This guide, published by CybersecurityJobs.tech, covers where to advertise cyber security roles in the UK in 2026, how the main platforms compare, what employers should expect to pay, and what the data says about hiring across different role types.

Cyber Security Jobs UK 2026: What to Expect Over the Next 3 Years

Cyber Security Jobs UK 2026: roles, salaries and the threat intelligence, cloud security and zero-trust hiring trends shaping UK cyber careers. Cyber security is one of the few sectors where demand for talent has never once dipped. Every major technological shift of the past decade — cloud migration, remote working, AI adoption, the proliferation of connected devices — has expanded the attack surface that security professionals are expected to defend. And every expansion of that attack surface has generated more jobs. But the cyber security jobs market of 2026 is not simply a larger version of what it was three years ago. It is a structurally different market. The threats have evolved, the technologies used to combat them have changed, the regulatory environment has tightened considerably, and the roles being created reflect all of that. A job seeker who understands only the cyber security landscape of 2023 is already working with an outdated map. The candidates who will thrive over the next three years are those who understand where the sector is heading — which specialisms are attracting the most investment, which technologies are reshaping defensive and offensive security practice, and how the definition of a cyber security professional is broadening well beyond the traditional image of a network defender in a SOC. This article breaks down what the UK cyber security jobs market is likely to look like through to 2028 — covering the titles emerging right now, the technologies driving employer demand, the skills that will matter most, and how to position your career ahead of the curve.