About this role
The Convex Internal Audit team provides independent, objective assurance and insight designed to protect organisational value, strengthen risk management and governance frameworks, and evaluate the internal control environment as Convex continues to scale. While we operate as an independent function, we view audit as a collaborative journey rather than a box-ticking exercise. We work side-by-side with teams across the organisation to help Convex reach its ambitious commercial goals, all while keeping a steady focus on robust internal controls and high-quality risk assurance. Using data-driven insights and a flexible, risk-based approach, we help protect the business and drive operational excellence every day.
Our success relies on genuine partnership, trust, and shared values. Within the department, we champion an open, supportive culture where clear communication, integrity, and continuous professional development take priority.
We believe the best audit outcomes come from empowering our people, which is why we invest heavily in regular training, dedicated career conversations, and overall well-being. It is all about combining sharp control and objective assurance with a warm, high-engagement mindset that adds real value to the organisation.
Technology is at the heart of Convex’s mission to redefine insurance. As a Returner in IT Audit, you will focus on evaluating risks and controls within our fast paced and growing digital landscape, including core underwriting systems, cloud infrastructure, data governance, cyber security, and third-party IT providers. This non-managerial position is designed to help you refresh and apply your technology risk expertise within a supportive and highly modern tech environment.
Key Responsibilities
- IT risk assessment: engage with IT and security teams to understand our technology roadmap, key software assets, and emerging digital risks.
- Technical audit planning: assist in drafting audit plans focused on IT General Controls (ITGCs), cyber security frameworks, change management, and data integrity.
- Audit execution: evaluate the design and operational effectiveness of IT controls, identifying system vulnerabilities, data quality concerns, or compliance gaps.
- Reporting & collaboration: formulate clear, non-technical explanations of complex IT risks and present them alongside practical, technology-driven recommendations to management.
- Continuous monitoring: monitor technology developments and collaborate with IT stakeholders to ensure robust implementation of agreed remediation actions.
Skills Knowledge and Expertise
- You hold a relevant professional certification (such as CISA, CRISC, CISSP, ACA, or equivalent) and have prior experience in IT audit, technology risk consulting, or IT control environments.
- You are returning from a career break of 2 years or more and are keen to re-apply your technology risk expertise in a modern, cloud-first organisation.
- A natural curiosity about emerging technologies (such as cloud computing, AI, and modern data platforms) and how they integrate into business processes.
- The ability to translate technical IT risk issues into clear, commercial language for non-technical stakeholders.
- A proactive attitude that thrives on teamwork, sharing insights, and working together to improve our overall security and operational posture.
Benefits
- Competitive Salary
- 30 days Annual Leave
- Birthday Leave
- 10% Employer Pension Contribution
- Private Health Insurance Medical Cover
- Group Income Protection
- Life Assurance Cover
- Enhanced Parental Leave
- Annual Health Check
- 3 days of Volunteer Leave each year
- £1,300 to spend on learning & wellbeing
- Give as You Earn
- Cycle to Work
- Season Ticket Loan