We are looking for an experienced IT Risk & Internal Controls Specialist to join a team responsible for executing second-line-of-defense (LOD2) control testing activities across technology and operational environments. You will play a key role in assessing the effectiveness of internal controls, supporting risk and compliance initiatives, and contributing to the continuous improvement of the Internal Control Framework.
Work Model: Hybrid (days per week in the office – Porto)
Key Responsibilities
- Perform design and operating effectiveness testing of key ICT and operational controls.
- Review, analyze, and validate control evidence provided by control owners.
- Conduct walkthroughs with first-line teams to understand processes and validate control execution.
- Document testing activities, findings, recommendations, and supporting evidence.
- Prepare control assessment reports and communicate results to relevant stakeholders.
- Support the follow-up and tracking of remediation actions resulting from control testing activities.
- Contribute to the maintenance and continuous improvement of the Internal Control Framework.
- Assist in the preparation of management reports and governance committee materials.
- Collaborate with business and support functions to facilitate testing and assessment activities.
- Promote best practices in governance, risk management, and internal controls.
Required Skills & Experience
- Experience in Internal Controls, Internal Audit, Risk Management, Compliance, Information Security, or External Audit.
- Solid understanding of internal control frameworks and governance principles, including COSO.
- Experience assessing and testing controls against recognized standards and regulatory frameworks.
- Knowledge of one or more of the following frameworks and regulations: ISO 27001, ISO 22301, NIST Cybersecurity Framework, CIS Controls, DORA, NIS2, or similar.
- Hands-on experience with control testing, evidence review, walkthroughs, and assessment methodologies.
- Experience preparing findings reports, remediation recommendations, and governance documentation.
- Strong analytical and critical-thinking skills.
- Excellent communication and stakeholder management abilities.
- Ability to work independently while collaborating effectively across multiple teams.
- Strong attention to detail and commitment to delivering high-quality assessments.
- Professional proficiency in English.
If you're passionate about IT Risk, Internal Controls, Governance, and helping organizations strengthen their risk and compliance frameworks, we'd love to hear from you.