Careers
Work here
We are a small assurance practice. That means broader exposure earlier than a large firm typically offers, and less scope to hide behind a methodology.
What working here is like
You will be on client sites, in front of control owners, forming judgements you have to defend. Findings you write go into reports read by audit committees. That is a reasonable amount of responsibility relatively early, and it suits some people considerably better than others.
We support professional certification — CISA, CISM, CRISC, ISO 27001 Lead Auditor and equivalents — because the credential is genuinely part of the job rather than a perk.
What we look for
- The ability to write clearly. Most of this job is writing, and a finding nobody can understand does not get fixed.
- Willingness to be wrong in public. Judgements get challenged by clients who know their environment better than you do.
- Technical depth in at least one area, and genuine curiosity about the others.
- Comfort saying "I do not know, I will find out" rather than improvising.
- Professional scepticism — the discipline of asking for evidence rather than accepting assertion, without becoming adversarial about it.
Current openings
We recruit continuously across IT audit, information security advisory and technical testing at all levels. If you are interested, send a CV and a short note about the work you want to be doing. We read everything that arrives.
Frequently asked questions
Need an independent view?
Tell us the scope, the regulator and the deadline. We will come back with an approach, a team and a fee estimate.
Request a proposal