ISO 27001 Internal Auditor
Date: 9 Oct 2026
Location: London, GB, EC3M 7AF
Company: Walkers Global

We are a leading international law firm for global corporations, financial institutions, capital market participants and investment fund managers. With a global presence spanning the Americas, Europe, the Middle East and Asia, we advise on the laws of Bermuda, the British Virgin Islands, the Cayman Islands, Guernsey, Ireland and Jersey.
We treat everyone as the intelligent professional they are. Our approach is to trust and empower our people to deliver consistently, and enable them to succeed. Diversity is our secret weapon – it’s the sheer breadth of Walkers people that makes us who we are – gathered from across the globe and fluent in languages, jurisdictions and cultures that help us to mirror our clients and keep our own thinking in tune with the world in which we operate.
Overview of role
Office: London (hybrid 50% required)
An opportunity has arisen for an Internal Auditor to join the firm’s Internal Audit function, with primary responsibility for providing independent assurance over the firm’s Information Security Management System (ISMS) and its alignment with ISO 27001 requirements. The role will plan and perform risk-based audits of the ISMS and applicable Annex A controls, assessing both their design adequacy and operating effectiveness through interviews, process walkthroughs, evidence review and control testing. The successful candidate will produce clear, timely reports setting out audit conclusions, control observations and practical recommendations to support the effective implementation, maintenance and continual improvement of the ISMS. While the role will principally focus on ISO 27001, the Internal Auditor may also support other audits across the Internal Audit plan, including regulatory, financial crime, governance and terms of engagement reviews.
Duties, Responsibilities & Person Specification
- Plan and deliver risk-based internal audits of the ISMS in accordance with the approved Internal Audit plan and established audit methodology.
- Assess the ISMS against the requirements of ISO/IEC 27001, relevant internal policies and procedures, and the firm’s defined information security objectives.
- Evaluate the design adequacy and operating effectiveness of applicable Annex A controls and requirements of the ISO 27001 Standard, including whether controls are appropriately documented, implemented and maintained.
- Perform audit fieldwork through stakeholder interviews, process walkthroughs, document and evidence review, control testing, data analysis and sample-based testing, using both remote and in-person approaches where appropriate.
- Maintain clear and comprehensive audit working papers that accurately document the scope, methodology, evidence reviewed, testing performed, conclusions reached and supporting rationale.
- Identify control weaknesses, non-conformities and opportunities for improvement, assessing their associated risks and potential impact on the effectiveness of the ISMS.
- Prepare clear, concise and balanced audit reports setting out the audit scope, overall conclusions, strengths, findings, root causes, risks and practical recommendations.
- Present and discuss audit findings with relevant stakeholders, constructively challenging management responses and supporting the agreement of proportionate and achievable remedial actions.
- Monitor and validate the implementation of agreed management actions, including reviewing supporting evidence and reporting overdue or insufficiently addressed actions through the appropriate governance channels.
- Support the development of the annual Internal Audit plan by contributing information security insight, identifying emerging risks and recommending areas for future assurance activity.
- Maintain current knowledge of ISO 27001 requirements, information security risks, relevant regulatory developments and industry good practice, incorporating relevant developments into audit planning and testing.
- Support other assignments across the Internal Audit plan, where required, including financial crime, sanctions, governance, operational and terms of engagement audits, and contribute to the continued development of the Internal Audit function.
Education, Skills & Experience
- ISO 27001 Internal Auditor or ISO 27001 Lead Auditor qualification.
- Experience of auditing remote or geographically dispersed operations.
- Practical experience of auditing an ISMS or testing information security and technology control.
- Working knowledge of ISO 27001 and its Annex A controls.
- Experience of preparing audit working papers and communicating findings to management.
- Ability to work independently and manage multiple assignments and stakeholders across different jurisdictions.
- Strong analytical, problem-solving and risk-assessment skills.
- Sound professional judgement, scepticism and attention to detail.
- Excellent written and verbal communication skills, with the ability to explain technical matters clearly.
- Strong stakeholder management skills and confidence in providing constructive challenge.
- High standards of integrity, objectivity, confidentiality and professionalism.
- Well organised and able to manage multiple assignments, priorities and deadlines.
- Commercially aware, with a willingness to support audits outside the ISO 27001 remit.
#LI-Hybrid
#LI-LQ1
Walkers global is an equal opportunity employer. Equality and diversity are key to our global identity and an integral part of our goal to continue being an employer of choice. We are committed to a work environment that supports all individuals irrespective of gender, ethnicity, nationality, race, religion, marital status, age, disability, pregnancy, sexual orientation, gender identity or any other applicable legally protected characteristics. We make every effort to ensure that employment opportunities are open and accessible to all purely on the basis of personal ability.
