General Information

Position
Senior Consultant | IT Audit & Assurance
Work arrangement
Plný pracovní úvazek
City
Bukurešť
Country
Rumunsko
Department
Audit & Assurance
Team
Audit Information Technology Development
Area of interest
Audit, IT Audit
Way of work
Hybridní model

Description & Requirements

Who we are looking for
Deloitte Romania is looking for a Senior Consultant to join our IT Audit & Assurance team.

We support organizations in understanding technology risks, strengthening their IT control environments and meeting financial reporting, assurance and regulatory requirements. Our clients include banks, insurance companies, technology businesses, outsourcing providers and other organizations operating in complex or regulated environments.

As a Senior Consultant, you will take ownership of defined project workstreams, work directly with client stakeholders and contribute to the delivery of high-quality IT Audit and Technology Assurance engagements. The role offers exposure beyond recurring IT general controls testing, including regulatory IT audits, SOC engagements, IT internal audits, cybersecurity assurance, IT governance and broader technology-risk assessments.

  • Approximately 3–5 years of relevant professional experience in IT Audit, Technology Risk, IT Internal Audit, IT Controls, Information Security Assurance, IT Risk and Compliance or a related field.
  • Practical knowledge of IT general controls and common technology risks.
  • Experience delivering defined project workstreams with a reasonable level of independence.
  • The ability to understand technology processes, analyse evidence, identify inconsistencies and reach clear, supportable conclusions.
  • Strong documentation and report-writing capabilities.
  • Confidence in communicating with both technical and non-technical stakeholders.
  • The ability to organise competing priorities and deliver work within agreed timelines.
  • A strong sense of ownership, professional judgement and attention to quality.
  • Professional proficiency in both Romanian and English.
  • CISA certification or a commitment to obtain it within the first six months after joining.
Experience that would be valuable:
The following would be considered an advantage but is not mandatory:
  • Previous experience within a Big Four firm or another professional-services organisation.
  • Experience in financial services, technology, outsourcing, shared-service centres or other regulated industries.
  • Exposure to technology procedures supporting financial statement audits.
  • Experience with SOC 1, ISAE 3402 or SOC 2 engagements.
  • Experience performing IT internal audits or regulatory IT assessments.
  • Familiarity with frameworks and standards such as COBIT, ISO 27001, NIST or ITIL.
  • Experience with ERP platforms, cloud environments, identity and access management or complex IT infrastructure.
  • Exposure to cybersecurity assurance, operational resilience, DORA, NIS2 or Romanian financial-sector regulatory requirements.
  • Experience coordinating junior colleagues or managing defined engagement workstreams.
  • Additional qualifications such as CISM, CRISC, CISSP, CCSP, CIA, ISO 27001 Lead Auditor or relevant EC-Council certifications.
  • You are not expected to have prior experience in every service area. We are interested in candidates with a solid IT risk and controls foundation who are motivated to expand their technical and client-facing capabilities.

Your future role
  • Deliver IT Audit and Technology Assurance workstreams, from planning and process understanding through testing, issue evaluation and reporting.
  • Understand clients’ business processes, technology environments, key systems and technology-related risks.
  • Assess IT general controls across areas such as user access management, privileged access, change management, system development, IT operations, incident management, backup, recovery and business continuity.
  • Test automated controls, system interfaces and system-generated reports.
  • Support technology-related audit procedures performed as part of financial statement audits.
  • Participate in regulatory IT audits and assessments covering NIS and NIS2, DORA, applicable BNR and ASF regulations, and requirements overseen by ADR.
  • Contribute to SOC 1, ISAE 3402 and SOC 2 readiness and assurance engagements.
  • Participate in IT internal audits, cybersecurity and information-security reviews, IT governance assessments and other technology-risk engagements.
  • Analyse audit evidence, identify control deficiencies and assess their potential business, regulatory and financial-reporting impact.
  • Prepare clear, structured and evidence-based working papers, observations, recommendations and reports.
  • Discuss processes, findings and recommendations with stakeholders from IT, information security, risk, compliance, finance and internal audit.
  • Coordinate junior colleagues, provide practical guidance and review selected elements of their work.
  • Contribute to proposals, internal knowledge-sharing, methodology development and the continued growth of our IT Audit and Assurance services.

What we offer
  • A varied portfolio of IT Audit and Assurance engagements, with opportunities to develop beyond recurring ITGC testing.
  • Exposure to regulatory IT audits, SOC reporting, cybersecurity assurance, cloud governance, IT internal audit, technology risk and other specialist areas.
  • The opportunity to work with complex organisations and engage directly with senior stakeholders across multiple industries.
  • Increasing ownership of project workstreams, client discussions, issue evaluation, reporting and the development of junior colleagues.
  • Structured learning, practical coaching and regular feedback from experienced professionals.
  • Access to LinkedIn Learning, Udemy and Deloitte’s internal learning resources.
  • Full payment of examination fees and related preparation training for approved IT audit, risk and cybersecurity certifications, including CISA and other relevant qualifications issued by professional bodies such as ISACA, ISC2 and EC-Council, based on your role and development objectives.
  • Opportunities to collaborate with specialists from Deloitte Romania and, where relevant to the engagement, colleagues from the wider Deloitte network.
  • A transparent development path towards engagement coordination, team leadership and broader client responsibility.
  • A hybrid working model, with two days per week in the office, balanced with client, project and team requirements.
  • A flexible benefits budget that can be used according to individual preferences and the available company benefits framework.
  • Access to employee assistance, support and wellbeing resources.
  • Eligibility for an annual performance bonus, based on individual and firm performance.

Selection process
We welcome applications from professionals with experience in IT Audit, Technology Risk, IT Controls, internal audit, information security, IT risk and compliance, technology governance or other relevant assurance and control roles.

You do not need to meet every preferred criterion to apply. We are looking for people with sound professional judgement, a strong foundation in IT risks and controls, and the motivation to take greater ownership of client delivery and their continued professional development.

#LI-BV1