General Manager - ICT Audit
Location of Post
There is currently one permanent and whole-time vacancy available.
HSE Internal Audit have offices in the following locations;
· Internal Audit, Phoenix Hall, St Mary's Hospital, Phoenix Park, Chapelizod, Dublin 20 D20 CK33;
· Internal Audit Unit, Bective Street, Kells, Co Meath A82 NX32;
· Gilligan House, Louth County Hospital, Dublin Rd, Dundalk A91 D762;
· Primary Care Building, St. Loman's Campus, Mullingar, Co. Westmeath;
· Scott Building, MRHT Campus, Arden Rd, Tullamore, Co. Offaly, R35 NY51;
· Internal Audit, Lacken, Dublin Road, Kilkenny R95 NV08;
· HSE South, Áras Slainte, Wilton Road, Cork;
· Internal Audit Unit, HSE West, Merlin Park University Hospital, Galway, H91 N973;
· Internal Audit, HSE, Holland Road, National Technology Park, Limerick
The Deputy Chief Internal Auditor, ICT Audit and Data Analytics Unit, is open to engagement in respect of flexibility around location subject to agreement at an agreed HSE office location.
The post holder will be assigned initially to theICT Audit and Data Analytics Unit in the Internal Audit function. The post holder will be required as part of the role to travel to locations throughout the HSE.
A panel may be formed as a result of this campaign for General Manager - ICT Audit within the ICT Audit and Data Analytics Unit, Internal Audit,from which current and future, permanent and specified purpose vacancies of full or part-time duration may be filled.
Key working relationships
To work collaboratively with colleagues in Internal Audit and management of business units and divisional units within the HSE. To develop and maintain positive working relationships with key stakeholders both internal and external.
Purpose of the Post
Be responsible for leading and overseeing the assessment of the effectiveness, security, and compliance of the HSE’s IT systems, infrastructure, and related controls. The post holder will plan, manage, and deliver a programme of IT audits, co-sourced with an external services provider, to identify technology risks and provide assurance to senior management and the Audit & Risk Committee on the adequacy of controls supporting clinical, operational, and corporate systems.
The role involves evaluating cybersecurity arrangements, data protection controls, and IT governance frameworks, and making evidence-based recommendations to enhance resilience, regulatory compliance, and operational efficiency in a complex healthcare environment.
Working closely with senior HSE management, ICT management (Technology & Transformation), clinical stakeholders, Internal Audit colleagues, and outsourced providers, the General Manager - ICT Audit will support the delivery of the annual Internal Audit Plan and strategies.
All audit activity will be conducted in accordance with the Global Internal Audit Standards (IIA) and relevant regulatory requirements, ensuring the safeguarding of the organisation’s digital assets, information systems, and patient data.
Principal Duties and Responsibilities
Responsibilities include but are not limited to:
Strategic Leadership in an IT Audit Function
· Support the Deputy Chief Internal Auditor, ICT and Data Analytics Unit in the development and delivery of the annual ICT audit plan, implementing a risk-based audit strategy aligned with organisational objectives, regulatory requirements, and emerging technology risks.
· Collaborate with HSE senior management / business owners, Internal Audit team members, co-source audit partners, auditees, regulatory bodies, and other stakeholders to ensure effective communication and coordination of IT audit activities. Manage on-going relationships with key stakeholders to understand pending / on-going IT developments across the business.
· Provide strategic oversight of IT, digital, and cybersecurity risks across the organisation, ensuring appropriate assurance coverage of critical systems and infrastructure.
· Ensure the delivery of high-quality, timely IT audit engagements that assess the adequacy and effectiveness of IT governance, risk management, and control frameworks.
· Advise the Internal Audit Leadership Team (IALT) on emerging technology risks, digital transformation initiatives, and associated assurance requirements.
· Contribute to the development and continuous improvement of Internal Audit methodologies, incorporating technology-enabled audit techniques and automation where appropriate.
· Ensure performance of the role aligns with Global Internal Audit Standards (IIA) and IT governance standards.
· Provide assurance regarding compliance with relevant legislation, regulatory requirements, and internal policies relating to IT systems, cybersecurity, and data protection.
IT Governance, Risk & Control Assurance
· Provide independent assurance over IT governance structures, policies, and processes, ensuring alignment with recognised frameworks and best practice.
· Evaluate the design and operating effectiveness of IT general controls (ITGCs), including access management, change management, system development lifecycle, business continuity, and disaster recovery controls.
· Assess the adequacy of controls relating to major ICT programmes, digital transformation initiatives, and third-party service providers.
· Ensure appropriate oversight of IT risk registers, control remediation plans, and management action tracking.
· Identify control weaknesses, root causes, and systemic issues, providing clear and practical recommendations to strengthen governance and resilience.
Cybersecurity & Digital Risk Oversight
· Provide assurance over cybersecurity governance, policies, and control environments, including incident response, vulnerability management, and threat monitoring arrangements.
· Review organisational preparedness for cyber incidents, including testing of business continuity and disaster recovery capabilities.
· Monitor developments in the external threat landscape and emerging technologies to inform audit planning and risk assessment.
· Engage with relevant stakeholders to ensure robust governance over data protection, privacy, and secure information management practices.
Audit Delivery & Quality Assurance
· Lead and oversee complex IT audit engagements from planning through to reporting and follow-up, ensuring compliance with Internal Audit standards and methodologies.
· Review audit findings to ensure clarity, accuracy, risk alignment, and practical recommendations.
· Ensure timely reporting of significant IT risks and control issues to senior management, the Audit and Risk Committee, and other governance forums as required.
· Maintain effective quality assurance processes, ensuring consistency, objectivity, and professional standards across all IT audit activity.
· Manage audit risks, issues, dependencies, and resource allocation to ensure delivery of the annual IT audit plan.
Innovation & Continuous Improvement
· Promote the use of technology-enabled auditing techniques, including automation and data analytics, to enhance audit effectiveness and efficiency.
· Evaluate emerging technologies and digital initiatives to ensure assurance approaches evolve in line with organisational change.
· Contribute to building a forward-looking IT audit capability that anticipates and responds to evolving digital risks.
· Stay abreast of developments in IT governance, cybersecurity, and audit best practice to ensure the function remains current and effective.
Stakeholder Engagement & Representation
· Build and maintain effective working relationships with senior management, ICT leadership (Technology & Transformation), risk management functions, and other key stakeholders.
· Present complex IT audit findings clearly and concisely to senior leadership and governance committees.
· Provide balanced, constructive challenge while maintaining independence and objectivity.
· Contribute to fostering a strong culture of accountability, governance, and risk awareness across the organisation.
Team Leadership
As the IT Audit function evolves, the General Manager – ICT Audit will be required to:
· Lead, manage, and develop IT audit staff, ensuring appropriate technical capability and professional development.
· Assign workloads appropriately and monitor the timely completion of assignments.
· Review team performance and ensure quality standards are consistently maintained.
· Create and sustain a positive working environment that promotes collaboration, accountability, and continuous learning.
· Manage team performance, addressing underperformance promptly and constructively.
General
· Act as spokesperson for the Organisation as required.
· Demonstrate pro-active commitment to all communications with internal and external stakeholders
· Engage in the HSE performance achievement process in conjunction with your Line Manager and staff as appropriate.
· Have a working knowledge of the Health Information and Quality Authority (HIQA) Standards as they apply to the role for example, Standards for Healthcare, National Standards for the Prevention and Control of Healthcare Associated Infections, Hygiene Standards etc. and comply with associated HSE protocols for implementing and maintaining these standards as appropriate to the role.
· Support, promote and actively participate in sustainable energy, water and waste initiatives to create a more sustainable, low carbon and efficient health service.
The above job specification is not intended to be a comprehensive list of all duties involved and consequently, the post holder may be required to perform other duties as appropriate to the post which may be assigned to them from time to time and to contribute to the development of the post while in office.
Eligibility Criteria
Qualifications and/ or experience
Candidates must have at the latest date of application:
· Hold a major academic award at Level 7 or higher on the National Framework of Qualifications (NFQ) maintained by Quality & Qualifications Ireland (QQI) in a relevant field, i.e. ICT, Data Analytics, Computer Science, Engineering or a related discipline.
AND
· Professional IT Audit qualification such as CISA, CISM, CRISC or equivalent.
AND
· A Minimum of 3 years’ experience in an IT Audit or an IT Security Function
· Experience of managing and working collaboratively with multiple internal and external stakeholders in an ICT audit or IT security environment with a demonstrated understanding of audit methodologies and risk management.
· Experience in reviewing compliance with relevant IT security and privacy regulations, standards and policies.
· Experience in managing IT Audit teams.
· Have the requisite knowledge and ability (including a high standard of suitability and management ability) for the proper discharge of the duties of the office.
Health
A candidate for and any person holding the office must be fully competent and capable of undertaking the duties attached to the office and be in a state of health such as would indicate a reasonable prospect of ability to render regular and efficient service.
Character
Each candidate for and any person holding the office must be of good character.
Other requirements specific to the post
Access to appropriate transport to fulfil the requirements of the role as post may involve some travel.
Additional eligibility requirements:
Citizenship requirements
Eligible candidates must be:
(i) EEA, Swiss, or British citizens
OR
(ii) Non-European Economic Area citizens with permission to reside and work in the State
Read Appendix 2 of the Additional Campaign Information for further information on accepted Stamps for Non-EEA citizens resident in the State, including those with refugee status.
To qualify candidates must be eligible by the closing date of the campaign.
Skills, competencies and/or knowledge
Professional Knowledge & Experience
Demonstrate:
· Comprehensive knowledge of the role, remit, and responsibilities of the Internal Audit function within a healthcare environment, including the provision of independent and objective assurance, support for effective governance, and the strengthening of risk management and internal control frameworks.
· Strong understanding of the key challenges, risks, and operational pressures facing the health system, including those arising from digital transformation, cybersecurity threats, data protection, and reliance on complex ICT systems.
· Working knowledge of the Global Internal Audit Standards (GIAS) and Health Information and Quality Authority (HIQA) Standards, and the ability to apply these standards in the planning, delivery, and reporting of IT audit work.
· Knowledge of relevant legislation, regulatory requirements, and HSE policies impacting ICT governance, information security, data protection, and technology-enabled service delivery.
· Proven knowledge and experience of IT audit best practice, including the audit of ICT operations, major systems, projects and programmes, and third-party / outsourced ICT services.
· Familiarity with recognised project and programme management methodologies, including risk, issue, and control management.
· Demonstrated ability to influence and engage effectively with senior stakeholders and management to support positive audit outcomes.
· Knowledge of the HSE and the broader health service structure.
· Commitment to ongoing professional development and maintaining up-to-date knowledge of emerging technology risks and audit practices.
· Strong knowledge of IT governance frameworks, industry standards, and regulatory requirements e.g. NIST Cyber Security Framework, NIS / NIS2 Directive
Critical Analysis, Problem Solving and Decision Making
Demonstrate:
· Strong professional judgement, with the ability to challenge constructively, maintain independence, and uphold the highest standards of integrity in complex and sensitive environments.
· Ability to make sound, evidence-based decisions in situations involving limited, complex, or rapidly changing information, often under tight timeframes.
· Capacity to evaluate options, involve relevant stakeholders at the appropriate level, and reach balanced and timely conclusions.
· Ability to anticipate emerging issues and risks, escalating and engaging others appropriately to support effective resolution.
· Ongoing review and evaluation of audit evidence to ensure conclusions and recommendations remain robust and evidence based.
Managing & Delivering Results (Operational Excellence)
Demonstrate:
· Proven ability to plan, prioritise, and manage a diverse portfolio of work, balancing competing demands and deadlines while maintaining high-quality outputs and effective working relationships.
· Strong programme and audit planning skills, with evidence of successful delivery of complex work programmes.
· Effective resource management skills, including an understanding of value for money and efficient use of internal and co-sourced audit resources.
· High levels of personal drive and resilience, with the ability to identify and seize opportunities that contribute to organisational objectives.
· Demonstrated ability to negotiate realistic deliverables and ensure delivery against demanding objectives.
· A strong focus on performance, quality, and continuous improvement, including the monitoring and measurement of outcomes.
· Ability to take initiative, assume ownership, and drive work to completion.
· Adequately identifies, manages and reports on risk within area of responsibility
Leadership & Direction
Demonstrate:
· Effective leadership in a demanding environment, including evidence of driving innovation, improvement, and enhanced ways of working.
· Ability to lead, manage, and motivate audit teams and co-sourced providers to deliver high-quality assurance services.
· Strong capability to work collaboratively with multidisciplinary teams and a wide range of stakeholders to achieve agreed objectives and high performance.
Communication & Interpersonal Skills
Demonstrate:
· Excellent interpersonal and communication skills, enabling effective engagement with stakeholders at all levels of the organisation.
· Ability to present complex technical and audit information clearly, concisely, and confidently in both written reports and verbal presentations.
· A proven track record of building and sustaining effective internal and external relationships to support audit delivery and organisational goals.
· Strong influencing and negotiation skills to support the objectives of the role and drive agreed actions.
· Commitment to open, constructive, and professional dialogue in addressing work-related issues.
Personal Commitment & Motivation
Demonstrate:
· High levels of self-motivation, professionalism, and commitment to delivering consistently high standards of performance.
· Ability to manage challenging and sensitive situations constructively and with resilience.
· Willingness to learn from experience and proactively identify opportunities for personal and professional development.
· Capacity to manage competing pressures without adverse impact on performance or quality.
· A service user–centred approach, recognising the importance of ICT assurance in supporting safe and effective patient care.
· Demonstrated alignment with, and commitment to, the core values and ethos of the HSE, with a strong focus on excellence and continuous improvement.
Remuneration
The salary scale for the post is: as at 01/06/2026
€ 87,471 89,679 93,178 96,703 100,200 103,706 108,804
New appointees to any grade start at the minimum point of the scale. Incremental credit will be applied for recognised relevant service in Ireland and abroad (Department of Health Circular 2/2011). Incremental credit is normally granted on appointment, in respect of previous experience in the Civil Service, Local Authorities, Health Service and other Public Service Bodies and Statutory Agencies.
CLICK THE APPLY BUTTON TO GO TO THEIR CAREERS PAGE WHERE YOU CAN CHECK THIS JOB AND ALL OTHER OPPORTUNITIES AVAILABLE
Before you go
By creating a job alert, you agree to our Terms. You can unsubscribe from these directly within the emails or as detailed in our terms.
Continue to job