Lead IT Audit & Controls Manager

Lead IT Audit & Controls Manager – Permanent

At Costa Coffee, we’re on a mission to reimagine coffee experiences across the globe. From bustling cities to local communities, we’re creating meaningful coffee moments, powered by innovation and driven by purpose.

As a proud part of the Coca-Cola system and working hand in hand with our pioneering partners, we’re in over 50 countries and counting. Whether it’s served in-store, from a machine, at home, or on the go, every cup is thoughtfully crafted by our passionate teams who put heart into every moment.

Our teams truly make a difference. Whether it’s pioneering new tech for the perfect pour, launching award-winning campaigns, developing exciting new menu items, or supporting our people to grow – together, we stir up success.

We’re seeking a Risk & Compliance professional to lead the implementation of the SOX IT General Controls framework across the Costa Group. You’ll act as a subject matter expert, guiding complex control processes, influencing senior stakeholders, and embedding compliance across internal teams and third parties. The role also supports IT audit readiness, risk management, and regulatory compliance (e.g. SOX, ISA-315), ensuring governance standards are met and reporting is delivered to senior leadership and The Coca-Cola Company.

With inspiring experiences, development programmes, and our apprenticeship scheme, your career can grow far beyond the day-to-day.

What you’ll do 

Being a Lead IT Audit and Controls Manager is about so much more than bringing our coffee to the world. It’s your chance to stir up real success – which means you will: 

  • Lead the development and implementation of the SOX IT General Controls and Risk & Compliance framework across the Costa Group.
  • Act as a subject matter expert, providing guidance on complex controls and influencing strategic decisions at senior management level.
  • Drive cultural change to embed SOX controls across internal teams and third parties, ensuring compliance and understanding.
  • Support continuous improvement in IT Audit, Risk Management, and regulatory compliance (e.g. SOX, ISA-315) across global operations.
  • Ensure effective risk monitoring, supplier assurance, and regular reporting to senior leadership and The Coca-Cola Company.

Who you are 

It’s your unique ingredients we’re interested in: 

  • Awareness of information and cyber security standards (e.g. ISO27000, NIST, PCI-DSS, CIS) and their relevance in a global retail environment.
  • Familiarity with security tools, processes, and risk management frameworks such as COBIT.
  • Experience working in a global organisation, including engagement with third parties and suppliers.
  • Exposure to developing policies, standards, and guidelines in a large-scale business context.
  • Desirable: Understanding of SOX, ITGC, IT risk, and data protection, with relevant certifications (e.g. CISA, CISSP, CISM) and familiarity with frameworks like ITIL and ISF.

So, why Costa?  

We didn’t become a global coffee brand by sitting back. When you work here, you join a community that values passion, progression, and integrity—with some brilliant perks to sweeten the deal. We work in a hybrid environment, giving us the flexibility to balance life while still spending meaningful time together and building strong connections: 

  • Own a piece of Costa’s success by becoming a share owner in Coca-Cola with our Share Investment Plan (SIP) 
  • An annual discretionary bonus scheme, based on business results and individual contribution.
  • A smart pension that saves you money on tax and national insurance, and matches your contributions up to 10% 
  • The Costa Financial Support Fund, supporting team members who find themselves in unexpected financial pressure 
  • 50% discount in all Costa-owned stores, and 25% off in other participating stores 
  • Private medical cover thanks to our Private Healthcare scheme 
  • And that’s not all. Explore even more of our perks here: https://costaperks 

Location – Hybrid based from London a minimum of 2 days per week.

For any reasonable adjustments and general queries, please contact

We believe in living life with heart – and that starts with our people.
By showing up as our authentic selves, we create a culture where everyone belongs. We celebrate diversity in all its forms and are committed to building an equitable and inclusive environment—one that embraces the unique blend of experiences, identities, and perspectives each person brings. This rich diversity strengthens our teams and reflects the spirit of our global brand.

Grounded in our core values—Passion for Progress, Win with Warmth, Courage to Challenge, and Trusted Team Players—we strive to make a meaningful impact in everything we do. From empowering communities through the Costa Foundation to supporting local initiatives, we’re committed to changing lives in coffee-growing regions and right here at home.

Costa Coffee London