Director, Technology, Cyber & Resilience Risk

Company: London Stock Exchange Group
Apply for the Director, Technology, Cyber & Resilience Risk
Location: London
Job Description:

Overview

In this role you lead the Technology Risk & Operational Resilience capability across DSM, FX, and Risk Intelligence, owning the first-line risk environment and ensuring adherence to risk appetite and regulatory expectations. You will embed robust controls, resilience practices, and data-led assurance across platforms, collaborating with senior stakeholders. Your work shapes engineering delivery with risk-informed perspectives and drives remediation of material issues. This role offers strategic impact by aligning technology risk with business outcomes and regulatory needs.

Pay / Benefits

  • healthcare
  • retirement planning
  • paid volunteering days
  • wellbeing initiatives

Responsibilities

  • Own 1LoD technology risk profile and alignment with risk appetite
  • Manage the technology control framework across applications, infrastructure, cloud, and cyber; define testing approaches and assurance mechanisms
  • Lead operational resilience implementations (IBS, impact tolerances, scenario testing) and embed resilience in architecture and change processes
  • Provide independent first-line challenge to engineering, architecture, and product teams; escalate material risk decisions
  • Own responses to audits/regulatory reviews; track remediation and provide evidence and assurance quality
  • Oversee third-party and cloud risk, including TPRM lifecycle and cloud risk alignment with enterprise standards
  • Own risk data, MI & reporting; define KRIs, KPIs, KCIs; ensure decision-ready data
  • Define and grow a high-performing risk team and a clear RACI across first and second lines

Key requirements

  • Senior leadership in technology risk within regulated financial services
  • Ownership of control frameworks aligned to NIST, ISO, COBIT
  • Proven governance and remediation of systemic risk issues
  • Operational resilience and incident management expertise
  • Experience engaging with regulators and executive stakeholders
  • Cloud and third-party risk oversight
  • Strong decision-making and challenge capability
  • Executive communication and regulatory engagement
  • Stakeholder alignment across complex landscapes
  • NIST, ISO, COBIT-aligned control frameworks
  • Operational resilience and incident management
  • Regulatory and risk governance processes

…

Posted: October 1st, 2026