Overview
In this role you lead the Technology Risk & Operational Resilience capability across DSM, FX, and Risk Intelligence, owning the first-line risk environment and ensuring adherence to risk appetite and regulatory expectations. You will embed robust controls, resilience practices, and data-led assurance across platforms, collaborating with senior stakeholders. Your work shapes engineering delivery with risk-informed perspectives and drives remediation of material issues. This role offers strategic impact by aligning technology risk with business outcomes and regulatory needs.
Pay / Benefits
- healthcare
- retirement planning
- paid volunteering days
- wellbeing initiatives
Responsibilities
- Own 1LoD technology risk profile and alignment with risk appetite
- Manage the technology control framework across applications, infrastructure, cloud, and cyber; define testing approaches and assurance mechanisms
- Lead operational resilience implementations (IBS, impact tolerances, scenario testing) and embed resilience in architecture and change processes
- Provide independent first-line challenge to engineering, architecture, and product teams; escalate material risk decisions
- Own responses to audits/regulatory reviews; track remediation and provide evidence and assurance quality
- Oversee third-party and cloud risk, including TPRM lifecycle and cloud risk alignment with enterprise standards
- Own risk data, MI & reporting; define KRIs, KPIs, KCIs; ensure decision-ready data
- Define and grow a high-performing risk team and a clear RACI across first and second lines
Key requirements
- Senior leadership in technology risk within regulated financial services
- Ownership of control frameworks aligned to NIST, ISO, COBIT
- Proven governance and remediation of systemic risk issues
- Operational resilience and incident management expertise
- Experience engaging with regulators and executive stakeholders
- Cloud and third-party risk oversight
- Strong decision-making and challenge capability
- Executive communication and regulatory engagement
- Stakeholder alignment across complex landscapes
- NIST, ISO, COBIT-aligned control frameworks
- Operational resilience and incident management
- Regulatory and risk governance processes
…
