Overview
In this role, you will strengthen the UK IIoT risk governance by establishing the second line of defense for Technology Risk and driving risk oversight across UK entities. You will collaborate with 2LOD teams and liaise with regulators, audits, and LE leadership to align risk metrics with Enterprise frameworks. You will advise businesses on applying technology risk controls and help shape resilient technology risk programs. This position offers a chance to influence risk governance in a globally respected financial services firm and support responsible growth.
Responsibilities
- Lead RAF refresh and align ILE Technology Risk metrics with Enterprise where possible
- Coordinate challenge between enterprise risk type 2LOD and local 1LOD teams
- Act as main Technology Risk contact for LE regulators, Audit, and LE Leadership
- Represent Technology Risk at LE board meetings as needed
- Contribute to ILE Technology Risk policies for UK requirements
- Influence Enterprise Technology Risk Frameworks to fit ILE deployment
- Advise business on effective execution of Technology Risk frameworks
- Coordinate with Enterprise Risk Lead on 2nd Line testing, risk assessments, and risk appetite reviews
- Communicate risks between ILE and Enterprise
- Support ILE CRO oversight and remediation of Technology Risks
- Oversee 2nd Line regulatory change management related to Technology Risk
- Develop LE metrics dashboard aligned with regulatory requirements
- Perform second level reviews of IT/IS/Data/AI/Business Disruption risk questionnaires for Regulators
- Participate in operational resilience incident channels to monitor incidents for regulatory notification (e.g., DORA)
Key requirements
- 5+ years of leadership experience in risk management
- Strong business acumen with risk-reward perspective
- Experience interacting with regulators and UK regulatory landscape familiarity
- Knowledge of UK/EU regulatory landscape for tech, data, cybersecurity, resilience, and AI risks including FCA/PRA, DORA, GDPR, EU AI Act, UK AI Regulation Framework, NCSC CAF, UK/EU data protection
- Understanding of risk assessment methodologies and standards
- Experience with Governance, Risk and Compliance tools (e.g. Archer / ServiceNow)
- Proven ability to manage multiple priorities under pressure
- Fluency in English
- Advanced degree in business, economics, engineering, or related field preferred
- Industry certifications in cybersecurity, operational resilience, business continuity, Disaster Recovery or AI risk management preferred
- leadership and coaching
- relationship and influence management
- integrity and challenge mindset
- Archer
- ServiceNow
- Regulatory change management
…
