response and notification processes, resilience testing, ICT third‐party risk controls, subcontractor oversight, exit planning and audit evidence. Provide security governance over cloud and SaaS environments, including identity and access management, logging and monitoring, encryption, key management, backup, tenant segregation, environment segregation, secure configuration and cloud security posture management. … risk processes. Ability to report security risks, control performance and remediation priorities to senior stakeholders, including ExCo or Board‐level audiences. Experience in a SaaS, fintech, financial services, regulated technology or B2B enterprise software environment. Desirable Exposure to DORA, FCA operational resilience, outsourcing/third‐party risk or financial services ...