Senior Risk Manager
Job Description Your role will be to provide second line oversight of IT change risk across the group with a focus on technology transformation and change initiatives. The role will work collaboratively across the 3 lines of defence to challenge, support and provide oversight over the execution of IT change initiatives.Your responsibilities will include:
- Deliver an effective second line IT change risk oversight approach, supporting framework and continuous improvement activity.
- Lead the assessment of programme and IT change risk as the line 2 subject matter expert in IT change, with a focus on technology transformation / change programmes.
- Assess the effectiveness of risk management capabilities within specific programmes, including assessment of the documentation and management of risks; the assessment, management, and escalation of key risks and issues; the appropriateness of management responses; and the impacts of key risks to the Group.
- Develop holistic management information and reporting on the risk profile of significant IT change programmes and the aggregate risk profile to the Group arising from change.
- Engage and collaborate with the wider team to ensure appropriate SME input and challenge into the broader non technology elements of change and associated operational risk e.g. business functionality, regulatory expectations and information risk requirements.
- Challenge that risks associated with IT change are appropriately assessed to consider all risk disciplines including consideration as to whether good customer outcomes are being achieved and foreseeable harm is being avoided in line with Consumer Duty.
- Lead and deliver ’deep dive’ reviews of specific programmes and IT change deliverables to include, as required: consideration of governance arrangements; solution design and selection; testing including non functional testing, business readiness, delivery and implementation planning; and the management of activities transitioning to BAU – providing second line views and reports to programme management and wider senior management.
- Engage with management to highlight potential gaps in the moment, provide structured feedback and drive improvements. Produce reports and MI for relevant groups, Committees and Board as required.
- Professional programme/change management qualification (e.g., CCMP, PMI, MSP) or IT audit (CISA) and equivalent experience of IT and change risk assessment at infrastructure, application and programme/project level.
- Demonstrable expertise in technology risk/change risk and control practices
- Ability to provide constructive challenge to senior stakeholders whilst building relationships.
- Outstanding communication skills (both verbal and written) and listening skills. Ability to deliver challenging messages to project leads.
- Experience in a change practitioner context, for example project or programme management.
- Able to work on own initiative, proactively seeking continuous improvement in all areas.
- Ability to develop and maintain relationships at all levels.
- Strategic and commercial outlook in the context of risk management and delivering change