Information Technology Risk Manager
Role Summary
We are looking for an experienced Senior Manager to lead our Technology Risk Consulting practice. This strategic position requires someone capable of building and developing a high‐performing consulting team, driving business growth, and delivering outstanding client outcomes across technology risk, resilience, and operational excellence.
The ideal candidate will be a seasoned technology risk professional with extensive experience supporting IT functions through major technology transformations, including cloud migration and modernisation of application architectures. A strong background in industry or consulting is essential, with hands‐on experience across IT Risk, Assurance, and Advisory disciplines.
You will play a critical role in delivering high‐quality consulting services, demonstrating expertise in transformation assurance and advisory work in areas such as:
Core Expertise
- Technology Strategy & Operating Model – Assess technology roadmaps and translate them into actionable plans that manage delivery and transformation risks.
- Cloud Transformation – Evaluate cloud architecture designs and conduct independent risk reviews of migration programmes.
- IT Operations – Review processes and operational performance using frameworks such as ITIL, TOGAF, and COBIT.
- IT Security & Resilience – Advise on improving technology security, resilience, and operational continuity.
- IT Governance & Risk Management – Design and implement governance structures and risk management plans, including remediation, IT assurance, and independent attestation services.
Experience within the UK Financial Services sector—particularly insurance and mid‐tier institutions—is highly desirable.
Key Objectives & Responsibilities
Technical Skills
- Proven experience in technology risk consulting within either industry or professional services.
- Strong knowledge of IT operations, resilience frameworks, and risk management practices.
- Experience leading IT architecture governance and operations reviews using TOGAF.
- Delivery of IT risk and control reviews, including cloud security assessments.
- Leadership of independent IT attestation services (e.g., ISAE 3402, SOC 2, SWIFT CSP, PCI DSS).
- Experience reviewing cloud platforms (Azure, AWS, GCP) — including architecture, privileged access, FinOps, and resilience.
- Assessment of DevOps lifecycles.
- Evaluation of Data Governance and AI within a lakehouse environment.
- Independent reviews of technology transformation programmes (PMO, governance, operating model).
- Familiarity with IT frameworks such as COBIT, NIST, Cloud Security Alliance, ITIL.
- Knowledge of relevant regulations and standards such as ISO 27001, PCI DSS, SWIFT CSP, DORA, and UK regulatory requirements.