Technology and Data Risk Manager

Role Overview The Technology & Data Risk Manager is a new second line of defence role within the Risk Directorate, responsible for providing independent oversight, assurance and expert challenge across technology, data, cyber security, and related operational risks. Reporting to the Head of Technical Risk and Data Protection Officer, the role supports the effective management of technology and data risks by ensuring first line teams identify, assess and mitigate risks in line with Nest’s risk appetite while enabling the organisation to deliver its strategic objectives securely and efficiently.Working across the organisation, the role promotes strong risk management practices, providing expert challenge on technology, data protection, information security, and third-party risk matters. It plays a key role in strengthening governance, embedding a strong data protection and security culture, and supporting compliance with regulatory requirements and recognised standards, includingUK GDPR, the Data Protection Act 2018 and ISO 27001.The Technology & Data Risk Manager also helps the organisation anticipate and respond to emerging risks and opportunities, including developments in artificial intelligence, evolving cyber threats, and third-party dependencies. Through effective stakeholder engagement, assurance activity and risk reporting, the role contributes to maintaining a resilient, compliant, and well-controlled technology and data environment across Nest. The minimum criteria for this role are: Essential
  • Sound knowledge of information security and data risk domains (access control, vulnerability management, logging and monitoring, incident response, secure development etc). 
  •  Experience in technology, data, security, or technical risk management including control frameworks such as ISO 27001 and NIST, ideally within a regulated or complex organisation.
  • Strong understanding of second line assurance and oversight, including how to challenge constructively while remaining independent.
  • Experience of assessing third-party technical risk. 
Desirable
  • Experience with product security and secure SDLC assurance. 
  •  Knowledge of AI risk, data ethics or emerging technology governance.
  • Working knowledge of UK GDPR and the Data Protection Act 2018.
  • Knowledge of threat intelligence, vulnerability disclosure, and security testing approaches.
  • Relevant professional certifications (e.g. CISM, CISSP, ISO 27001 LI/LA, CRISC, ITIL).
Don't worry if you think you don't have all the key skills, it might be worth taking the few minutes to apply as we're good at spotting potential. At Nest, you’ll have access to a range of learning opportunities to learn, grow and build the skills you need to be successful in your role and career.Flexible and agile working Everyone's personal situation is different.To make the most out of hybrid working, we've introduced different ways of working, which include (subject to role requirements):
  • hybrid of office (Canary Wharf, London) and home working (there will be an expectation to attend the office, once - twice a week, or more, as required) 
  • vary working hours
Directorate/Department Overview The Technical Risk team sits within the Risk Directorate, along with Risk, Risk Assurance, Risk Operations and Regulatory Risk, and Controls Oversight. The directorate supports the business in delivering its strategic priorities by overseeing that risk and controls are identified, prioritised and managed through an enterprise risk management framework. Nest operates a ‘three lines of defence’ model, with Risk sitting in the second line providing advice, guidance and challenge to the first line.The Technical Risk team provides support to Nest specifically in relation to risks covering data, privacy, technology, cyber and financial crime. Support includes conducting investigations, regulatory reporting as well as training and awareness across Nest Corporation.Organisational Overview Nest is an award-winning workplace pension scheme, the largest in the country. Set up by the government to give every worker in the UK somewhere to save, our first-class responsible investment practice and governance are the backbone of what we do, supported by all the functions you’d expect to find in a thriving business. We’re committed to creating a workplace where you can be your authentic self and offer an inclusive and flexible working environment.Diversity, Equity and Inclusion Everyone is welcome to apply for our roles, and we are determined to ensure that no applicant or employee receives less favourable treatment because of their age, disability, gender identity, marital status, national origin, pregnancy or caring responsibilities, race, religion/belief, sex, sexual orientation or socio economic background.We also recognise the importance of diversity of thought and other forms of neurocognitive variation.Nest is a Disability Confident Leader, which is the highest level of the Disability Confident Scheme. If you have a disability, please declare that you’re applying through the scheme. We aim to offer an interview to those applicants who apply through the Disability Confident Scheme and best meet the minimum criteria. However, there may be some circumstances where this is not possible due to the volume of applications.Please note that this advert may close early if we receive a sufficient number of satisfactory applications. If you have any difficulty in sending your application or need the application pack in an alternative format, or you require any reasonable adjustments please contact: .

Job Details

Company
NEST Corporation
Location
London, South East, England, United Kingdom
Hybrid / Remote Options
Employment Type
Full-Time
Salary
£80,000 - £85,000 per annum
Posted