Technology and Data Risk Manager
Role Overview The Technology & Data Risk Manager is a new second line of defence role within the Risk Directorate, responsible for providing independent oversight, assurance and expert challenge across technology, data, cyber security, and related operational risks. Reporting to the Head of Technical Risk and Data Protection Officer, the role supports the effective management of technology and data risks by ensuring first line teams identify, assess and mitigate risks in line with Nest’s risk appetite while enabling the organisation to deliver its strategic objectives securely and efficiently.Working across the organisation, the role promotes strong risk management practices, providing expert challenge on technology, data protection, information security, and third-party risk matters. It plays a key role in strengthening governance, embedding a strong data protection and security culture, and supporting compliance with regulatory requirements and recognised standards, includingUK GDPR, the Data Protection Act 2018 and ISO 27001.The Technology & Data Risk Manager also helps the organisation anticipate and respond to emerging risks and opportunities, including developments in artificial intelligence, evolving cyber threats, and third-party dependencies. Through effective stakeholder engagement, assurance activity and risk reporting, the role contributes to maintaining a resilient, compliant, and well-controlled technology and data environment across Nest. The minimum criteria for this role are: Essential
- Sound knowledge of information security and data risk domains (access control, vulnerability management, logging and monitoring, incident response, secure development etc).
- Experience in technology, data, security, or technical risk management including control frameworks such as ISO 27001 and NIST, ideally within a regulated or complex organisation.
- Strong understanding of second line assurance and oversight, including how to challenge constructively while remaining independent.
- Experience of assessing third-party technical risk.
- Experience with product security and secure SDLC assurance.
- Knowledge of AI risk, data ethics or emerging technology governance.
- Working knowledge of UK GDPR and the Data Protection Act 2018.
- Knowledge of threat intelligence, vulnerability disclosure, and security testing approaches.
- Relevant professional certifications (e.g. CISM, CISSP, ISO 27001 LI/LA, CRISC, ITIL).
- hybrid of office (Canary Wharf, London) and home working (there will be an expectation to attend the office, once - twice a week, or more, as required)
- vary working hours