Senior Enterprise Risk Manager
Rev & Regs are recruiting for a Senior Enterprise Risk Manager role for a dynamic commercial and retail bank focused on mortgages / lending.
The role sits within the Second Line of Defence, reporting to the Head of Enterprise Risk, and has responsibility for managing a team of three direct reports. We are looking for a Manager or Senior Manager with recent Second Line experience overseeing Operational Resilience (OpRes) and Third-Party Risk Management (TPRM), together with a strong focus on data risk, cyber risk, and emerging risks such as AI, all from a Second Line perspective.
Responsibilities:
- Lead second line oversight of first line Operational Risk activities, including Risk and Control Self-Assessments (RCSAs), scenario analysis, and control effectiveness reviews.
- Deliver a structured programme of Key Control assurance, thematic reviews, and deep-dives to assess control effectiveness and identify systemic weaknesses.
- Own, maintain and continuously enhance the Group Operational Risk Management Framework (GORMF), and other Operational Risk policies and guidance.
- Lead the end-to-end delivery of a strategic GRC system implementation, including requirements definition, vendor selection, testing, and embedding.
- Develop and embed second line oversight of Operational Resilience, ensuring alignment with regulatory expectations (e.g. important business services, impact tolerances, and scenario testing).
- Own, maintain and continuously enhance the Group Operational Resilience Risk Framework and Group Third Party Risk Framework.
- Expand second line coverage across key non-financial risk domains, including: Third Party Risk, Management (TPRM), Cyber and Information Security Risk, Technology and IT Risk and Artificial Intelligence (AI) Risk.
- Provide independent challenge to ensure these risk domains are effectively governed, controlled, and integrated into the wider risk framework.
- Support the design, development, and implementation of a comprehensive Data Risk Framework, covering data governance, quality, privacy, lineage, and usage risks.
- Ensure the framework is embedded across the organisation, with clear roles, responsibilities, and controls aligned to regulatory expectations and best practice.
- Establish appropriate oversight, metrics, and reporting to support effective management of data-related risks.
Experience:
Essential:
- Significant experience (typically 10+ years) in Operational Risk or Enterprise Risk within Financial Services or a similarly regulated industry.
- Demonstrable second line experience with oversight and challenge responsibilities.
- Diverse knowledge of financial services with specific knowledge of current regimes pertaining to Operational Risk under the auspices of the PRA and FCA regulatory authorities.
- Practical experience in Operational Resilience (e.g. important business services, impact tolerances, scenario testing).
- Exposure to or oversight of TPRM, Cyber/IT Risk, and emerging risks such as AI.
- Demonstrated ability to partner effectively with first line business units while maintaining independence of oversight.
- Familiarity with risk systems, GRC tooling, analytics, and the use of dashboards/KRIs to drive insight.
- Demonstrates curiosity and proactively explores new risk areas (e.g. AI, data, digital resilience).
Desirable:
- Good understanding of data architecture, data governance, and data quality principles.
- Awareness of emerging technologies (e.g. AI/ML) and associated risk management approaches.
- Experience leading complex risk transformation or change programs
Salary: £100,000 plus bonus
Location: Hybrid (3 days per week in City of London)