IT Risk and Control Specialist
Location: Sheffield (Hybrid 3 days per week at the office)
Contract: inside Ir35, 6 months
Overview
We are seeking an experienced IT Risk & Control Specialist to join a major technology function supporting enterprise-wide business services and workplace technologies.
This is an excellent opportunity for a technology risk professional with strong experience in IT controls, cyber risk, vulnerability management, and governance to work within a complex, regulated environment. The successful candidate will play a key role in strengthening risk management practices, driving control improvements, and ensuring technology services remain secure, compliant, and resilient.
Key Responsibilities
- Build strong relationships with technology teams, architects, developers, and service owners to understand end-to-end technology services and identify control gaps.
- Support the implementation and enhancement of IT risk and control frameworks across the technology estate.
- Partner with Cyber Security, Risk, and Compliance teams to ensure security best practices are Embedded within technology operations.
- Analyse vulnerability and patch management data to identify risks and drive remediation activities.
- Design and produce meaningful risk, control, and vulnerability reporting for technical and senior business stakeholders.
- Support Identity and Access Management (IAM), Software Lifecycle Management, Evergreening, and Data Movement control activities.
- Maintain process documentation, control evidence, and governance reporting.
- Facilitate risk assessments and ensure remediation actions are tracked through to completion.
- Drive continuous improvement initiatives across risk management processes, tools, and controls.
- Present findings, recommendations, and progress updates to governance forums and senior management.
Required Skills & Experience
- Strong experience in IT Risk Management, IT Controls, or Technology Governance.
- Solid understanding of risk management frameworks and control environments.
- Experience managing or analysing vulnerability management and patch remediation activities.
- Knowledge of information security principles including network, host, and application security.
- Ability to assess threats, risks, vulnerabilities, and control effectiveness.
- Experience working within large-scale, complex technology environments.
- Excellent stakeholder management and communication skills.
- Strong analytical and reporting capabilities.
Mandatory Skills
- Risk Management (IT Risk/Operational Risk)
- BMC Control-M
Preferred Skills
- Vulnerability Management
- Cyber Security Risk
- Identity & Access Management (IAM/IDAM)
- Governance, Risk & Compliance (GRC)
- Power BI
- Jira
- Confluence
- Cyberport
- Cyberflows
Ideal Background
- Technology Risk Analyst
- IT Controls Analyst
- Technology Governance Specialist
- Cyber Risk Specialist
- IT Compliance & Controls Consultant
- Information Security Risk Analyst
- IT Risk Manager
If you're an experienced technology risk professional looking to contribute to a highly regulated and fast-paced environment, we'd like to hear from you.