grow your career. Here, your voice and ideas matter, your work makes an impact, and together, you will help us decide the future of American Express. The Technology & Operational Risk Advisor will help ensure safe and sound banking & business operations by creating embedded partnerships focused on reducing technology and operational risk and advancing Technology Risk and Information … such information that could result in substantial harm or inconvenience to any customer This role will have a significant positive impact on the overall Operational, Technology, and Information Security risk posture of American Express and its legal entities by leading risk-reduction through clear and candid communication, early engagement in new products and projects, regulatory engagement, information security … and technology risk consultation. How will you make an impact in this role? We are seeking an experienced and proactive leader to be responsible for technology risk, operational risk and information security control enforcement as well as risk prioritization across Business Unit CIO groups, the business, and American Express legal entities. Responsibilities: Build strong partnerships with More ❯
Reading, Berkshire, United Kingdom Hybrid / WFH Options
Deloitte LLP
five shared values lead every decision wemake and action we take, guiding us to deliver impact how and where it mattersmost . Connect to your opportunity The Technical Cyber RiskAssessment Manager will be responsible for the following: Develop an understanding of Deloitte's global line of business and its priorities, becoming an advocate for addressing cyber risk. … Demonstrate familiarity with the Three Lines of Defense (3LOD) model. Possess knowledge of risk management practices and the ability to conduct technical risk assessments. Work with the Global Technology Infrastructure team to integrate system cybersecurity assessments into their processes to ensure consistent implementation of security controls. Work with the Cybersecurity Architecture team and apply reference architectures for security … reported threats at peer organizations, and overall cybersecurity threats in the internet ecosystem and you will notify leadership of potential or existing threats and assist in the development of risk mitigating strategies of these items. Monitor security blogs, articles, and reports and remain current on related laws, regulations, and industry standards to keep up to date on the latest More ❯
Guildford, Surrey, United Kingdom Hybrid / WFH Options
Deloitte LLP
five shared values lead every decision wemake and action we take, guiding us to deliver impact how and where it mattersmost . Connect to your opportunity The Technical Cyber RiskAssessment Manager will be responsible for the following: Develop an understanding of Deloitte's global line of business and its priorities, becoming an advocate for addressing cyber risk. … Demonstrate familiarity with the Three Lines of Defense (3LOD) model. Possess knowledge of risk management practices and the ability to conduct technical risk assessments. Work with the Global Technology Infrastructure team to integrate system cybersecurity assessments into their processes to ensure consistent implementation of security controls. Work with the Cybersecurity Architecture team and apply reference architectures for security … reported threats at peer organizations, and overall cybersecurity threats in the internet ecosystem and you will notify leadership of potential or existing threats and assist in the development of risk mitigating strategies of these items. Monitor security blogs, articles, and reports and remain current on related laws, regulations, and industry standards to keep up to date on the latest More ❯
Guildford, Surrey, United Kingdom Hybrid / WFH Options
Sycurio
driving the attainment and maintenance of the ISO27001, PCI-DSS, and SOC2 compliance. They are the subject matter expert on all things regarding security and compliance, owning the information risk management processes. They are the thought leader on all matters within the security and compliance domain such that the company remains secure against the ever-changing security threat and … external auditors to achieve positive outcomes. Expert in information security with strong communication and stakeholder management skills. Experience in managing security incidents and leading incident response. Experience with security assessment tools and vulnerability management. Strong vendor management and third-party riskassessment experience. Skills: Strong understanding of cloud security principles and best practices, particularly in AWS. Solid More ❯
systems within the private credit sector. This senior role plays as an interlink between business operations and technology, with the ultimate goal to enhance investment decision-making, portfolio management, riskassessment, and operational efficiency. The ideal candidate will have a promising career development and growth. Responsibilities: Monitor industry trends, evaluate competitor offerings, and stay abreast of regulatory changes … functionalities that will enhance business processes and systems, assess the impact of changes, and work with IT colleagues on technical solution design. Work in strategic contact with investment teams, risk managers, business leaders, and operations teams to identify their needs and translate them into actionable requirements. Simplify the private credit platform as much as possible while ensuring it is … in private credit, asset management, or financial services, with a focus on technology platforms and operations. Technical Proficiency: Hands-on experience with loan origination systems, portfolio management tools, or risk management platforms (e.g., LoanIQ, WSO Web). Industry Knowledge: Detailed understanding of the operational, financial, and legal requirements of private credit funds, including closed-ended funds, semi-liquid funds More ❯
Rochester, England, United Kingdom Hybrid / WFH Options
Locke and McCloud
want to hear from you. Key Responsibilities: Develop and implement security solutions for Microsoft Azure and M365 environments. Ensure compliance with regulatory requirements, including PCI and FCA standards. Conduct risk assessments using established frameworks and methodologies. Configure and manage security-related controls, systems, and applications. Lead and manage compliance and security programs across technical infrastructure and applications. Respond effectively … controls, and compliance programs. Preferred certifications: Microsoft Azure (AZ-500), M365 (MS-500), CISSP, CCSP, or CompTIA Security+. Vendor certifications for firewall, antivirus, and networking solutions. Strong understanding of riskassessment frameworks and methodologies. Technical expertise in security tools and applications. Excellent analytical and problem-solving skills. Proactive, tenacious, and team-oriented approach. Strong interpersonal skills to build More ❯
Tunbridge Wells, England, United Kingdom Hybrid / WFH Options
Locke and McCloud
want to hear from you. Key Responsibilities: Develop and implement security solutions for Microsoft Azure and M365 environments. Ensure compliance with regulatory requirements, including PCI and FCA standards. Conduct risk assessments using established frameworks and methodologies. Configure and manage security-related controls, systems, and applications. Lead and manage compliance and security programs across technical infrastructure and applications. Respond effectively … controls, and compliance programs. Preferred certifications: Microsoft Azure (AZ-500), M365 (MS-500), CISSP, CCSP, or CompTIA Security+. Vendor certifications for firewall, antivirus, and networking solutions. Strong understanding of riskassessment frameworks and methodologies. Technical expertise in security tools and applications. Excellent analytical and problem-solving skills. Proactive, tenacious, and team-oriented approach. Strong interpersonal skills to build More ❯
Fareham, England, United Kingdom Hybrid / WFH Options
Zurich Insurance Company
skills (Data Analytics, IT fundamentals, and GenAI), and Agile methods, and serve as a role model for delivering change. What will you be doing? Input into the overall UK riskassessment and audit planning and, determining the right auditscope, key risks to be addressed and most suitable audit techniques and approaches alongside the Audit Director Keeping the business … Security and new technologies, such as Robotics and Artificial Intelligence. Experience in third-party, outsourcing and project management auditing. Strong understanding and applicability of audit and/or business risk management and control processes. Proven record of working with and influencing executive/senior stakeholders, verbally and through written reports. Demonstrated success in business, functional and people management. Excellent More ❯
Social network you want to login/join with: Head of Market risk and Market Data IT, slough col-narrow-left Client: Morgan McKinley Location: slough, United Kingdom Job Category: Other - EU work permit required: Yes col-narrow-right Job Views: 4 Posted: 31.05.2025 Expiry Date: 15.07.2025 col-wide Job Description: The Risk IT division manages and mitigates … risks within financial markets, focusing on Market Risk, Credit Risk, and Market Data. Market Risk involves assessing and managing risks due to adverse price movements. Credit Risk focuses on evaluating and mitigating risks from borrower defaults. Market Data ensures the accuracy and timeliness of data for risk analysis and decision-making. Job Purpose: The Head … of Market Risk and Market Data IT leads the development, implementation, and management of technology solutions for market risk management and market data functions. This role oversees market risk models, ensures data integrity, and provides strategic direction to enhance market risk and market data processes. Collaboration with cross-functional teams, compliance with regulations, and driving innovation More ❯
Social network you want to login/join with: The Risk IT division manages and mitigates risks within financial markets, focusing on Market Risk, Credit Risk, and Market Data. Market Risk involves assessing and managing risks due to adverse price movements. Credit Risk focuses on evaluating and mitigating risks from borrower defaults. Market Data ensures … the accuracy and timeliness of data for risk analysis and decision-making. Job Purpose: The Head of Credit Risk IT leads the development, implementation, and management of technology solutions for credit risk management. This role oversees credit risk models, ensures data integrity, and provides strategic direction to enhance credit risk processes. Collaboration with cross-functional … teams, compliance with regulations, and driving innovation are key aspects of this role. Key Responsibilities: Strategic Leadership: o Develop and execute the Credit Risk IT technology strategy. o Provide visionary leadership and foster a culture of innovation. Technology Development and Implementation: o Oversee the design and implementation of credit risk models and systems. o Integrate advanced analytics and More ❯
Coordinate the incident response process, including investigation, containment, and remediation of security breaches Perform forensic analysis to determine the root cause of incidents and develop strategies to prevent recurrence Risk Management and Compliance: Ensure compliance with recognised industry standards, such as SOC2, ISO 27001 and ISAE 3402 etc Assessment of Third-Party RiskAssessment responses and … diligence requests for both clients and vendors Collaborate with internal and external auditors to support security audits and assessments and develop risk mitigation plans Collaboration and Communication: Work closely with IT teams and other stakeholders to integrate and advise on suitable security controls for all systems, applications and projects Report security risks and strategies to senior management and non More ❯
South East London, England, United Kingdom Hybrid / WFH Options
Sarafin Partners
an experienced professional to work with their offices around the world to support cyber security initiatives. The successful candidate will possess strong analytical skills, an understanding of security administration, risk management and identity access management solutions. The main focus of the role will include: Performance of system security administration on designated technology platforms in accordance with the defined policies … are maintained To succeed in this role, the individual will need: Exceptional communication skills (both written and verbal) At least 18 months experience of working with cybersecurity principles, including riskassessment and management, threat and vulnerability management, incident response, and identity and access management Experience in developing, documenting and maintaining security procedures Knowledge of network infrastructure, including routers More ❯
advocate internal and external policy to shape the development of new laws and regulations consistent with company objectives. Develop and implement a compliance monitoring system. Coordinate a company-wide riskassessment process to identify potential risks and control solutions. Monitor actions to identify emerging risks and close gaps. Create internal partnerships with key stakeholders to influence and align … expertise, processes and networks together to solve the post-trade challenges of global financial markets. OSTTRA operates cross-asset post-trade processing networks, providing a proven suite of Credit Risk, Trade Workflow and Optimisation services. Together these solutions streamline post-trade workflows, enabling firms to connect to counterparties and utilities, manage credit risk, reduce operational risk and More ❯
participate on projects with varied industry and business imperative focus including business-related IT and OT challenges and cybersecurity, business applications, systems, and business process integration solutions Experience with riskassessment, especially cyber risk is preferred Additional Information The Team Business Value Consulting is a strategic, consultative team and is a critical member of Palo Alto Networks More ❯
TN1, Royal Tunbridge Wells, Kent, United Kingdom Hybrid / WFH Options
Town & Country Housing Group
Excellent problem-solving, analytical, and decision-making abilities. *Ability to manage multiple projects in a fast-paced environment. *Detail-oriented with strong organizational and time management skills. *Proficiency in riskassessment and conflict resolution. *Adaptability to new technologies and evolving business requirements. *Strong negotiation and influencing skills. Required Behaviours *Ability to support the strategic vision and goals of More ❯
Maidenhead, Berkshire, United Kingdom Hybrid / WFH Options
Wireless Logic Group
PE-backed group Treasury Management Systems (TMS): Demonstrable ability to personally manage operational treasury responsibilities Financial Modeling: Advanced skills in financial modeling, including cash flow forecasting, investment analysis, and risk assessment. Data Analysis & Visualization: Ability to analyze large datasets, identify trends, and create insightful reports using tools like Excel, and potentially PowerBI, or Tableau. Advanced Excel skills essential Foreign … Exchange (FX) Management: Knowledge of FX trading platforms and risk management tools. Debt Management: Experience with debt management systems and tools. Highly Self-Sufficient - thrives in a standalone role with full ownership Strong Communicator: Communicates clearly and confidently with senior stakeholders Banking Platforms: Experience with online banking platforms and electronic funds transfer systems. What Will Make You Shine at More ❯
coupled with our extensive experience of engineering, regulatory practices and operations delivery enable us to develop sustainable, long-term solutions for our clients. The Role As a Senior Consultant - Risk Manager , you will play a key role in delivering risk management solutions to clients, helping them identify, assess, and mitigate risks while ensuring regulatory compliance and operational resilience. … Your key responsibilities will include: Risk Strategy & Project Leadership: Develop and implement risk management frameworks, ensuring effective mitigation strategies Stakeholder Engagement: Collaborate with clients, regulators, and internal teams to align risk initiatives with business goals RiskAssessment & Compliance: Identify, assess, and monitor risks while ensuring adherence to regulatory and industry standards Data Analysis & Reporting: Provide … insights through risk modelling, scenario analysis, and strategic reporting Process Improvement & Advisory: Recommend enhancements to governance, controls, and resilience planning Apply to DAS if you want to work on varied, complex projects within a business that values your development, where no two days are alike, and where you'll have a tangible impact on critical infrastructure in the UK. More ❯
Southampton, England, United Kingdom Hybrid / WFH Options
Zurich Insurance
Join to apply for the IT Risk Manager role at Zurich Insurance 4 days ago Be among the first 25 applicants Join to apply for the IT Risk Manager role at Zurich Insurance Get AI-powered advice on this job and more exclusive features. Working hours: This role is available on a part-time, job-share or full … on how to move our UK business forward. You will be asked to drive change and improve on a set of already well-established IT Controls and an IT Risk Management Framework to allow senior IT management, business functions and 3rd party service providers to demonstrate they are managing and safeguarding company assets, data, and operations. Your ideas will … Controls Manager and other governance colleagues to gather data and collate, aggregate and interpret information to provide the Boards of Directors, Business Executives and other interested parties with an assessment of the UK IT Risk and Controls landscape. You will also manage multiple demands for IT risk-based information within Zurich, ensuring all reporting commitments are met. More ❯
Reading, Berkshire, United Kingdom Hybrid / WFH Options
Deloitte LLP
following: Shape the development of technology control management including scoping, development of and testing ServiceNow tools for ITRM processes in DT to allow for an effective, efficient and adaptable risk governance capability and contribute to its continuous improvement. Direct control development across DT, driving a consistent approach utilising the IRM capabilities within ServiceNow. Deliver the DT control library architecture … and control data management. Secure commitment from member firms and stakeholders in the global firm to participate in the Technology Standards and Maturity Assessment with the objective to assess the member firm's overall IT capability/maturity and to help them establish their own priorities. Keep abreast of new and emerging technologies being deployed and ensure riskassessment processes are appropriately applied and advise on decisions with technology risk impacts as new activities and other change management/transformational initiatives. Leverage available technical resources/tools to research; expand technology risk knowledge to enhance work product, to remain up to date on member firms and line of businesses hot topics while sharing the More ❯
Guildford, Surrey, United Kingdom Hybrid / WFH Options
Deloitte LLP
following: Shape the development of technology control management including scoping, development of and testing ServiceNow tools for ITRM processes in DT to allow for an effective, efficient and adaptable risk governance capability and contribute to its continuous improvement. Direct control development across DT, driving a consistent approach utilising the IRM capabilities within ServiceNow. Deliver the DT control library architecture … and control data management. Secure commitment from member firms and stakeholders in the global firm to participate in the Technology Standards and Maturity Assessment with the objective to assess the member firm's overall IT capability/maturity and to help them establish their own priorities. Keep abreast of new and emerging technologies being deployed and ensure riskassessment processes are appropriately applied and advise on decisions with technology risk impacts as new activities and other change management/transformational initiatives. Leverage available technical resources/tools to research; expand technology risk knowledge to enhance work product, to remain up to date on member firms and line of businesses hot topics while sharing the More ❯
the role Manage commercial activities for complex multi-domain bids. In a support role to sales, create structure and negotiate commercial and financial structure of bids with minimal residual risk, to address customer needs as well as Orange Business financial and business objective, in conjunction with policy requirements. Key accountabilities Advisor with significant experience and ability to support structuring … presentations to internal and external executives. In support of Sales, and in coordination with Legal, Finance and Solutions teams, create, structure and negotiate (internally and externally) commercial, financial and risk structure of bids from qualification through to customer proposal submission, negotiation and contract signature. In support of commercial structure inclusive of: Customer & Opportunity discovery & assessment including due diligence … flow-up; Heads of Agreements/MOU/LOI ; Technology refresh; Termination & termination liability; Penalties and liabilities; Governance model; Migration planning; Change management Key result/decision areas (outcomes) Risk is understood and mitigated through design and negotiation of business terms and conditions, and linked to the business case. Clearly presented overview of pricing and commercial terms to customers More ❯
rota Key skills for the Senior Information Security Analyst: Proven experience in a security-focused role, ideally across several of the following areas: security operations, vulnerability management, security assurance, risk management, or project consultancy A clear enthusiasm for cybersecurity, with a proactive attitude and eagerness to learn Solid understanding of riskassessment frameworks and methodologies Strong communication More ❯
rota Key skills for the Senior Information Security Analyst: Proven experience in a security-focused role, ideally across several of the following areas: security operations, vulnerability management, security assurance, risk management, or project consultancy A clear enthusiasm for cybersecurity, with a proactive attitude and eagerness to learn Solid understanding of riskassessment frameworks and methodologies Strong communication More ❯
Reading, England, United Kingdom Hybrid / WFH Options
SITA
identify information security weaknesses and provide remediation strategies. You will also contribute to the automation of security testing as part of the product development lifecycle. Key Responsibilities Conduct authorized assessment of infrastructure and applications to proactively identify security weaknesses. Verify weaknesses by leveraging attacker techniques to evaluate the difficulty and effectiveness of potential attack from various threat actors. Provide … weaknesses, given the applicable threat landscape. Bring an offensive mindset to the design of internal solutions and provide input to the selection of countermeasures and security controls through technical risk assessment. Report findings to technical audiences (e.g.: product development teams, IT, operations), and to business management and leadership, indicating the impact to the business of verified weaknesses found. Research … e.g. ISO/IEC 27001, PCI DSS, etc.) Good understanding of common business applications (e.g. content management systems, application servers, databases, etc.) and how to leverage them in an assessment Good understanding of web technologies and how they are commonly subverted (e.g. OWASP Top 10) At least a basic understanding of development frameworks (.NET, Java,...) Ability to remain More ❯
business units, as requested, when a business disruption occurs and assist with recovery efforts Help Maintain the internal Business Continuity Management Website and network shared drive Participate in vendor risk management program on behalf of the BC in the Business Continuity review and evaluation in the vendor risk management program Co-assist the global emergency notification system to … and gathering timelines, data points and action items, and following up with responsible parties for close-out of assigned action items. Collaborate with various teams, including Facilities, IT, Operations, Risk as well as BCP stakeholders within each line of business at the firm ; Work closely with development teams who own/maintain BC related software and platforms. Perform other … V-Lookups, etc.) Excellent interpersonal and communication skills (written, verbal, presentation) Demonstrated skill in development of working relationships with key contacts both inside and outside the organization Understand Operational Risk in the Finance sector. Proven ability to work independently and manage multiple project initiatives, and as part of a team Ability to coordinate and implement Business Continuity strategies and More ❯