Overview JOB TITLE: Head of Infrastructure & Enterprise Technology Risk SALARY: £114,810 - £135,070 LOCATIONS: Birmingham, Bristol, Edinburgh, Leeds, Halifax, Chester or Manchester HOURS: Full time WORKING PATTERN: Hybrid, 40% (or two days) in an office site About this opportunity We're looking for a Head of IT Systems Risk who'll lead and develop its risk specialist centre of excellence, to support robust riskmanagement in alignment with the Group's Enterprise RiskManagement Framework (ERMF). This will include giving our senior leaders and Risk Owners in these businesses advice on their risk appetite decisions, safely, and at pace. You will also be part of management's … we need you to have a breadth and depth of knowledge in current tech, and we want you to be passionate about its application and how we manage its risk; prepare to disrupt the norm in the pursuit of the best possible customer and staff experience. You should have people at your heart; we strive for excellent customer experience More ❯
Snelshall West, Milton Keynes, Buckinghamshire, England, United Kingdom
DS Smith
products and recycling services in more than 30 different countries across EMEA with over 30,000 colleagues. About the role Reporting to Head of I&T GRC, Governance and Risk Lead will be responsible for driving information and cyber security awareness, delivering security awareness training including phishing and facilitation of cyber scenario desktop simulations across central and manufacturing site … legal, data protection and digital security and business stakeholder in relation to supplier information and cyber security due diligence and requirements. As the successful candidate you will also lead risk-based party security assurance, management, and continuous improvement activities. In addition, facilitate and coordinate IT riskmanagementrisk register, tools, process, reporting and review. You … will take responsibility for managing a subset of aspects of ISO 27001 related documentation and control activities. As the I&T Governance and Risk Lead you will have the responsibility of aspects of the I&T GRC scope, delegated and assigned by the Head of I&T GRC. Key Accountabilities Engage with key IT and business stakeholders in relation More ❯
do together. RISCAuthority is an annually funded research scheme administered by the FPA and supported by a significant group of UK insurers. It publishes extensive guidance and recommendations for riskmanagement, predominantly in the areas of fire and security, and its core purpose is to raise resilience standards within the business community. RISCAuthority is managed by its members … and industry experts to shape strategic direction, oversee the delivery of high-quality research programmes, and ensure that our guidance continues to set the benchmark for fire and security risk management. This is a pivotal role for someone who can unite technical insight with stakeholder engagement, driving forward our mission to raise resilience standards across the business community. Work … document library and digital toolkits Liaising with the Marketing Department on a regular basis regarding RISCAuthority publications and webinars Developing and maintaining effective relationships with key RISCAuthority members Time management and organisation skills Strategic thinking Budget management Leadership and team management Technical acumen Strong networking abilities and experience building partnerships within the industry Ability to collaborate with More ❯
A leading global (re)insurance group is seeking a highly skilled and experienced IT Risk Director to join its expanding RiskManagement team. This is a rare opportunity to work closely with senior leadership across a dynamic and innovative business, gaining exposure to Board-level decision-making and world-class proprietary systems. About the Role The IT … Risk Director will play a pivotal role in managing and enhancing the Group's IT Risk Framework. This includes oversight of technology-related risks spanning cyber security, infrastructure, systems integrity, and emerging technologies such as AI. Reporting directly to senior risk executives, the role offers unmatched visibility and influence across a rapidly growing insurance platform with international … reach. Key Responsibilities Lead the quarterly IT risk review (QRR) and risk radar process across the Group. Maintain and enhance the ICT Risk Framework, including relevant 2LOD risk policies and controls. Produce Board and Committee-level reporting on IT risk matters. Serve as the primary liaison on IT risk incidents, coordinating with internal and More ❯
london (city of london), south east england, united kingdom
Arthur Recruitment
A leading global (re)insurance group is seeking a highly skilled and experienced IT Risk Director to join its expanding RiskManagement team. This is a rare opportunity to work closely with senior leadership across a dynamic and innovative business, gaining exposure to Board-level decision-making and world-class proprietary systems. About the Role The IT … Risk Director will play a pivotal role in managing and enhancing the Group's IT Risk Framework. This includes oversight of technology-related risks spanning cyber security, infrastructure, systems integrity, and emerging technologies such as AI. Reporting directly to senior risk executives, the role offers unmatched visibility and influence across a rapidly growing insurance platform with international … reach. Key Responsibilities Lead the quarterly IT risk review (QRR) and risk radar process across the Group. Maintain and enhance the ICT Risk Framework, including relevant 2LOD risk policies and controls. Produce Board and Committee-level reporting on IT risk matters. Serve as the primary liaison on IT risk incidents, coordinating with internal and More ❯
Africa, our 5 year strategy ensures “Controlled Growth” as we aim to become the Bank of choice for businesses wishing to transact in the African continent. Role Overview: Market Risk is a 2nd Line of Defence function primarily tasked with active monitoring of the banks risk portfolios to identify, monitor, and escalate (where necessary) risks and control findings … effectively, to enable timely decision making by the CRO and wider ZBUK executive. Oversight extends to infrastructure, user activity and controls, compliance with Bank Risk Appetite and associated policy/project development to support the successful delivery of wider Risk projects and other regulatory publications/requirements. Role Responsibilities: Identification For agreed risks (split by asset class, risk … proprietary and client-based FX, trading, and banking book products. Monitor limits for the Trading and Non-Trading portfolios in accordance with ZBUK’s policies approved by the Board Risk Committee. Report on breaches of riskmanagement policies, limits and/or controls. Produce daily market risk reporting and other ad hoc reporting for senior managementMore ❯
Africa, our 5 year strategy ensures “Controlled Growth” as we aim to become the Bank of choice for businesses wishing to transact in the African continent. Role Overview: Market Risk is a 2nd Line of Defence function primarily tasked with active monitoring of the banks risk portfolios to identify, monitor, and escalate (where necessary) risks and control findings … effectively, to enable timely decision making by the CRO and wider ZBUK executive. Oversight extends to infrastructure, user activity and controls, compliance with Bank Risk Appetite and associated policy/project development to support the successful delivery of wider Risk projects and other regulatory publications/requirements. Role Responsibilities: Identification For agreed risks (split by asset class, risk … proprietary and client-based FX, trading, and banking book products. Monitor limits for the Trading and Non-Trading portfolios in accordance with ZBUK’s policies approved by the Board Risk Committee. Report on breaches of riskmanagement policies, limits and/or controls. Produce daily market risk reporting and other ad hoc reporting for senior managementMore ❯
that could impede the reputation, safety, security, or financial success of the organisation and the programme. Facilitate identification, assessment and prioritisation of threats, opportunities, and issues Experience of RAID Management on a complex Programme of work, dealing with multiple senior stakeholders. Maintain visibility of threat/opportunity trigger points to facilitate risk cost profiling, timely drawdown of risk budget or retirement of threat/opportunity. Assist with the identification and development of appropriate management responses which are measurable and specific, along with assessing the post mitigated positions. Monitor overall risk exposure and assess against the remaining risk budget and timeline. Produce and present fit for purpose risk reports, in a timely manner, to … support the effective communication of threat & opportunity status and required senior management action. Establish and maintain documentation of policies and procedures including a RiskManagement Framework and Corporate Assurance Framework. A working understanding of a developing and implementing integrated riskmanagement solutions across portfolios, programmes and projects. Experience of managing a Dependency Management process More ❯
advisory team, then this could be the role for you. As a Manager within the team, you will be a key member of controls advisory team. Combining your Oracle risk and controls expertise with your stakeholder and project management skills and experience, this role will provide you with opportunities to lead multi-disciplinary teams leveraging your knowledge of … risk, controls and Oracle to assess, design and implement Oracle controls for a wide range of clients across multiple industries. This includes applying knowledge of Oracle Cloud emerging technology such as AI Agents and leveraging Oracle RiskManagement & Compliance GRC modules to drive improvements throughout the control lifecycle from assessing risks to implementing, monitoring and assessing controls. … HR Transformation programme; Assessing, designing and implementing Oracle controls across areas including: business process controls, application security/role based access controls, segregation of duties, IT general controls, programme management controls, etc; Assessing, designing and implementing Oracle RiskManagement and Compliance (RMC) modules; Applying your risk and controls experience to support clients in meeting specific requirements More ❯
advisory team, then this could be the role for you. As a Manager within the team, you will be a key member of controls advisory team. Combining your Oracle risk and controls expertise with your stakeholder and project management skills and experience, this role will provide you with opportunities to lead multi-disciplinary teams leveraging your knowledge of … risk, controls and Oracle to assess, design and implement Oracle controls for a wide range of clients across multiple industries. This includes applying knowledge of Oracle Cloud emerging technology such as AI Agents and leveraging Oracle RiskManagement & Compliance GRC modules to drive improvements throughout the control lifecycle from assessing risks to implementing, monitoring and assessing controls. … HR Transformation programme; Assessing, designing and implementing Oracle controls across areas including: business process controls, application security/role based access controls, segregation of duties, IT general controls, programme management controls, etc; Assessing, designing and implementing Oracle RiskManagement and Compliance (RMC) modules; Applying your risk and controls experience to support clients in meeting specific requirements More ❯
Manchester, Lancashire, United Kingdom Hybrid / WFH Options
Deloitte LLP
advisory team, then this could be the role for you. As a Manager within the team, you will be a key member of controls advisory team. Combining your Oracle risk and controls expertise with your stakeholder and project management skills and experience, this role will provide you with opportunities to lead multi-disciplinary teams leveraging your knowledge of … risk, controls and Oracle to assess, design and implement Oracle controls for a wide range of clients across multiple industries. This includes applying knowledge of Oracle Cloud emerging technology such as AI Agents and leveraging Oracle RiskManagement & Compliance GRC modules to drive improvements throughout the control lifecycle from assessing risks to implementing, monitoring and assessing controls. … HR Transformation programme; Assessing, designing and implementing Oracle controls across areas including: business process controls, application security/role based access controls, segregation of duties, IT general controls, programme management controls, etc; Assessing, designing and implementing Oracle RiskManagement and Compliance (RMC) modules; Applying your risk and controls experience to support clients in meeting specific requirements More ❯
Bristol, Gloucestershire, United Kingdom Hybrid / WFH Options
Deloitte LLP
advisory team, then this could be the role for you. As a Manager within the team, you will be a key member of controls advisory team. Combining your Oracle risk and controls expertise with your stakeholder and project management skills and experience, this role will provide you with opportunities to lead multi-disciplinary teams leveraging your knowledge of … risk, controls and Oracle to assess, design and implement Oracle controls for a wide range of clients across multiple industries. This includes applying knowledge of Oracle Cloud emerging technology such as AI Agents and leveraging Oracle RiskManagement & Compliance GRC modules to drive improvements throughout the control lifecycle from assessing risks to implementing, monitoring and assessing controls. … HR Transformation programme; Assessing, designing and implementing Oracle controls across areas including: business process controls, application security/role based access controls, segregation of duties, IT general controls, programme management controls, etc; Assessing, designing and implementing Oracle RiskManagement and Compliance (RMC) modules; Applying your risk and controls experience to support clients in meeting specific requirements More ❯
in Digital Operational Resilience (DORA) and European cyber regulations. As a subject matter expert, you will drive DORA implementation, collaborate with operational resilience teams, and influence policies, controls, and risk frameworks to safeguard critical business services. Key Responsibilities Regulatory Assurance (DORA): Lead gap analyses and implement solutions to ensure full DORA compliance . Embed DORA's six pillars: ICT … RiskManagement, Incident Reporting, Resilience Testing, Information Sharing, Third Party Risk, and Governance . Collaborate with operational resilience and business continuity teams. Design and execute testing initiatives to measure cyber and digital resilience. Assess third-party resilience as part of TPRM efforts. Partner with IT and Risk stakeholders on cross-functional initiatives. Act as a subject … both local and enterprise-wide regulatory requirements. Contribute to the information security policy framework . Governance & Controls: Support ongoing control maintenance and internal audits. Work with stakeholders to assess risk and strengthen mitigation strategies . Build deep expertise around regulated business services . What You Bring Expertise & Education: Degree in IT, Information Security, RiskManagement or a More ❯
Farnborough, Hampshire, South East, United Kingdom
Damia Group Ltd
willing to stand still. Wants to continually develop new skills and undertake personal training. Integrity - Promote a high professional standard at all times. Experience in working with multiple project management methodologies Responsibilities: Project management- The ability to manage all aspects of project delivery, including forecasting, change management and risk management. Oversee deliverables from cross-functional teams … ability to identify problems collaboratively and develop actions/solutions, communicating both to key stakeholders and presenting information through reports, dashboards and slides as appropriate. Commercial awareness- Providing contract management, supplier management. Market experience working within the UK Defence & Security sector is advantageous. Qualifications: Bachelor's or Master's degree in Business, Engineering, Project Management, or related fields … preferred or equivalent experience. Relevant certifications (e.g., APMP, Prince2, Agile Certification) Strong project management, riskmanagement, and procurement management skills. Familiarity with the Agile, Waterfall and Shape Up profiles and methodologies. DV Clearance DV cleared Senior Project Manager - Farnborough (Hybrid), a driving licence and a willingness to travel between the customer site is essential More ❯
NAT CAT Risk - Modelling & Analytics Lead Hybrid As Nat CAT Risk Modelling and Analytics Lead you will be responsible for leading our NAT CAT modelling and analytics team with the CAT Risk function, reporting directly into the AVP for CAT Risk and Capital. You will lead in the areas of complex pricing support, portfolio analysis and … industry leading expertise within our Enterprise Cat function.You will have a thorough understanding of the Lloyd’s market and hold specialist qualifications such as the Certified Specialist in Catastrophe Risk (CSCR), Certified Catastrophe RiskManagement Professional (CCRMP), or a CAT modelling designation from a leading third-party vendor, such as Verisk’s Certified Extreme Event Modeler (CEEM … and verbal communication skills allow you to consult on complex projects and present confidently at all levels of seniority. What Will You Do? Provide complex pricing support to optimize risk assessment and pricing strategies. Conduct portfolio risk reward analysis to influence CAT underwriting strategy Lead model validation efforts and play an leading role in CAT View of RiskMore ❯
of digital transformation projects and programmes across the organisations. Main duties of the job Working within a clear framework the post holder will be responsible for implementing the clinical riskmanagement processes and procedures in accordance with the relevant NHS guidelines. The postholder will lead the digital clinical safety effectiveness team. They will line manage the digital clinical … regulations. Attended clinical safety training for Health IT or hold Master Modules in Patient Safety (or complete training within a short time of joining) Suitably trained and qualified in riskmanagement or have an understanding in principles of risk and safety as applied to Health IT Systems. Desirable Management/Supervisory qualification Experience Essential Extensive experience … as a Clinical Safety Officer. Knowledgeable in riskmanagement and its application to clinical domains. Experience in process and policy development and operating model implementation. Experience of utilising project and programme management techniques. Experience in managing highly complex stakeholder relationships. Experience in writing and delivering high quality reports, documentation, and presentations to people at all levels, including More ❯
Milton Keynes, Buckinghamshire, England, United Kingdom
Lorien
IT Risk & Controls Specialist Location: Milton Keynes Santander is seeking a highly motivated IT Risk & Controls Specialist to lead and enhance riskmanagement practices across both cloud and on-premise environments within the CIO function. This pivotal role ensures compliance with legal, regulatory, and internal standards, while supporting audits and fostering a culture of proactive risk awareness. Key Responsibilities: Champion a strong risk culture across the technology function. Design and implement effective control measures aligned with financial services standards and regulatory requirements. Act as the subject matter expert for IT Risk & Controls across cloud and on-prem platforms. Prepare and present risk reports to senior management and regulatory bodies. Lead continuous … improvement initiatives balancing control effectiveness with business needs. Essential Skills & Experience: Senior-level expertise in IT riskmanagement within regulated industries, ideally Tier 1 banks. Strong understanding of regulatory frameworks, compliance, and technology standards. Proven ability to influence stakeholders and manage risk appetite decisions. Experience managing audits and large-scale risk assessments. Desirable Qualifications: Familiarity with More ❯
Manchester, Lancashire, United Kingdom Hybrid / WFH Options
Softcat plc
have an impact and join a business where you can make the difference? Are you keen to work as part of an enthusiastic, passionate, and collaborative team? Join our Risk, Assurance & Process Improvement As Softcat's business continues to grow and evolve, so have the risks and the regulatory landscape. Softcat Plc has recognised the need to further strengthen … its RiskManagement and Internal Controls and has created a second line function to strengthen the overall three lines model and improve the way in which risks are identified, managed and communicated across the organisation including Board and Audit Committee. The function is led by the Head of Risk, Assurance and Process Improvement who reports to the … ve got even bigger plans for the future. So, if you share our drive and ambition, get ready to achieve more from your career. Strengthening Controls, Enhancing Processes, Managing Risk This senior role within the Risk, Assurance & Process Improvement team offers a unique opportunity to strengthen the control environment and improve end-to-end processes across Softcat Plc More ❯
Manchester, Lancashire, United Kingdom Hybrid / WFH Options
Leigh Day And Co
to manage large amounts of data; a commitment to access to justice; and ability to foster teamwork to create a culture that values collaboration. Main duties and responsibilities Case management To effectively review and draft technical documents. To ensure that accurate information and instructions are obtained from clients and accurate records are maintained. To effectively manage, delegate to and … areas of practice for the department, particularly other potential group actions. To include presentation of seminars, writing articles, joining, and participating in professional and other relevant organisations. Compliance and riskmanagement To always maintain the strictest concern for and awareness of the need for GDPR and data protection and in accordance with the Firm's internal policies. To … adhere to and manage all court deadlines and time limits where applicable. To ensure regulatory compliance in all aspects of the case and that effective and regular riskmanagement is carried out as part of case management. To immediately report any compliance or riskmanagement concerns to the relevant persons without delay. Professional standards To work More ❯
of Travel & Subsistence) Clearance Required: DV (Developed Vetting) (MOD) Brief Summary We are seeking a highly skilled Security Practitioner with strong expertise in MoD Secure by Design (SbD) and riskmanagement , as well as practical knowledge of Operational Technology (OT) and ISO 62443 standards. The successful candidate will play a critical role in supporting security assurance activities within … a high-security environment, contributing to the design, implementation, and management of secure systems. Key Responsibilities Apply MoD SbD principles to ensure systems are designed and implemented securely Lead and support riskmanagement activities aligned with MoD frameworks and standards Provide security assurance for Operational Technology (OT) systems in line with ISO 62443 Collaborate with multidisciplinary teams … and governance requirements Essential Skills & Experience Demonstrable experience as a Security Practitioner (SFIA Level 4/5) Strong understanding of MoD Secure by Design (SbD) principles Proven background in riskmanagement within MoD or similar high-assurance environments Knowledge and application of Operational Technology (OT) security Practical experience with ISO 62443 Active DV Clearance Desirable Familiarity with other More ❯
broad team responsible for ensuring safe, efficient, and well-governed changes across a large-scale data platform. This is a hybrid leadership role combining functional oversight, process design, and riskmanagement - ideal for someone who thrives in high-change environments and understands how to build scalable frameworks that support engineering teams and internal customers. Responsibilities: Lead and evolve … change release and riskmanagement practices across data platforms. Design and implement a service transition framework to manage hundreds of monthly changes. Develop a guidebook for platform change standards and ensure consistent, safe deployments. Collaborate with engineering teams to ensure alignment with best practices and governance. Measure success through internal customer feedback and service quality metrics. Manage a … growing team of up to 8 Stay current with industry trends and apply modern testing, DevOps, and CICD strategies. Requirements: Experience in Change & RiskManagement within Financial Services. Strong understanding of AWS Cloud and modern deployment environments. Exposure to Scaled Agile or similar delivery frameworks. Ability to design and implement service-oriented processes. Strategic thinker with excellent stakeholder More ❯
broad team responsible for ensuring safe, efficient, and well-governed changes across a large-scale data platform. This is a hybrid leadership role combining functional oversight, process design, and riskmanagement - ideal for someone who thrives in high-change environments and understands how to build scalable frameworks that support engineering teams and internal customers. Responsibilities: Lead and evolve … change release and riskmanagement practices across data platforms. Design and implement a service transition framework to manage hundreds of monthly changes. Develop a guidebook for platform change standards and ensure consistent, safe deployments. Collaborate with engineering teams to ensure alignment with best practices and governance. Measure success through internal customer feedback and service quality metrics. Manage a … growing team of up to 8 Stay current with industry trends and apply modern testing, DevOps, and CICD strategies. Requirements: Experience in Change & RiskManagement within Financial Services. Strong understanding of AWS Cloud and modern deployment environments. Exposure to Scaled Agile or similar delivery frameworks. Ability to design and implement service-oriented processes. Strategic thinker with excellent stakeholder More ❯
Project Management Business Partner Location: Broughton (onsite requirement) Hours: 35 per week (4.5 days, flexible between 7am-7pm) Pay: £29.18/hr PAYE | £39.04/hr Umbrella Security Clearance: BPSS+ (completed by Airbus Security) IR35: Inside About the Role Join our professional Project Management team, supporting the Single Aisle Wing Value Stream Management (VSM) programme. You'll … play a pivotal role in driving best practice project management governance, methods, and tools across a dynamic workstream, reporting to the Head of VSM, Project Team, or PM Office. This is a fantastic opportunity to make a real impact on ramp-up governance and key enablement projects, while developing your skills in a collaborative and forward-thinking environment. What … You'll Be Doing Championing project management expertise and ensuring robust governance and practices are applied across the VSM team. Working closely with project leaders and teams, providing coaching, awareness sessions, and constructive challenge to embed best practice. Shaping project management methods and tools to suit the needs of each project or activity. Supporting efficient communication and stakeholder More ❯
role Effectively lead the planning, execution and delivery of multiple complex projects ensuring they are on track and deliver on time within scope and budget Excelllent communication and stakeholder management skills Effective riskmanagement, governance and reporting Strong team management and leadership, with an ability to flex the team as appropriate Proactive, strong and pragmatic delivery … and articulate these clearly Attract, select, develop, motivate, train, and retain a high-quality workforce to deliver excellent outcomes and customer service About you Extensive experience in a Project Management function General Insurance experience is preferred Experience of project management, Financial and budget management, Management of external contractors to agreed service levels, Proven communicator with excellent … people management experience gained in a similar position. Experience developing and presenting business cases and recommendations to senior stakeholders. Experience leading teams or practices, In-depth experience relevant to project delivery Experience supporting projects/change initiatives across a variety of delivery environments Why QBE? At My Best At QBE, we want our people to feel rewarded and inspired More ❯
As a Cyber Security Risk Consultant, you will join our Information Assurance and Cyber Risk team that provides expert risk assessments, audits, analysis and advice to our clients. Applicants must be currently residing in Northern Ireland due to the role’s requirement for client site attendance Your responsibilities will include: Creating business risk models and associated … cyber security and business planning activity across a range of different domains or sectors against recognised standards (e.g. ISO27001, NCSC CAF, NIS Directive, UK GovAssure) Identify mitigations for cyber risk in a given business or operational scenario and threat environment Lead and deliver cyber security audits, risk reviews and control assessments Identify control weaknesses, assess risks, and present … actionable recommendations Produce high-quality risk reports, advisory outputs and client presentations Essential experience of the Cyber Security Risk Consultant: Minimum of 2-3 years of experience in security vulnerability, risk, audit & compliance Proven track record of Cyber Security compliance audits, managing regulatory engagements and working with external and internal regulatory bodies Strong understanding of Cyber security More ❯