Job Title: IT Risks & Control Manager
Target Start Date: ASAP
Contract Type: Permanent, Part Time, Full Time, Job Share option available
Salary Range: Β£59,200 - Β£88,800
Location: Hybrid, Eastleigh
Work Level: 4
Closing Date for applications: Wednesday 23rd September
Hiring Manager: Richard Frost
IT Risks & Control Manager: We're looking for an experienced IT Risk and Controls Manager to join our Information Security Governance, Risk and Compliance team. In this senior specialist role, you'll lead the identification, assessment, management and reporting of IT risks across Ageas, helping ensure technology risks are clearly understood, documented and managed in line with our risk appetite.
Reporting to the Governance, Risk and Compliance Lead, you'll own the IT risk register, facilitate senior IT risk discussions and provide clear, high-quality reporting for governance forums and second-line risk teams.
Main Responsibilities:
- Lead IT risk and control assessments using recognised frameworks such as ISO/IEC 27001 and NIST-aligned controls.
- Own and maintain the IT risk register, ensuring risks, controls and treatment plans are accurate and up to date.
- Assess the design and effectiveness of IT controls and support timely remediation, acceptance or escalation of risks.
- Facilitate IT risk meetings with senior technology leaders, providing clear insight and practical recommendations.
- Produce meaningful risk reporting covering trends, control effectiveness and key issues for governance forums.
- Support internal and external audits by providing evidence aligned to recognised control frameworks.
- Work with Security Architecture, Engineering and Operations teams to ensure risks are managed through effective, proportionate controls.
Skills and experience:
- Strong experience in IT risk management, technology risk or information security risk.
- Good knowledge of IT control frameworks, particularly ISO/IEC 27001 and NIST-aligned controls.
- Experience maintaining IT risk registers and working with GRC tools.
- Confidence facilitating senior stakeholder discussions and governance meetings.
- Ability to translate technical risk and control issues into clear, decision-ready insight.
- A pragmatic, structured and risk-based approach, with strong attention to detail.
It would be great if you also have -
- Certifications such as CRISC, CISM, CISSP or ISO 27001 Lead Implementer/Auditor.
- Experience working in a regulated or high-assurance environment.
- Experience mapping controls across ISO 27001, NIST and internal frameworks.
To find out more about this role and for information please contact Zoe Powell OR Richard Frost.
#J-18808-Ljbffr
IT Risks & Control Manager employer: Ageas
Ageas is an excellent employer that fosters a collaborative and innovative work culture, where employees are empowered to contribute to meaningful projects like large-scale integration programmes. With a strong focus on professional development, you will have ample opportunities for growth and advancement while enjoying the benefits of a supportive team environment in a dynamic industry. Located in a vibrant area, Ageas offers unique advantages such as flexible working arrangements and a commitment to employee well-being.