At a Glance
- Tasks: Manage IT risk and compliance, ensuring robust controls and effective reporting.
- Company: Join a leading financial services firm focused on technology and risk management.
- Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
- Other info: Collaborative culture with excellent career advancement opportunities.
- Why this job: Make a real impact in technology governance and risk management within a dynamic environment.
- Qualifications: 10+ years in technology compliance and risk management, strong analytical skills required.
The predicted salary is between 60000 - 75000 £ per year.
Division: Information Technology
Reports To: As per Beazley’s organisation chart
Key Relationships: Risk, Audit, Compliance, Information Security, Financial controls teams, General Management, IT/Data leadership and SMEs, Operational resilience, Procurement and Third-Party Management, COO general management, COO Business Risk and Controls team.
Job Summary: The role will effectively manage and oversee compliance across the IT and Data portfolio, ensuring robust risk, control management and assurance, internal and external audits, regulatory actions and workstreams. The role will play a pivotal part in developing and producing comprehensive monthly, quarterly, and ad‑hoc risk and controls review and reporting, providing assurance to senior management and keeping them informed.
Key Responsibilities
- Risk & Control Management
- Manage all first line risk and controls activities within the IT and Data functions to maintain consistency, support a strong risk culture, and ensure alignment with organisational risk framework & appetite and governance expectations.
- Oversee risk identification, assessments, acceptances, and mitigation strategies within technology functions, ensuring appropriate controls are in place.
- Effective management of all risks, controls and incidents activities that fall under the IT and Data remit, liaising and ensuring alignment and collaboration with Group Risk management in maintaining and communicating up to date risk information.
- Partner with relevant teams and SMEs to co‑manage the existing controls to include alignment on priorities and performance expectations.
- Manage controls annual assessment and improvement plan for controls.
- Manage all IT and Data actions related to risk, assurance, controls.
- Enhance and manage the IT risk management process and IT/Data risk registers, and where applicable, alignment with functional and group risk management frameworks.
- Develop, implement, and monitor KPIs and KRIs for technology controls and risk exposure, supporting reporting for governance forums and senior management.
- Where risks fall outside of appetite/tolerance, work with relevant stakeholders in developing and tracking a mitigation plan within reasonable timelines.
- Support the identification of issues, issue management and remediation and provide reporting on risk/controls/KRIs to the relevant stakeholders.
- Challenging business on risk and control matters (e.g., incidents, issues, and actions) and the overall management of control environment.
- Mapping policies, standards and controls to regulatory requirements and industry frameworks (DORA, CBI, CIS, ISO, NIST).
- Manage internal and external audit processes, ensuring timely and accurate responses to audit requests, and driving remediation of findings with timely closures of related actions.
- Provide guidance and support to stakeholders regarding compliance and governance requirements.
- Manage and enhance an IT compliance register, mapped with applicable regulatory requirements and associated controls.
- Monitor changes in relevant laws and regulations and advising on impact and remediation, in conjunction with Compliance.
- Ensure policies, standards and guidance are updated following any review activities such as (but not limited to) external audits, regulatory changes and any internal change/requirements.
- Support the governance and communication of these updates to relevant stakeholders and committee/boards.
- Sit on relevant committees, incl. Tech Risk committee as required.
- In collaboration with Compliance, support relevant teams in fulfilling regulatory deliverables and provide input on any required communication to a regulator (e.g. CBI).
Personal Specification
Essential Criteria
- Extensive experience in governance roles, such as risk and controls, audit or compliance.
- Extensive experience in technology roles with excellent analytical and problem‑solving abilities.
- Strong stakeholder engagement skills across all organisational levels.
Education and Qualifications
- Extensive experience (10+ years) in technology compliance, risk management, controls, and governance within a regulated environment.
- Experience within a financial industry desired.
- BA/BS degree, and/or relevant industry experience.
Skills and Abilities
- Experience in Technology governance, risk, and compliance.
- Strong stakeholder management at all levels.
- Providing guidance on Technology governance, risk, and compliance matters.
- Ability to identify and evaluate Technology risks and controls and provide practical and effective recommendations.
- Ability to communicate complex Technology risk and compliance issues to non‑technical audiences.
- Experience in writing effective committee papers desired.
Knowledge Requirements
- Passionate about compliance, risk management, audit principles and practices and continuous improvement.
- Proven experience in operating in an IT GRC environment and in particular, leading the designing of IT risk frameworks, controls and policies.
- Excellent stakeholder management, communication and influencing skills, with the ability to build strong relationships and partnerships across the organisation.
- Strong knowledge and understanding of Technology risk management frameworks, methodologies and tools, such as COBIT, ISO 27001, NIST, etc.
- Strong knowledge of Technology governance, compliance and regulatory requirements, such as GDPR, PCI‑DSS, Solvency II, etc.
- Analytical approach with ability to work systematically and unsupervised, to tight deadlines and with multiple competing priorities.
- Demonstrable ability to communicate with project teams and advise on operational implications of business requirements and change delivery risks.
- A self‑starter and independent learner who takes the initiative to challenge the status quo and is creative and comfortable with ‘blank sheet of paper’ assignments.
- Strong written and oral communication skills.
- Influencing and excellent report‑writing experience with a high standard of English is a pre‑requisite.
Senior Technology Risk Analyst employer: Beazley Management Limited
Contact Detail:
Beazley Management Limited Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Technology Risk Analyst
✨Tip Number 1
Network like a pro! Reach out to your connections in the industry, especially those in risk and compliance roles. A friendly chat can lead to insider info about job openings that aren't even advertised yet.
✨Tip Number 2
Prepare for interviews by brushing up on your knowledge of technology risk frameworks and compliance regulations. We want you to be able to discuss how you've tackled similar challenges in the past, so have some examples ready!
✨Tip Number 3
Don’t just apply anywhere; focus on companies that align with your values and expertise. When you find a role that excites you, apply through our website to ensure your application gets the attention it deserves!
✨Tip Number 4
Follow up after interviews! A quick thank-you email can go a long way in keeping you top of mind. Plus, it shows your enthusiasm for the role and the company, which is always a bonus.
We think you need these skills to ace Senior Technology Risk Analyst
Some tips for your application 🫡
Tailor Your CV: Make sure your CV speaks directly to the role of Senior Technology Risk Analyst. Highlight your experience in governance, risk management, and compliance, especially within a tech environment. We want to see how your skills align with our needs!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about technology risk and how your background makes you the perfect fit for us. Don’t forget to mention specific experiences that relate to the job description.
Showcase Your Stakeholder Engagement Skills: Since this role involves working with various teams, make sure to highlight your stakeholder management experience. Share examples of how you've successfully collaborated with different departments or influenced decision-making in your previous roles.
Proofread, Proofread, Proofread!: Before hitting send, double-check your application for any typos or grammatical errors. A polished application shows attention to detail, which is crucial in risk management. We’re excited to see your application on our website!
How to prepare for a job interview at Beazley Management Limited
✨Know Your Risk Frameworks
Familiarise yourself with key risk management frameworks like COBIT, ISO 27001, and NIST. Be ready to discuss how these frameworks apply to the role and how you've used them in past experiences.
✨Showcase Stakeholder Engagement Skills
Prepare examples that highlight your ability to engage with stakeholders at all levels. Think about times when you successfully communicated complex risk issues to non-technical audiences and how you built strong relationships.
✨Demonstrate Analytical Problem-Solving
Be prepared to discuss specific instances where you've identified technology risks and implemented effective controls. Use the STAR method (Situation, Task, Action, Result) to structure your responses.
✨Stay Updated on Regulatory Changes
Research recent changes in relevant laws and regulations that impact the financial industry. Be ready to discuss how these changes could affect the organisation and what proactive steps you would recommend.