At a Glance
- Tasks: Lead Technology Risk Management and ensure effective risk processes across D&T's Products and Platforms.
- Company: Join M&S, a dynamic and inclusive retailer committed to quality and customer service.
- Benefits: Enjoy a 20% discount, competitive holidays, bonuses, and wellbeing support.
- Why this job: Be part of an innovative team transforming retail in a digital era with exciting opportunities.
- Qualifications: Strong IT Risk experience and knowledge of technology controls frameworks required.
- Other info: M&S values diversity and encourages applicants from all backgrounds.
The predicted salary is between 43200 - 72000 £ per year.
As a Technology Risk Senior Lead within the First Line of Defence (1LOD) for M&S Digital and Technology (D&T), you will lead Technology Risk Management within the D&T Risk, Audit, and Compliance function, reporting directly to the Head of Risk, Audit, and Compliance. Your core responsibility will involve managing Technology Risk processes across D&T's Products and Platforms. Your primary objective is to ensure that both individual and aggregated Technology Risks are thoroughly identified, assessed, clearly understood, and effectively managed, with robust strategies in place for mitigating both strategic and tactical risks.
You will work closely with the D&T Products and Platforms teams to identify and assess Technology Risks, encompassing Operational, Transformational, Regulatory, and Emerging Risks, and detail the findings in the M&S GRC (Governance, Risk Management, and Compliance) platform.
Here are some of the benefits we offer that make working for M&S just that little bit more special:
- After completing your probationary period, you’ll receive 20% colleague discount across all M&S products and many of our third-party brands for you and a member of your household.
- Competitive holiday entitlement with the potential to buy extra holiday days!
- Discretionary bonus schemes awarded based on how you achieve your personal objectives and our performance as a business.
- A generous Defined Contribution Pension Scheme and Life Assurance.
- A dedicated welcome to our teams with a tailored induction and a wide range of training programmes to develop your skills.
- Amazing perks and discounts via our M&S Choices portal to maximise your financial and personal wellbeing.
- Industry-leading parental, adoption and neonatal policies, providing support and flexibility for your family.
- Access to a fantastic range of wellbeing support for all colleagues including access to our 24/7 Virtual GP and PAM Assist to support you and your family.
- A charity volunteer day to support a charity or cause you’re passionate about through a dedicated day away from work.
What you’ll do:
- Take the lead in implementing the Risk Assurance Framework across all D&T Product and Platforms.
- Conduct and coordinate Risk identification and assessments processes to identify and analyse potential risks to Technology Operations.
- Develop comprehensive risk mitigation plans in response to identified Risks and control weaknesses.
- Support the development and maintenance of Technology Risk Dashboards and reports that provide an executive overview of the Technology risk landscape, including key risk indicators, mitigation progress, and emerging risks.
- Lead and develop a team of Technology risk professionals, encouraging a culture of continuous improvement, innovation, and risk-aware decision-making.
Who you are:
- Strong experience of IT Risk and Technology Controls Frameworks and the application of Technology Risk standard processes and Risk Standards (ISO 31000, ITIL, Cobit 5, IS27001 COSO, NIST 800-53, SOX etc).
- A track record as an experienced Risk and control practitioner in leading digital/technology controls (experience in managing Cloud and Data technology controls is highly desirable).
- High-level analytical approach to sophisticated technical and business problems.
- Proven track record in technology control identification and management.
- ITGC controls experience preferable.
- Strong communicator - written and verbal with the ability to produce quality reporting and documentation.
- Ability to facilitate and develop cross team collaboration, communicating with people at all levels within the organisation.
- Basic understanding of technology development practices and ways of working (e.g. Waterfall, Agile, DevOps).
- A continuous learner eager to develop knowledge on own and with others.
Marks & Spencer strives to be an inclusive organisation, trusted and admired by our colleagues, customers and suppliers. Join us and make change happen. We are committed to building diverse and representative teams, where everyone can bring their whole selves to work and be at their best. We support each other and work together to win together.
Tech Risk Senior Lead employer: ENGINEERINGUK
Contact Detail:
ENGINEERINGUK Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Tech Risk Senior Lead
✨Tip Number 1
Familiarise yourself with the specific Technology Risk frameworks mentioned in the job description, such as ISO 31000 and NIST 800-53. Understanding these standards will not only help you in interviews but also demonstrate your commitment to the role.
✨Tip Number 2
Network with professionals already working in technology risk management or related fields. Engaging with them on platforms like LinkedIn can provide insights into the company culture and expectations, which can be invaluable during your application process.
✨Tip Number 3
Prepare to discuss real-world examples of how you've identified and mitigated technology risks in previous roles. Having concrete stories ready will showcase your experience and problem-solving skills effectively during interviews.
✨Tip Number 4
Stay updated on the latest trends and challenges in technology risk management, especially those relevant to retail and digital transformation. This knowledge will help you engage in meaningful conversations during interviews and show your proactive approach to the field.
We think you need these skills to ace Tech Risk Senior Lead
Some tips for your application 🫡
Understand the Role: Before applying, make sure to thoroughly understand the responsibilities and requirements of the Tech Risk Senior Lead position. Familiarise yourself with the key technologies and risk management frameworks mentioned in the job description.
Tailor Your CV: Customise your CV to highlight relevant experience in IT Risk and Technology Controls Frameworks. Emphasise your track record in managing digital/technology controls and any specific frameworks like ISO 31000 or NIST 800-53 that you have worked with.
Craft a Compelling Cover Letter: Write a cover letter that showcases your passion for technology risk management. Use specific examples from your past experiences to demonstrate how you have successfully identified and mitigated risks in previous roles.
Highlight Communication Skills: Since strong communication is essential for this role, ensure your application reflects your ability to produce quality reporting and documentation. Mention instances where you facilitated cross-team collaboration or communicated complex information effectively.
How to prepare for a job interview at ENGINEERINGUK
✨Understand the Risk Frameworks
Familiarise yourself with key risk management frameworks such as ISO 31000, ITIL, and NIST 800-53. Be prepared to discuss how these frameworks can be applied in the context of Technology Risk Management at M&S.
✨Showcase Your Analytical Skills
Prepare examples that demonstrate your high-level analytical approach to complex technical and business problems. Highlight any past experiences where you successfully identified and managed technology risks.
✨Communicate Effectively
Practice articulating your thoughts clearly and concisely. As a strong communicator, you should be able to produce quality reports and documentation, so consider bringing samples of your work to showcase your writing skills.
✨Emphasise Team Collaboration
Be ready to discuss your experience in facilitating cross-team collaboration. M&S values teamwork, so share instances where you effectively communicated with various stakeholders to achieve common goals.