Job Description for Technology Risk Manager - Regulatory Reporting Solutions Engineering
Job Description
Job Title: Manager, Technology Risk & Controls (Regulatory Reporting Solutions Engineering)
Global Grade: 13
Company / Division: London Stock Exchange Group - Markets & Risk Intelligence Engineering
Location: London
Work Style: Blended (3 days per week in office - St Martins Court PSQ)
Role Type: Individual Contributor
Job Family / Level: Risk (Technology, Cyber & Resilience Risk)
Reports To: Rupert Thomas - Director, Technology Risk & Controls
Role Purpose
The Manager, Technology Risk & Controls is accountable for leading technology risk, control and regulatory compliance activities across Regulatory Reporting Solutions Engineering. The role applies expert knowledge of technology risk, cyber security, operational resilience and regulatory expectations to ensure risks are identified, assessed, controlled and reported in line with LSEG policy, regulatory standards and industry best practice.
The role will coordinate risk and control activity, produce management information, support governance forums, facilitate reviews, track issue remediation, and partner with engineering, product, production management, cyber, cloud, infrastructure, second-line risk, audit, compliance and legal stakeholders.
Key Responsibilities & Accountabilities
Technology Risk & Control Management
- Support the identification, assessment, monitoring and mitigation of technology, cyber and resilience risks across products, platforms, services and third-party dependencies.
- Coordinate risk and control activities to ensure risks are appropriately recorded, assessed and managed in accordance with internal policies and standards.
- Facilitate regular reviews of risk mitigation plans, ensuring actions, issues and control gaps are tracked through to completion.
- Contribute to the maintenance and continuous improvement of technology risk frameworks, control standards and supporting processes.
- Provide constructive challenge on control effectiveness, evidence quality and risk treatment approaches.
Regulatory Compliance & Oversight
- Support implementation of technology, cyber security and operational resilience requirements applicable to Regulatory Reporting Solutions, including DORA obligations and relevant regulatory reporting expectations.
- Assist in translating regulatory obligations into practical control requirements and governance processes.
- Coordinate evidence gathering and responses for regulatory reviews, ICT risk management assessments, SOC 2 assurance and internal audit activity.
- Escalate emerging compliance risks, control weaknesses and potential breaches in a timely manner.
- Maintain awareness of relevant regulatory developments and industry best practice.
Operational Resilience
- Embed operational resilience requirements within Regulatory Reporting Solutions engineering, technology, production and change activities.
- Contribute to resilience assessments, scenario testing, control validation and remediation activities.
- Coordinate resilience-related actions, evidence and reporting to demonstrate compliance with internal and external requirements.
- Work with engineering, production management, cyber, infrastructure and business stakeholders to strengthen resilience across regulated reporting services and supporting platforms.
Governance, Risk Reporting & MI
- Produce and maintain high-quality risk and control management information for governance forums and senior stakeholders.
- Support the preparation of committee materials, risk papers, dashboards and reporting packs.
- Monitor and report on key risk indicators, control metrics and remediation progress.
- Analyse trends and emerging themes to support risk-informed decision making.
- Ensure risk data remains accurate, complete and appropriately evidenced.
Risk Assessment, Issue Management & Remediation
- Coordinate technology risk assessments, control reviews and thematic risk activities.
- Support the identification, recording and assessment of technology, cyber and resilience risks.
- Track remediation plans for risk events, audit findings, control deficiencies and regulatory actions.
- Provide oversight of action delivery, challenging delays and escalating concerns where required.
- Ensure remediation activities are appropriately evidenced and sustainably implemented.
Third-Party & Technology Dependency Risk
- Support oversight of technology suppliers, cloud services and other critical dependencies from a risk and control perspective.
- Coordinate due diligence, assurance reviews and risk assessments relating to third-party services.
- Monitor remediation activity arising from supplier reviews and control assessments.
- Promote alignment with enterprise standards relating to cloud, supplier and technology risk management.
- Maintain effective stakeholder relationships to support the management of dependency-related risks.
Stakeholder Partnership & Risk Advisory
- Act as a trusted partner to engineering, product and techn
#J-18808-Ljbffr
Technology Risk Manager - Post Trade Regulatory Reporting employer: LSEG
LSEG is an exceptional employer that fosters a culture of integrity, partnership, and excellence, making it an ideal place for professionals seeking to make a meaningful impact in technology procurement. With a focus on employee growth, you will have the opportunity to lead high-value negotiations and develop a talented team while working in a dynamic environment in London, where innovation and continuous improvement are at the forefront. Join us to shape the future of Corporate Engineering technology and enjoy the benefits of a supportive workplace that values your contributions.