At a Glance
- Tasks: Lead technology risk management and ensure safe innovation in a regulated environment.
- Company: Join a forward-thinking firm focused on risk and compliance.
- Benefits: Competitive salary, flexible working, and opportunities for professional growth.
- Other info: Dynamic role with opportunities to collaborate across various teams.
- Why this job: Make a real impact by managing technology risks and enabling innovation.
- Qualifications: Experience in technology risk management or audit, with strong communication skills.
The predicted salary is between 60000 - 80000 £ per year.
Are you passionate about enabling innovation safely in a highly regulated environment? We are seeking a Technology Risk Manager to join our Risk & Compliance function and operate as part of the First Line of Defence (1LoD) in protecting the firm against existing and emerging risks. In this role, you will help the firm identify, assess, manage and report technology risks including those relating to Data, AI and Operational Resilience embedding pragmatic risk management into day-to-day delivery, operational processes and third-party relationships. You will partner closely with Technology, Information Security, Data, Legal, Compliance and business stakeholders to ensure that risk is understood, owned, and managed in line with the firm’s risk appetite supporting growth, client trust and the right regulatory outcomes.
Department Risk & Compliance work in collaboration with the business to ensure best practice across the firm, effectively managing all aspects of the regulation surrounding the efficient running of the firm. We are looking for someone with high attention to detail who prides themselves on providing excellent service. The Risk and Compliance team is working closely with the Technology and Cyber teams to ensure colleagues and clients facing products and services are secure, resilient and well-governed. This role strengthens our ability to scale responsibly by ensuring risk management is embedded into how we operate and change globally. This role will report to the General Counsel.
Duties and Responsibilities
- Risk Leadership & Ownership
- Act as a risk partner supporting Technology leadership and teams to own and manage risks within their areas.
- Maintain a clear view of the firm’s technology risk profile across Data, AI and Operational Resilience and Technology operations e.g., infrastructure, cloud, applications, identity, endpoints, collaboration tooling. This includes maintaining a Technology Risk Register.
- Translate regulatory and internal requirements into practical controls and guidance, regularly assessing and reporting on the design and operating effectiveness of the control environment through controls validation.
- Promote a strong risk culture: "secure and compliant by design" while enabling pace and innovation.
- Data Risk
- Work with the Technology Business Solutions, DPO and Data Governance teams to support effective management of data risks including:
- Updating policies and minimum standards.
- Independently validating the Data Governance Framework and assessing the design and operating effectiveness of key controls.
- Assessing, reporting on and tracking risk mitigation plans where risks are outside appetite.
- AI Risks and Responsible AI Enablement
- Help maintain and embed AI risk management for both internal and client-facing use cases, including:
- Use-case/product risk assessments (privacy, security, bias/fairness, explainability, IP, confidentiality).
- Approval pathways and guardrails for generative AI tools.
- Model/solution lifecycle controls (testing, monitoring, change management).
- Support creation and maintenance of AI standards, playbooks and minimum control baselines aligned to the firm’s risk appetite.
- Cyber / Information Security Risk
- Partner with Cyber Security to ensure security risks are identified, documented and actively managed across teams (Technology, brand etc.).
- Assess and report on the design and operating effectiveness of security controls ensuring control failures are addressed on a timely basis and reported/escalated where necessary.
- Where applicable, assist with security risk acceptances: ensuring decisions are documented, time-bound, and include remediation plans.
- Technology & Operational Resilience Risk
- Assess and report on risk management for technology operations, including:
- Availability, resilience, backup and recovery of critical services.
- Capacity, obsolescence and technical debt.
- Change/release risk and service stability.
- Contribute to business continuity and disaster recovery planning, testing and lessons learned.
- Monitor incident governance: capturing risk themes, root causes, control improvements and reporting.
- Change, Delivery & Control-by-Design
- Help embed technology risk management into delivery lifecycles (Waterfall/Agile), including:
- Project/product risk assessments and go/no-go decision support.
- Design reviews to confirm controls are considered early.
- Support for secure SDLC practices and control evidence capture.
- Help define "minimum viable controls" that are proportionate to risk and practical for teams.
- Third-Party / Supplier & Outsourcing Risk
- Working closely with Technology to support the assessment and ongoing oversight of technology suppliers, including cloud and SaaS vendors:
- Due diligence, control requirements and contractual risk input.
- Ongoing monitoring (performance, incidents, compliance attestations).
- Exit/portability and concentration risk considerations.
- Maintain a view of material supplier risks and remediation actions.
- Governance, Reporting & Assurance Support
- Maintain and improve technology risk artefacts: risk registers, control libraries/universe, KRIs/KPIs, thematic findings and action plans.
- Provide clear reporting for Technology leadership and relevant governance committees.
- Support audits, second line reviews and regulatory requests by coordinating evidence and ensuring timely closure of actions.
Skills & Experience
- Professional Experience
- Proven experience in technology risk management or technology audit—ideally within a regulated or professional services environment.
- Demonstrable experience working in or alongside a Three Lines of Defence model, with an understanding of 1LoD responsibilities.
- Experience (depth and breadth) supporting risk management across multiple domains including data, AI, resilience, and Technology operations and change.
- Domain Knowledge
- Strong understanding of risk assessment techniques (inherent/residual risk, control effectiveness, action planning).
- Familiarity with control frameworks and assurance concepts (e.g., ISO 27001, NIST, COBIT, ITIL).
- Familiarity with UK regulations relating to the areas in scope for this role.
- Experience defining, embedding and monitoring controls balancing pragmatism with robustness.
- Leadership and Interpersonal Skills
- Strong influencing skills to gain buy-in from stakeholders at all levels.
- Ability to navigate complex organisational dynamics and drive consensus.
- Communication Skills
- Exceptional verbal and written communication skills, with the ability to present complex ideas clearly and persuasively.
- Experience in presenting to boards, executive committees, and large audiences.
- Skilled in building and maintaining relationships with clients, partners, and internal stakeholders.
- Personal Attributes
- Passionate about innovation and driving change to enhance business outcomes.
- Open-minded and adaptable to new ideas and technologies.
- Strong focus on achieving goals and delivering measurable results.
- Ability to prioritise and manage multiple initiatives effectively.
- Commitment to the highest ethical standards and professional integrity.
Please note that this job profile is not an exhaustive list of duties but merely an outline of the key components of the role. You may be required by your line manager to take on additional responsibilities when requested.
Technology Risk Manager in London employer: Mishcon de Reya Group
As a Technology Risk Manager at our firm, you will thrive in a dynamic and collaborative work culture that prioritises innovation while ensuring compliance in a highly regulated environment. We offer competitive benefits, a commitment to employee growth through continuous learning opportunities, and a strong focus on fostering a secure and resilient operational framework. Join us in a role that not only supports your professional development but also contributes to the firm's mission of enabling safe technological advancements.
StudySmarter Expert Advice🤫
We think this is how you could land Technology Risk Manager in London
✨Join Compliance Communities
Get involved in compliance and risk communities — both online and offline. Look for forums, LinkedIn groups, or even local meetups where compliance pros hang out. You never know who might drop a job opportunity your way!
✨Attend Industry Conferences
Keep an eye out for compliance and risk management conferences and workshops in your area. These events are a goldmine for networking, and they often have job boards or recruiters on-site looking for new talent. Plus, it’s a chance to learn what's trending in the field.
✨Leverage Your University Career Services
If you’ve recently graduated or are still studying, head over to your university's career services. Many companies, including those in compliance, actively recruit fresh talent through these services, so make sure you tap into that resource.
✨Showcase Your Knowledge Online
Start writing articles or blog posts about compliance topics that interest you. Share them on platforms like LinkedIn to demonstrate your knowledge and passion. This not only builds your presence in the field but can also catch the attention of companies like Mishcon de Reya Group looking for candidates who are engaged and informed.
We think you need these skills to ace Technology Risk Manager in London
Some tips for your application 🫡
Show Your Understanding of Compliance:In the compliance-risk field, it's super important to showcase your understanding of regulations and risk management frameworks. Highlight any relevant coursework, certifications (like ICA or AML), or even projects that demonstrate your knowledge and commitment to this area. We want to see how you can navigate this complex landscape!
Quantify Your Achievements:When detailing your experience, try to quantify your achievements. For example, if you've previously worked on a project that improved compliance metrics or reduced risk exposure, give us the numbers! This data-driven approach really stands out to hiring managers in compliance-risk roles.
Tailor Your CV to Reflect Relevant Skills:Make sure your CV highlights skills that are particularly relevant to compliance, like attention to detail, analytical thinking, and report writing. Ensure these are easy to spot – consider using bullet points to break down your responsibilities and achievements for maximum impact!
Craft a Motivating Cover Letter:In your cover letter, let us know why you’re excited about the compliance-risk role at Mishcon de Reya Group. Share what motivates you about compliance, and how you believe you can contribute to our mission. This is your chance to showcase not only your skills but also your passion for this important field!
How to prepare for a job interview at Mishcon de Reya Group
✨Master the Regulations
Brush up on key compliance regulations relevant to the industry you're applying to. Familiarising yourself with specific laws and frameworks used in your field will give you an edge during technical questions. Show that you’re not just aware of them but can also apply them—think real-life scenarios!
✨Show Your Analytical Skills
Compliance roles really focus on analytical skills, so be prepared for case studies or situational questions during the interview. We've got to demonstrate how we approach risk assessments or compliance audits, possibly drawing on examples from past experiences or university projects. Bring some thoughtful case scenarios to discuss!
✨Know Your Tools
Get comfortable with commonly used compliance software and tools. Familiarity with platforms like RSA or MetricStream can really impress during your interview, as it shows you're ready to hit the ground running. If you’ve had any experience with them, make sure to highlight that!
✨Align with Company Culture
Since it's a full-time position, show your long-term commitment and interest in the company’s mission and values. Dive into how your ethics and professional philosophy align with Mishcon de Reya Group’s stance on compliance. A shared vision can really resonate with interviewers looking for fit as much as skill!