Technology Risk Manager

Technology Risk Manager

Full-Time 60000 - 80000 £ / year (est.) No working from home possible
Mishcon de Reya Group

At a Glance

  • Tasks: Lead technology risk management and ensure safe innovation in a regulated environment.
  • Company: Join a forward-thinking firm focused on risk and compliance.
  • Benefits: Competitive salary, flexible working, and opportunities for professional growth.
  • Other info: Dynamic team environment with a focus on collaboration and ethical standards.
  • Why this job: Make a real impact by managing technology risks and enabling innovation.
  • Qualifications: Experience in technology risk management and strong communication skills.

The predicted salary is between 60000 - 80000 £ per year.

Are you passionate about enabling innovation safely in a highly regulated environment? We are seeking a Technology Risk Manager to join our Risk & Compliance function and operate as part of the First Line of Defence (1LoD) in protecting the firm against existing and emerging risks. In this role, you will help the firm identify, assess, manage and report technology risks including those relating to Data, AI and Operational Resilience embedding pragmatic risk management into day-to-day delivery, operational processes and third-party relationships. You will partner closely with Technology, Information Security, Data, Legal, Compliance and business stakeholders to ensure that risk is understood, owned, and managed in line with the firm’s risk appetite supporting growth, client trust and the right regulatory outcomes.

Department Risk & Compliance work in collaboration with the business to ensure best practice across the firm, effectively managing all aspects of the regulation surrounding the efficient running of the firm. We are looking for someone with high attention to detail who prides themselves on providing excellent service. The Risk and Compliance team is working closely with the Technology and Cyber teams to ensure colleagues and clients facing products and services are secure, resilient and well-governed. This role strengthens our ability to scale responsibly by ensuring risk management is embedded into how we operate and change globally. This role will report to the General Counsel.

Duties and Responsibilities

  • Risk Leadership & Ownership: Act as a risk partner supporting Technology leadership and teams to own and manage risks within their areas. Maintain a clear view of the firm’s technology risk profile across Data, AI and Operational Resilience and Technology operations e.g., infrastructure, cloud, applications, identity, endpoints, collaboration tooling. This includes maintaining a Technology Risk Register. Translate regulatory and internal requirements into practical controls and guidance, regularly assessing and reporting on the design and operating effectiveness of the control environment through controls validation. Promote a strong risk culture: "secure and compliant by design" while enabling pace and innovation.
  • Data Risk: Work with the Technology Business Solutions, DPO and Data Governance teams to support effective management of data risks including updating policies and minimum standards, independently validating the Data Governance Framework and assessing the design and operating effectiveness of key controls, and assessing, reporting on and tracking risk mitigation plans where risks are outside appetite.
  • AI Risks and Responsible AI Enablement: Help maintain and embed AI risk management for both internal and client-facing use cases, including use-case/product risk assessments (privacy, security, bias/fairness, explainability, IP, confidentiality), approval pathways and guardrails for generative AI tools, model/solution lifecycle controls (testing, monitoring, change management), and support creation and maintenance of AI standards, playbooks and minimum control baselines aligned to the firm’s risk appetite.
  • Cyber / Information Security Risk: Partner with Cyber Security to ensure security risks are identified, documented and actively managed across teams (Technology, brand etc.). Assess and report on the design and operating effectiveness of security controls ensuring control failures are addressed on a timely basis and reported/escalated where necessary. Where applicable, assist with security risk acceptances: ensuring decisions are documented, time-bound, and include remediation plans.
  • Technology & Operational Resilience Risk: Assess and report on risk management for technology operations, including availability, resilience, backup and recovery of critical services, capacity, obsolescence and technical debt, change/release risk and service stability. Contribute to business continuity and disaster recovery planning, testing and lessons learned. Monitor incident governance: capturing risk themes, root causes, control improvements and reporting.
  • Change, Delivery & Control-by-Design: Help embed technology risk management into delivery lifecycles (Waterfall/Agile), including project/product risk assessments and go/no-go decision support, design reviews to confirm controls are considered early, and support for secure SDLC practices and control evidence capture. Help define "minimum viable controls" that are proportionate to risk and practical for teams.
  • Third-Party / Supplier & Outsourcing Risk: Working closely with Technology to support the assessment and ongoing oversight of technology suppliers, including cloud and SaaS vendors: due diligence, control requirements and contractual risk input, ongoing monitoring (performance, incidents, compliance attestations), and exit/portability and concentration risk considerations. Maintain a view of material supplier risks and remediation actions.
  • Governance, Reporting & Assurance Support: Maintain and improve technology risk artefacts: risk registers, control libraries/universe, KRIs/KPIs, thematic findings and action plans. Provide clear reporting for Technology leadership and relevant governance committees. Support audits, second line reviews and regulatory requests by coordinating evidence and ensuring timely closure of actions.

Skills & Experience

  • Professional Experience: Proven experience in technology risk management or technology audit—ideally within a regulated or professional services environment. Demonstrable experience working in or alongside a Three Lines of Defence model, with an understanding of 1LoD responsibilities. Experience (depth and breadth) supporting risk management across multiple domains including data, AI, resilience, and Technology operations and change.
  • Domain Knowledge: Strong understanding of risk assessment techniques (inherent/residual risk, control effectiveness, action planning). Familiarity with control frameworks and assurance concepts (e.g., ISO 27001, NIST, COBIT, ITIL). Familiarity with UK regulations relating to the areas in scope for this role. Experience defining, embedding and monitoring controls-balancing pragmatism with robustness.
  • Leadership and Interpersonal Skills: Strong influencing skills to gain buy-in from stakeholders at all levels. Ability to navigate complex organisational dynamics and drive consensus.
  • Communication Skills: Exceptional verbal and written communication skills, with the ability to present complex ideas clearly and persuasively. Experience in presenting to boards, executive committees, and large audiences. Skilled in building and maintaining relationships with clients, partners, and internal stakeholders.
  • Personal Attributes: Passionate about innovation and driving change to enhance business outcomes. Open-minded and adaptable to new ideas and technologies. Strong focus on achieving goals and delivering measurable results. Ability to prioritise and manage multiple initiatives effectively. Commitment to the highest ethical standards and professional integrity.

Please note that this job profile is not an exhaustive list of duties but merely an outline of the key components of the role. You may be required by your line manager to take on additional responsibilities when requested.

Technology Risk Manager employer: Mishcon de Reya Group

Join a forward-thinking firm that prioritises innovation while ensuring safety in a highly regulated environment. As a Technology Risk Manager, you will thrive in a collaborative culture that values excellence and integrity, with ample opportunities for professional growth and development. Our commitment to a strong risk culture and employee empowerment makes us an exceptional employer, particularly in our dynamic location that fosters creativity and strategic thinking.

Mishcon de Reya Group

Contact Details:

Mishcon de Reya Group Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Technology Risk Manager

Tip Number 1

Network like a pro! Reach out to people in the industry, attend events, and connect on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Prepare for interviews by researching the company and its culture. Understand their approach to technology risk management and think about how your skills align with their needs. This will help you stand out as a candidate who truly gets them.

Tip Number 3

Practice your responses to common interview questions, especially those related to risk management and compliance. Use the STAR method (Situation, Task, Action, Result) to structure your answers and showcase your experience effectively.

Tip Number 4

Don’t forget to follow up after interviews! A quick thank-you email can leave a lasting impression and show your enthusiasm for the role. Plus, it keeps you on their radar as they make their decision.

We think you need these skills to ace Technology Risk Manager

Technology Risk Management
Data Risk Management
AI Risk Management
Operational Resilience
Regulatory Compliance
Risk Assessment Techniques
Control Frameworks (ISO 27001, NIST, COBIT, ITIL)

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in technology risk management. Use keywords from the job description to show that you understand what we're looking for.

Showcase Your Skills:Don’t just list your skills; provide examples of how you've applied them in real-world situations. We want to see how you’ve managed risks, especially in areas like Data, AI, and Operational Resilience.

Be Clear and Concise:When writing your application, keep it straightforward. Use clear language and avoid jargon unless it's relevant. We appreciate a well-structured application that gets straight to the point.

Apply Through Our Website:We encourage you to submit your application through our website. It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it shows you're keen on joining our team!

How to prepare for a job interview at Mishcon de Reya Group

Know Your Risk Management Frameworks

Familiarise yourself with key risk management frameworks like ISO 27001 and NIST. Be ready to discuss how these frameworks apply to technology risk, especially in relation to data, AI, and operational resilience.

Showcase Your Communication Skills

Prepare to demonstrate your exceptional verbal and written communication skills. Think of examples where you've presented complex ideas clearly, especially to stakeholders at various levels, as this is crucial for the role.

Understand the Regulatory Landscape

Brush up on UK regulations relevant to technology risk management. Be prepared to discuss how you would ensure compliance while enabling innovation, as this will show your understanding of balancing risk and growth.

Prepare Real-World Examples

Think of specific instances where you've successfully managed technology risks or led initiatives in a regulated environment. Use the STAR method (Situation, Task, Action, Result) to structure your responses and highlight your achievements.