Technology Risk Manager in City of Westminster

Technology Risk Manager in City of Westminster

City of Westminster Full-Time 60000 - 80000 £ / year (est.) No working from home possible
Mishcon de Reya

At a Glance

  • Tasks: Manage technology risks and ensure safe innovation in a regulated environment.
  • Company: Join a leading firm focused on risk management and compliance.
  • Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
  • Other info: Collaborative culture with a focus on innovation and ethical standards.
  • Why this job: Be at the forefront of technology risk management and drive impactful change.
  • Qualifications: Experience in technology risk management or audit, with strong communication skills.

The predicted salary is between 60000 - 80000 £ per year.

Are you passionate about enabling innovation safely in a highly regulated environment? We are seeking a Technology Risk Manager to join our Risk & Compliance function and operate as part of the First Line of Defence (1LoD) to protect the firm against existing and emerging risks. In this role, you will help the firm identify, assess, manage and report technology risks including those relating to Data, AI and Operational Resilience, embedding pragmatic risk management into day‑to‑day delivery, operational processes and third‑party relationships. You will partner closely with Technology, Information Security, Data, Legal, Compliance and business stakeholders to ensure that risk is understood, owned, and managed in line with the firm's risk appetite, supporting growth, client trust and the right regulatory outcomes. This role will report to the General Counsel and works closely with the Technology and Cyber teams to ensure colleagues and clients facing products and services are secure, resilient and well‑governed. It strengthens our ability to scale responsibly by ensuring risk management is embedded into how we operate and change globally.

Risk Leadership & Ownership Responsibilities

  • Act as a risk partner supporting Technology leadership and teams to own and manage risks within their areas.
  • Maintain a clear view of the firm's technology risk profile across Data, AI and Operational Resilience and Technology operations (e.g., infrastructure, cloud, applications, identity, endpoints, collaboration tooling). This includes maintaining a Technology Risk Register.
  • Translate regulatory and internal requirements into practical controls and guidance, regularly assessing and reporting on the design and operating effectiveness of the control environment through controls validation.
  • Promote a strong risk culture: 'secure and compliant by design' while enabling pace and innovation.

Data Risk

  • Work with the Technology Business Solutions, DPO and Data Governance teams to support effective management of data risks, including updating policies and minimum standards.
  • Independently validate the Data Governance Framework and assess the design and operating effectiveness of key controls.
  • Assess, report on and track risk mitigation plans where risks are outside appetite.

AI Risks and Responsible AI Enablement

  • Help maintain and embed AI risk management for both internal and client‑facing use cases, including use‑case/product risk assessments (privacy, security, bias/fairness, explainability, IP, confidentiality).
  • Develop approval pathways and guardrails for generative AI tools.
  • Implement model/solution lifecycle controls (testing, monitoring, change management).
  • Support creation and maintenance of AI standards, playbooks and minimum control baselines aligned to the firm's risk appetite.

Cyber / Information Security Risk

  • Partner with Cyber Security to ensure security risks are identified, documented and actively managed across teams.
  • Assess and report on the design and operating effectiveness of security controls, ensuring control failures are addressed on a timely basis and reported/escalated where necessary.
  • Where applicable, assist with security risk acceptances: ensuring decisions are documented, time‑bound, and include remediation plans.

Technology & Operational Resilience Risk

  • Assess and report on risk management for technology operations, including availability, resilience, backup and recovery of critical services, capacity, obsolescence and technical debt, change/release risk and service stability.
  • Contribute to business continuity and disaster recovery planning, testing and lessons learned.
  • Monitor incident governance: capturing risk themes, root causes, control improvements and reporting.

Change, Delivery & Control‑by‑Design

  • Help embed technology risk management into delivery lifecycles (Waterfall/Agile), including project/product risk assessments and go/no‑go decision support.
  • Support design reviews to confirm controls are considered early.
  • Support secure SDLC practices and control evidence capture.
  • Define 'minimum viable controls' that are proportionate to risk and practical for teams.

Third‑Party / Supplier & Outsourcing Risk

  • Working closely with Technology to support the assessment and ongoing oversight of technology suppliers, including cloud and SaaS vendors.
  • Conduct due diligence, control requirements and contractual risk input.
  • Perform ongoing monitoring (performance, incidents, compliance attestations).
  • Manage exit/portability and concentration risk considerations.
  • Maintain a view of material supplier risks and remediation actions.

Governance, Reporting & Assurance Support

  • Maintain and improve technology risk artefacts: risk registers, control libraries/universe, KRIs/KPIs, thematic findings and action plans.
  • Provide clear reporting for Technology leadership and relevant governance committees.
  • Support audits, second line reviews and regulatory requests by coordinating evidence and ensuring timely closure of actions.

Professional Experience

  • Proven experience in technology risk management or technology audit—ideally within a regulated or professional services environment.
  • Demonstrable experience working in or alongside a Three Lines of Defence model, with an understanding of 1LoD responsibilities.
  • Experience supporting risk management across multiple domains including data, AI, resilience and Technology operations and change.

Domain Knowledge

  • Strong understanding of risk assessment techniques (inherent/residual risk, control effectiveness, action planning).
  • Familiarity with control frameworks and assurance concepts (ISO 27001, NIST, COBIT, ITIL).
  • Knowledge of UK regulations relating to the areas in scope for this role.
  • Experience defining, embedding and monitoring controls, balancing pragmatism with robustness.

Leadership and Interpersonal Skills

  • Strong influencing skills to gain buy‑in from stakeholders at all levels.
  • Ability to navigate complex organisational dynamics and drive consensus.

Communication Skills

  • Exceptional verbal and written communication skills, with the ability to present complex ideas clearly and persuasively.
  • Experience presenting to boards, executive committees and large audiences.
  • Skilled in building and maintaining relationships with clients, partners and internal stakeholders.

Personal Attributes

  • Passionate about innovation and driving change to enhance business outcomes.
  • Open‑minded and adaptable to new ideas and technologies.
  • Strong focus on achieving goals and delivering measurable results.
  • Ability to prioritise and manage multiple initiatives effectively.
  • Commitment to the highest ethical standards and professional integrity.

Technology Risk Manager in City of Westminster employer: Mishcon de Reya

As a Technology Risk Manager at our firm, you will thrive in a dynamic and innovative environment that prioritises safety and compliance while fostering growth. Our collaborative work culture encourages professional development and offers unique opportunities to engage with cutting-edge technologies like AI and data management, all within a highly regulated framework. Join us to be part of a team that values your expertise and supports your career progression in a role that is both meaningful and impactful.

Mishcon de Reya

Contact Details:

Mishcon de Reya Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Technology Risk Manager in City of Westminster

Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Prepare for interviews by researching the company and its culture. Understand their approach to technology risk management and think about how your skills align with their needs. This will help you stand out as a candidate who truly gets what they’re about.

Tip Number 3

Practice your pitch! Be ready to explain how your experience in technology risk management can help them navigate challenges. Use specific examples that highlight your problem-solving skills and ability to work with cross-functional teams.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our team and contributing to our mission.

We think you need these skills to ace Technology Risk Manager in City of Westminster

Technology Risk Management
Data Risk Management
AI Risk Management
Operational Resilience
Regulatory Compliance
Risk Assessment Techniques
Control Frameworks (ISO 27001, NIST, COBIT, ITIL)

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in technology risk management. Use keywords from the job description to show that you understand what we're looking for.

Showcase Your Skills:Don’t just list your skills; provide examples of how you've applied them in real-world situations. This is your chance to demonstrate your understanding of risk assessment techniques and your ability to manage technology risks effectively.

Be Clear and Concise:When writing your application, keep it straightforward and to the point. We appreciate clarity, so avoid jargon and make sure your ideas come across clearly. Remember, less is often more!

Apply Through Our Website:We encourage you to submit your application through our website. It’s the best way to ensure your application gets into the right hands and shows that you're serious about joining our team at StudySmarter.

How to prepare for a job interview at Mishcon de Reya

Know Your Risk Management Frameworks

Familiarise yourself with key risk management frameworks like ISO 27001 and NIST. Be ready to discuss how these frameworks apply to technology risk, especially in relation to data, AI, and operational resilience.

Showcase Your Communication Skills

Prepare to demonstrate your exceptional verbal and written communication skills. Think of examples where you've presented complex ideas clearly, especially to stakeholders at various levels, as this role requires strong influencing abilities.

Understand the Regulatory Landscape

Brush up on UK regulations relevant to technology risk management. Be prepared to discuss how you would ensure compliance while enabling innovation, as this is a crucial aspect of the role.

Demonstrate Your Collaborative Spirit

Highlight your experience working closely with cross-functional teams, such as Technology, Cyber Security, and Compliance. Share specific examples of how you've partnered with others to manage risks effectively and promote a strong risk culture.