Technology Risk & Resilience Manager (Second Line)
Technology Risk & Resilience Manager (Second Line)

Technology Risk & Resilience Manager (Second Line)

Full-Time 48000 - 84000 £ / year (est.) Home office (partial)
M

At a Glance

  • Tasks: Oversee technology risk and resilience, ensuring effective integration into risk management frameworks.
  • Company: Join MUFG Investor Services, a leader in asset servicing with a global presence.
  • Benefits: Enjoy competitive salary, hybrid working, and opportunities for professional growth.
  • Why this job: Make a real impact in technology risk management at a top financial institution.
  • Qualifications: 10+ years in risk oversight, strong knowledge of technology and information security risks.
  • Other info: Be part of a vibrant culture that values innovation and collaboration.

The predicted salary is between 48000 - 84000 £ per year.

MUFG Investor Services is a trusted partner to many of the world’s largest public and private funds, providing asset servicing and operational solutions built for alternatives. With over $1 trillion in client assets under administration, we offer fund administration, banking, payments, fund financing, foreign exchange overlay, corporate and regulatory services, custody, business consulting, and more. Operating from 17 locations worldwide, we help clients mitigate risk, enhance efficiency, and navigate the operational complexities of today’s investment management landscape.

We’re looking for an experienced Technology Risk & Resilience Manager to join our second line risk in London, United Kingdom or Dublin, Ireland. In this pivotal role, you will:

  • Provide independent second line oversight and credible challenge of Technology Risk (Information Technology and Information Security) within the firm, ensuring effective integration of technology risk into the overarching second line Risk Management Framework, including alignment with DORA, third-party risk, and service resilience expectations.
  • Define and embed Technology Risk (IT & Information Security) appropriately within the Operational Risk Taxonomy and Framework, ensuring clear, documented delineation of 1LOD vs 2LOD accountability in line with company’s governance models.
  • Provide independent 2LOD oversight of the Technology Risk Management Framework, assessing its alignment and interdependency with first-line control frameworks (e.g. Third-Party Risk Management, IT Controls, Cybersecurity, etc.) and ensuring coherence with second line Operational Risk and Resilience frameworks.
  • Support the maturation of a consistent service-based view of technology risk by challenging 1LOD mapping of applications, infrastructure and third-party ICT services to internal and client-facing business services.
  • Review and challenge first line identification and assessment of technology risks, including application risk, infrastructure dependencies, information security risks and third-party technology dependencies, ensuring consistency with the company’s risk taxonomy and regulatory expectations.
  • Assess the quality, completeness, and consistency of Technology Risk Registers, control inventories, incident remediation activities and impact analysis.
  • Provide credible 2LOD challenge where risk assessments, severity ratings, or residual risk conclusions are not sufficiently supported.
  • Support integration of technology risk into the firm’s Operational Risk & Resilience frameworks, including regulatory/jurisdictional aligned frameworks.
  • Provide second line review and challenge of technology related incidents, including severity, client impact, and regulatory reporting considerations.
  • Contribute and support with resilience testing and scenario analysis from a technology dependency perspective.
  • Provide 2LOD oversight of technology-related third-party risks, ensuring appropriate risk identification where services rely on externally procured applications or infrastructure.
  • Review dependency and concentration risk associated with critical technology vendors.
  • Conduct thematic reviews of incidents, audit findings, or control weaknesses, and assess whether these indicate systemic risk or control gaps.
  • Draft and peer review committee papers and support where required the delivery of periodic reporting to management and governance forums.
  • Deliver on annual requirement to report and present the second line technology framework as well as contribute risk reporting on technology risk themes for senior management and risk committees.
  • Translate technical risk information into clear, business-relevant risk insights for non-technical stakeholders.
  • Support the Head of Risk in setting, monitoring, and challenging technology-related risk appetite.
  • Partner with senior first line leaders and control functions to embed risk and resilience principles in business planning and oversee and support the development of technology risk reporting.

Candidate should be comfortable facing challenges from CISO/CIO/CTO levels in addition to demonstrated ability to manage relationships within a parent company structure involving cross-collaboration within Risk, such as Enterprise, Data, Operational Risk & Resilience.

Education Requirements:

  • Post-secondary degree in technology, business or a related discipline plus qualification in CRISC, CISSP, CISM.
  • Fluency with frameworks such as NIST CSF, ISO 27001 / 27002, COBIT to facilitate an oversight role.
  • Professional qualification in risk or a related discipline would be preferred but not essential.

Work Experience:

  • 10+ years’ experience operating in a second line or independent risk oversight role overseeing Technology Risk, IT Risk, Cyber Risk in a financial institution or compatible industry.
  • Experience within governance, oversight programs of IT Architecture, Application and EUC development and deployment.
  • Strong knowledge of technology risk concepts, information security risk, third-party technology risk, operational resilience principles, corporate insurance.
  • Familiarity with information management frameworks through the lens of technology risk (inclusive of cyber and information security).
  • Experience engaging credibly with senior technology and business stakeholders.
  • Strong written and verbal communication skills, particularly in translating technical issues into business risk.

Functional/Technical Skills and Knowledge Requirements:

  • Experience with DORA, operational resilience, or similar regulatory regimes.
  • Experience working in fund services, asset servicing, or regulated financial services.
  • Exposure to multi-entity or cross-jurisdictional regulatory environments.
  • Proactive, solution-oriented mindset with the ability to work effectively in a fast-paced environment.
  • Advanced proficiency in Microsoft Excel and experience of onboarding new systems / technology are preferred.
  • Strong IT skills with strengths in Microsoft Office products.

Preferred:

  • Proficiency in Power BI, Tableau, and Power Apps for data visualisation and dashboard creation.
  • Experience with Excel, SharePoint, and Microsoft 365 tools for workflow automation.

We thank all candidates for applying; however, only those proceeding to the interview stage will be contacted.

Technology Risk & Resilience Manager (Second Line) employer: MUFG Investor Services

MUFG Investor Services is an exceptional employer, offering a dynamic work environment in London or Dublin where innovation and collaboration thrive. With a strong commitment to employee growth through continuous learning and development opportunities, we foster a culture that values diversity and encourages a hybrid working model, ensuring a healthy work-life balance. Join us to be part of a leading financial institution that not only prioritises client success but also invests in the well-being and professional advancement of its employees.
M

Contact Detail:

MUFG Investor Services Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Technology Risk & Resilience Manager (Second Line)

✨Tip Number 1

Network like a pro! Reach out to people in the industry, attend events, and connect on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

✨Tip Number 2

Prepare for interviews by researching the company and its culture. Understand their values and how they align with your own. This will help you stand out and show that you're genuinely interested in being part of their team.

✨Tip Number 3

Practice your responses to common interview questions, but keep it natural. Use the STAR method (Situation, Task, Action, Result) to structure your answers and highlight your achievements effectively.

✨Tip Number 4

Don’t forget to follow up after your interview! A simple thank-you email can leave a lasting impression and shows your enthusiasm for the role. Plus, it keeps you on their radar as they make their decision.

We think you need these skills to ace Technology Risk & Resilience Manager (Second Line)

Technology Risk Management
Information Security
Operational Risk Frameworks
Regulatory Compliance (DORA)
Third-Party Risk Management
Incident Management
Risk Assessment
Stakeholder Engagement
Governance and Reporting
Data Analysis
Communication Skills
Microsoft Excel
Power BI
Tableau
Problem-Solving Skills

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the Technology Risk & Resilience Manager role. Highlight relevant experience and skills that align with the job description, especially in technology risk and operational resilience.

Craft a Compelling Cover Letter: Your cover letter should tell us why you're the perfect fit for this role. Use specific examples from your past experiences to demonstrate how you meet the requirements and how you can contribute to our team.

Showcase Your Communication Skills: Since you'll be translating technical issues into business risks, it's crucial to showcase your written communication skills. Make sure your application materials are clear, concise, and free of jargon.

Apply Through Our Website: We encourage you to apply through our careers site. It’s the best way for us to receive your application and ensures you’re considered for this exciting opportunity at StudySmarter!

How to prepare for a job interview at MUFG Investor Services

✨Know Your Tech Risk Frameworks

Familiarise yourself with key frameworks like NIST CSF and ISO 27001. Be ready to discuss how these frameworks apply to technology risk management and operational resilience, as this will show your depth of knowledge in the field.

✨Prepare for Scenario-Based Questions

Expect questions that ask you to assess technology risks or respond to hypothetical incidents. Practise articulating your thought process clearly, demonstrating how you would challenge first-line assessments and ensure compliance with regulatory expectations.

✨Showcase Your Stakeholder Engagement Skills

Be prepared to discuss your experience in collaborating with senior leaders and cross-functional teams. Highlight specific examples where you've successfully navigated complex relationships and communicated technical risks to non-technical stakeholders.

✨Demonstrate a Proactive Mindset

Share examples of how you've identified potential risks before they became issues. This could include your approach to thematic reviews or oversight of technology-related changes, showcasing your ability to think ahead and contribute to a resilient operational environment.

Technology Risk & Resilience Manager (Second Line)
MUFG Investor Services

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>