Technology and Data Risk Manager in London

Technology and Data Risk Manager in London

London Full-Time 63000 - 77000 £ / year (est.) Home office (partial)
Nest

At a Glance

  • Tasks: Oversee technology and data risks, ensuring compliance and security across the organisation.
  • Company: Join Nest, the UK's largest workplace pension scheme with a commitment to diversity and inclusion.
  • Benefits: Competitive salary, flexible working, and access to learning opportunities for career growth.
  • Other info: Be part of a supportive team that values your unique perspective and potential.
  • Why this job: Make a real impact on data protection and security in a dynamic environment.
  • Qualifications: Experience in technology risk management and knowledge of data protection regulations.

The predicted salary is between 63000 - 77000 £ per year.

The Technology & Data Risk Manager is a new second line of defence role within the Risk Directorate, responsible for providing independent oversight, assurance and expert challenge across technology, data, cyber security, and related operational risks. Reporting to the Head of Technical Risk and Data Protection Officer, the role supports the effective management of technology and data risks by ensuring first line teams identify, assess and mitigate risks in line with Nest’s risk appetite while enabling the organisation to deliver its strategic objectives securely and efficiently.

Working across the organisation, the role promotes strong risk management practices, providing expert challenge on technology, data protection, information security, and third-party risk matters. It plays a key role in strengthening governance, embedding a strong data protection and security culture, and supporting compliance with regulatory requirements and recognised standards, including UK GDPR, the Data Protection Act 2018 and ISO 27001. The Technology & Data Risk Manager also helps the organisation anticipate and respond to emerging risks and opportunities, including developments in artificial intelligence, evolving cyber threats, and third-party dependencies.

Through effective stakeholder engagement, assurance activity and risk reporting, the role contributes to maintaining a resilient, compliant, and well-controlled technology and data environment across Nest.

Minimum criteria for this role are:

  • Sound knowledge of information security and data risk domains (access control, vulnerability management, logging and monitoring, incident response, secure development etc).
  • Experience in technology, data, security, or technical risk management including control frameworks such as ISO 27001 and NIST, ideally within a regulated or complex organisation.
  • Strong understanding of second line assurance and oversight, including how to challenge constructively while remaining independent.
  • Experience of assessing third‑party technical risk.
  • Experience with product security and secure SDLC assurance.
  • Knowledge of AI risk, data ethics or emerging technology governance.
  • Working knowledge of UK GDPR and the Data Protection Act 2018.
  • Knowledge of threat intelligence, vulnerability disclosure, and security testing approaches.
  • Relevant professional certifications (e.g. CISM, CISSP, ISO 27001 LI/LA, CRISC, ITIL).

Don't worry if you think you don't have all the key skills, it might be worth taking the few minutes to apply as we're good at spotting potential. At Nest, you’ll have access to a range of learning opportunities to learn, grow and build the skills you need to be successful in your role and career.

Flexible and agile working

Everyone's personal situation is different. To make the most out of hybrid working, we've introduced different ways of working, which include (subject to role requirements): hybrid of office (Canary Wharf, London) and home working (there will be an expectation to attend the office, once - twice a week, or more, as required).

Directorate/Department Overview

The Technical Risk team sits within the Risk Directorate, along with Risk, Risk Assurance, Risk Operations and Regulatory Risk, and Controls Oversight. The directorate supports the business in delivering its strategic priorities by overseeing that risk and controls are identified, prioritised and managed through an enterprise risk management framework. Nest operates a ‘three lines of defence’ model, with Risk sitting in the second line providing advice, guidance and challenge to the first line. The Technical Risk team provides support to Nest specifically in relation to risks covering data, privacy, technology, cyber and financial crime. Support includes conducting investigations, regulatory reporting as well as training and awareness across Nest Corporation.

Organisational Overview

Nest is an award-winning workplace pension scheme, the largest in the country. Set up by the government to give every worker in the UK somewhere to save, our first-class responsible investment practice and governance are the backbone of what we do, supported by all the functions you’d expect to find in a thriving business. We’re committed to creating a workplace where you can be your authentic self and offer an inclusive and flexible working environment.

Diversity, Equity and Inclusion

Everyone is welcome to apply for our roles, and we are determined to ensure that no applicant or employee receives less favourable treatment because of their age, disability, gender identity, marital status, national origin, pregnancy or caring responsibilities, race, religion/belief, sex, sexual orientation or socio economic background. We also recognise the importance of diversity of thought and other forms of neurocognitive variation. Nest is a Disability Confident Leader, which is the highest level of the Disability Confident Scheme. If you have a disability, please declare that you’re applying through the scheme. We aim to offer an interview to those applicants who apply through the Disability Confident Scheme and best meet the minimum criteria. However, there may be some circumstances where this is not possible due to the volume of applications.

Please note that this advert may close early if we receive a sufficient number of satisfactory applications. If you have any difficulty in sending your application or need the application pack in an alternative format, or you require any reasonable adjustments please contact:

£70,000 to £75,000 (Depending on Experience)

Technology and Data Risk Manager in London employer: Nest

Nest is an exceptional employer, offering a dynamic work culture that prioritises employee growth and development. With flexible hybrid working arrangements at our Canary Wharf location, we empower our team to thrive while contributing to one of the UK's largest pension schemes, ensuring a meaningful impact on data governance and decision-making processes.

Nest

Contact Details:

Nest Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Technology and Data Risk Manager in London

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Nest, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Nest

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Nest. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Technology and Data Risk Manager in London

Communication Skills
Problem-Solving Skills
SQL
Automation
Data Governance
Python
Attention to Detail

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Nest insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Nest that you’re committed to staying ahead in the game.

How to prepare for a job interview at Nest

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Nest to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Nest.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.