Information Risk Manager

Information Risk Manager

Full-Time 60000 - 75000 £ / year (est.) Home office (partial)
Skipton Building Society

At a Glance

  • Tasks: Lead risk management across cyber, technology, data, and operational resilience.
  • Company: Join the fourth largest building society in the UK, owned by its members.
  • Benefits: Enjoy flexible working, generous leave, bonuses, and health benefits.
  • Other info: Collaborative workspace with excellent career development opportunities.
  • Why this job: Make a real impact on security and innovation in a supportive environment.
  • Qualifications: Certification in risk or information security and strong technical experience required.

The predicted salary is between 60000 - 75000 £ per year.

Hours: Permanent, full time role (35 hours per week) with hybrid and flexible working. You'll spend 3 days per week collaborating with colleagues at our Head Office in Skipton.

In a world of rapid technological change and evolving external threats, the Information Risk Lead plays a key role in keeping the Society secure, resilient and future ready. You will lead second line oversight of risk management activity across cyber, technology (including AI), data, change and operational resilience, ensuring robust protection while enabling innovation and progress. Through trusted assurance and insightful challenge, you will help safeguard the Society’s ability to operate safely, confidently and in line with regulatory expectations.

Skipton values work/life balance and we are proud to support hybrid and flexible working. For this opportunity, you'll spend 3 days per week collaborating with colleagues at our Head Office in Skipton.

Who Are We? Not just another building society. Not just another job. We're the fourth biggest building society in the UK and what makes us a bit different is that we're a mutual organisation. We don't have shareholders; we're owned by our members. Our colleagues say Skipton's a great place to work, and you could be one of them, bringing with you new ideas on how we can keep customers at the heart of what we do. Whatever your background, and whatever your goals, we'll help you take the next step towards a better future.

What Will You Be Doing? As a subject matter expert across information security, technology (including AI), data, change and operational resilience, you will provide independent second line oversight, challenge and assurance to ensure risks are effectively identified, assessed and managed. Key responsibilities include:

  • Provide strong independent second line oversight and challenge of first line activities, including risk assessments, control testing and mitigation actions, ensuring effective framework implementation and escalation of key risks.
  • Provide oversight, guidance and support to ensure risks are managed in line with the Group Risk Management Framework, Group Risk Policy Framework and Board Risk Appetite.
  • Lead oversight and provide assurance across cyber and technology risk, AI and emerging technologies, data risk, operational resilience and strategic change, aligned to evolving industry practice and regulatory expectations.
  • Deliver high quality, timely risk reporting and insight to senior committees, including thematic reviews and emerging risk identification.
  • Support senior leadership in delivering annual Enterprise Risk objectives, while leading priority information risk initiatives.
  • Oversee risk events, incidents and issues, including independent review of root cause analysis, timely escalation, and challenge of remediation effectiveness.
  • Provide technical leadership and coaching to colleagues, supporting capability development and consistent application of the Group Risk Management Framework.

What Do We Need From You? To be successful in this role, you’ll have:

  • A recognised certification (e.g. CISA, CISM, CISSP, CRISC) or an equivalent qualification in risk, IT or information security.
  • Strong technical experience in IT, information security, technology risk and resilience, including frameworks such as NIST and ISO 27001.
  • Proven second line experience in risk oversight, assessment, control evaluation and embedding enterprise risk frameworks and risk appetite.
  • Demonstrated leadership and delivery capability coordinating multiple workstreams and delivering initiatives.
  • Strong analytical and strategic thinking skills, with the ability to interpret complex issues, identify emerging risks and translate these into actionable insights.

What’s In It For You? We have a newly refurbished head office which offers a vibrant and collaborative working space. We have a range of other benefits available to you including:

  • Annual discretionary bonus scheme
  • 25 days standard annual leave + bank holidays + rising 1 day per year of service to a maximum of 30 days
  • Holiday trading scheme allowing the ability to buy and sell additional annual leave days
  • Matching employer pension contribution (up to 10% per annum)
  • Colleague mortgage (conditions apply)
  • Salary sacrifice scheme for hybrid & electric car
  • A commitment to training and development
  • Private medical insurance for all our colleagues
  • 3 paid volunteering days per annum
  • Diverse and inclusive colleague networks available for you to join including our Carers and Pride Alliance groups
  • We care about your health and wellbeing – we provide a range of benefits that support this including cycle to work initiative and discounted gym membership

Information Risk Manager employer: Skipton Building Society

Skipton Building Society is an exceptional employer that prioritises work/life balance and offers a vibrant, collaborative environment at our newly refurbished Head Office in Skipton. With a strong commitment to employee growth through training and development opportunities, alongside a comprehensive benefits package including flexible working, generous annual leave, and private medical insurance, we empower our colleagues to thrive both personally and professionally. Join us in making a meaningful impact while being part of a mutual organisation that values its members and fosters innovation.

Skipton Building Society

Contact Details:

Skipton Building Society Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Risk Manager

Tip Number 1

Network like a pro! Reach out to current employees at Skipton via LinkedIn or other platforms. Ask them about their experiences and any tips they might have for landing the Information Risk Manager role. Personal connections can give you an edge!

Tip Number 2

Prepare for the interview by brushing up on your knowledge of risk management frameworks like NIST and ISO 27001. Be ready to discuss how you've applied these in past roles. We want to see your expertise shine through!

Tip Number 3

Showcase your leadership skills! Think of examples where you've led initiatives or teams, especially in risk oversight. We love candidates who can demonstrate their ability to guide others while managing complex issues.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, it shows you’re genuinely interested in being part of the Skipton team. Let’s get you that job!

We think you need these skills to ace Information Risk Manager

Information Security
Risk Management
Cyber Risk Oversight
Technology Risk
AI and Emerging Technologies
Data Risk Management
Operational Resilience

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter for the Information Risk Manager role. Highlight your relevant experience in risk management, especially in IT and information security, to show us you’re the perfect fit!

Showcase Your Certifications:Don’t forget to mention any recognised certifications like CISA, CISM, or CISSP. These are key for us, so make them stand out in your application to demonstrate your expertise in the field.

Be Clear and Concise:When writing your application, keep it clear and to the point. Use bullet points where possible to make it easy for us to see your skills and achievements at a glance. We love a well-structured application!

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you don’t miss out on any important updates about the process!

How to prepare for a job interview at Skipton Building Society

Know Your Stuff

Make sure you brush up on your knowledge of information security, technology risk, and resilience frameworks like NIST and ISO 27001. Be ready to discuss how your experience aligns with the responsibilities of the role, especially around risk assessments and control testing.

Showcase Your Leadership Skills

Prepare examples that demonstrate your leadership capabilities, particularly in coordinating multiple workstreams and delivering initiatives. Think about times when you've provided oversight or guidance in risk management and be ready to share those stories.

Understand the Company Culture

Familiarise yourself with Skipton's values and their commitment to work/life balance and member ownership. This will help you articulate why you're a good fit for their culture and how you can contribute to keeping customers at the heart of what they do.

Ask Insightful Questions

Prepare thoughtful questions that show your interest in the role and the company. Inquire about their approach to emerging risks, how they support professional development, or specifics about their hybrid working model. This not only shows your enthusiasm but also helps you gauge if it's the right fit for you.