At a Glance
- Tasks: Oversee cyber and technology risks while supporting digital transformation initiatives.
- Company: Join Nottingham Building Society, a member-owned mutual with a strong community focus.
- Benefits: Enjoy a competitive salary, 29 days holiday, and health & wellbeing resources.
- Other info: Embrace diversity in a supportive culture with opportunities for personal growth.
- Why this job: Make a real impact in cybersecurity while driving innovation and change.
- Qualifications: 5+ years in cyber/technology risk; strong communication and decision-making skills required.
The predicted salary is between 36000 - 60000 € per year.
Contract type: Permanent
Hours: Full-time, 35 hours
Location: Head Office, Nottingham (Hybrid working, minimum 2 days per week)
Application process: Please apply via the application button which will direct you to our careers site. If you require any adjustments to assist you in applying, please contact us.
As a Cyber and Technology Risk Manager, you will operate as part of our second line of defence, providing expert oversight across our digital and technology transformation journey. You will play a pivotal role in ensuring the organisation remains secure as we modernise, offering robust risk assurance across information security, technology initiatives, major transformation programmes and change portfolios.
You will build strong relationships across the business and act as a trusted, influential voice on cyber and technology risk at all levels. With a focus on embedding smart technology solutions, you will help drive our strategic agenda while continuously enhancing our risk management frameworks and processes to protect the organisation now and in the future.
Here’s a taste of what you will be doing:
- Independent Risk Oversight: Deliver objective assurance over cyber and technology risks, using strong technical knowledge to assess controls, challenge effectively, and guide stakeholders.
- Strategic Transformation Support: Align with the digital strategy and roadmap to provide proactive risk insight, building trusted relationships across Technology & Transformation.
- Change Risk Management: Ensure risks are properly identified and managed throughout change initiatives by reviewing assessments and monitoring supporting controls.
- Incident Monitoring & Assurance: Oversee robust processes for tracking cyber and technology incidents, ensuring clear visibility of themes, actions and residual risks.
- Insightful Reporting: Develop forward-looking MI and produce clear, high-quality reports for the CRO, Director of Risk, and risk committees.
- Second Line Challenge: Provide an independent perspective on incidents and risk matters at the Operational Risk Committee, ensuring strong governance and accountability.
- Continuous Improvement: Identify opportunities to strengthen frameworks, processes and controls to stay ahead of emerging cyber and technology threats.
- Stakeholder Influence: Act as a trusted partner across the business, offering credible challenge and expert guidance to drive effective risk management behaviours.
About you:
- Cyber Security Expertise: Strong, transferable experience in cyber security with a solid understanding of threat vectors, security controls and modern IT architectures.
- Risk Framework Knowledge: Practical experience using recognised information security and risk management methodologies such as NIST, COBIT and ISO27001.
- Broader Risk Awareness: Understanding of wider risk management systems and methodologies beyond cyber and technology.
- Insightful Reporting: Ability to design and produce clear, meaningful MI and committee-level risk reporting.
- Proven Industry Experience: 5+ years in cyber/technology risk, internal audit or change assurance within regulated financial services; 2nd line experience desirable.
- Strong Decision-Making: Able to use initiative, make sound judgements and respond confidently to complex issues.
- Collaborative Influencer: Skilled at building strong stakeholder relationships, offering credible challenge and communicating clearly at all levels.
- Qualified & Knowledgeable: Degree-level education preferred; CISSP or CISM qualifications advantageous but not essential.
Reward & Benefits:
- Competitive Package: Fair salary benchmarked against market data, annual discretionary bonus, and 29 days holiday plus bank holidays.
- Health & Wellbeing: Access to Medicash healthcare, mental health first aiders, and a suite of wellbeing resources to support you inside and outside of work.
- Work-Life Balance: 35-hour working week for full-time roles, with flexibility to help you perform at your best.
- Career Growth: Ongoing personal and professional development, we will support your ambitions and help you grow your potential.
- Inclusive Culture: Be part of a friendly, values-led team that genuinely cares about doing the right thing for colleagues and customers.
- Giving Back: Use two paid volunteering days each year to support causes close to your heart, through our Samuel Fox Foundation.
- Sustainability Focus: Join a business committed to reducing its carbon footprint and making a positive impact on the environment.
- Free access to Octopus Money: Financial coaching & tools that help you plan, manage, and make the most of your money.
Embracing Diversity Together:
We proudly embrace and celebrate diversity as a fundamental cornerstone of our values. We believe that a diverse and inclusive workplace is not just essential for our success but is also a reflection of the vibrant communities we serve. Our commitment to diversity extends beyond our internal culture to the way we approach advertising and engage with our customers.
Our commitment means actively working to eliminate barriers and biases that may hinder equal opportunities within our organisation. We strive to ensure that all individuals, regardless of background, have an equal chance to thrive and advance in their careers. We acknowledge that diversity is not just a goal to be achieved but a continuous journey toward creating an environment that embraces differences and promotes equal opportunities for all. We are committed to creating an inclusive culture that encourages collaboration, creativity, and a sense of belonging for every member of our community.
About Us:
We are a mutual, which means we don’t have shareholders. Instead, we’re owned by our members and use our money to do good, investing in our community, responsible causes, and – well, you. So, we’re always striving to do the right thing for our team, communities and members.
Although our history spans over 170 years, our purpose of helping our members save, plan for and protect their financial futures is enduring. At The Nottingham Building Society, we are dedicated to overcoming obstacles and turning challenges into opportunities. At the heart of our mission is our unwavering commitment to breaking down barriers and building better futures by helping our customers achieve the significant milestone of owning their own home.
Cyber and Technology Risk Manager in Nottingham employer: TheNottingham
Nottingham Building Society is an exceptional employer that prioritises inclusivity and employee well-being, offering a competitive salary, generous holiday allowance, and a supportive work-life balance through hybrid working arrangements. With a strong focus on personal and professional development, employees are encouraged to grow their careers while contributing to meaningful community initiatives, all within a friendly and values-driven culture that celebrates diversity and sustainability.
StudySmarter Expert Advice🤫
We think this is how you could land Cyber and Technology Risk Manager in Nottingham
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend events, and connect on LinkedIn. Building relationships can open doors that a CV just can't.
✨Tip Number 2
Prepare for interviews by researching the company and its culture. Understand their values and how you can contribute to their mission. This shows you're genuinely interested and not just ticking boxes.
✨Tip Number 3
Practice your responses to common interview questions, but keep it natural. Use the STAR method (Situation, Task, Action, Result) to structure your answers and highlight your achievements.
✨Tip Number 4
Don't forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, if you need any adjustments during the process, just reach out – we’re here to help!
We think you need these skills to ace Cyber and Technology Risk Manager in Nottingham
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Cyber and Technology Risk Manager role. Highlight your relevant experience in cyber security, risk management frameworks, and any specific methodologies like NIST or ISO27001 that you’ve worked with.
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about this role and how your skills align with our mission at Nottingham Building Society. Don’t forget to mention your collaborative approach and stakeholder influence!
Showcase Your Achievements:When detailing your experience, focus on your achievements rather than just responsibilities. Use metrics where possible to demonstrate how you’ve made a positive impact in previous roles, especially in risk oversight and incident management.
Apply Through Our Website:We encourage you to apply through our careers site for a smooth application process. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, we love seeing applications come directly from our website!
How to prepare for a job interview at TheNottingham
✨Know Your Cyber Security Stuff
Make sure you brush up on your knowledge of cyber security, especially around threat vectors and security controls. Be ready to discuss how your experience aligns with the methodologies like NIST, COBIT, and ISO27001, as these will likely come up during the interview.
✨Showcase Your Risk Management Skills
Prepare examples that demonstrate your ability to identify and manage risks effectively. Think about specific instances where you've provided oversight or assurance in previous roles, and be ready to explain how you approached those challenges.
✨Build Relationships Before the Interview
Since this role involves a lot of stakeholder engagement, try to connect with current employees or others in the industry beforehand. This can give you insights into the company culture and help you tailor your responses to show how you can fit in and contribute.
✨Prepare Insightful Questions
Have a list of thoughtful questions ready for your interviewers. Ask about their current technology transformation initiatives or how they measure success in risk management. This shows you're genuinely interested in the role and have done your homework.