Overview
In this role you support the GRC team delivering technology and cyber regulatory engagements for WTW. You will coordinate with cross-functional teams across regulators, control owners, and senior management to map standards to regulatory requirements and drive remediation. Youβll prepare high-quality responses, assist with risk and control testing, and support reporting on engagement status. The role combines regulatory delivery with process improvement and stakeholder communication in a global context.
Pay / Benefits
- 25 days of annual leave
- private healthcare
- life insurance
- group income protection
- hybrid working
- pension scheme with up to 10% matched contributions
Responsibilities
- Execute regulatory deliverables, RFIs, audits and regulatory questionnaire submissions focused on GRC, ICS and Technology Risk within deadlines
- Define engagement planning, scoping and issues communication with regulators, control owners and senior management
- Map ICS and Technology standards to regulatory requirements with ICS Policies and Standards teams
- Coordinate timely, consistent responses to information requests and leverage evidence
- Engage with GRC controls testing team for application controls testing where needed
- Support and monitor remediation of issues and gaps in line with WTW controls and regulatory requirements
- Collaborate with GRC Risk Team to report and manage identified risks using established processes
- Support management reporting on engagement status and issue management
- Contribute to delivery of presentations, briefings and stakeholder documentation
- Generate reports and documentation for both technical and non-technical audiences
- Understand wider GRC, IT and ICS functions to support delivery
- Cross-Functional Collaboration: work with Audit, Compliance and Privacy to track and consolidate regulatory compliance
- Regulatory Engagements Programs: help develop operating model, templates and tools for GRC regulatory engagements and reporting
- Support implementation and monitoring of controls following Information Security standards and frameworks
Key requirements
- Extensive experience in GRC, Information Security or IT with ability to lead security, risk and compliance initiatives
- Experience identifying and managing risks and compensating controls
- Experience applying regulatory requirements to security practices
- Experience helping the business implement controls to maintain compliance in a global organization
- Strong Project Management skills
- Excellent writing, presentation and communication skills
- Ability to work autonomously and deliver on tight schedules
- Familiarity with other technology, cybersecurity and privacy regulations (beneficial)
- Excellent analytical problem-solving skills
- General IT operations knowledge
- Holistic understanding of risk processes and functions
- Good communication and interpersonal skills
- Customer focus and relationship management
- Capability to review and challenge materials produced by colleagues
- Resilience, determination and delivery focus
- Ability to manage multiple changing priorities
- Willingness to continue learning
- Ideally degree-level qualification in IT or GRC subject
- Information security certifications preferable (e.g., CISSP, CCSP, CISA, CRISC, CISM, ISO 27001 LA) and PMP preferable
- Degree-related details not strictly required but preferred
- Strong communication
- Collaborative and team-oriented
- Analytical problem-solving
- GRC / IT risk management
- Information security controls and regulatory mapping
- Regulatory engagements and reporting
Senior Associate /Manager β Technology Risk and Assurance in London employer: Willis Towers Watson
Willis Towers Watson is an exceptional employer, offering a dynamic work culture that fosters collaboration and innovation within the insurance sector. Employees benefit from comprehensive growth opportunities, competitive compensation, and a supportive environment that values professional development, all while being part of a leading global firm located in the heart of the UK. Join us to make a meaningful impact in the industry and build lasting relationships with key partners.