Information Technology Risk Manager

Company: Actus Search
Apply for the Information Technology Risk Manager
Location: London
Job Description:

Job Summary:

Provide a high-level overview of the role and its scope.

  • Drive technology, data, and product innovation from a risk perspective.
  • Play a key role in identifying, assessing, and governing technology, data, and product risk.
  • Operate within the 2nd Line Group Risk function, guiding first-line stakeholders on their approach to risk across IT infrastructure, AI, cloud, emerging technologies, and product lifecycle.
  • Advise stakeholders at all levels on control effectiveness, providing independent challenge, oversight, and clear risk insight in decision-making related to digitalisation, data, and products.
  • Highlight both risks and opportunities in how the business can take informed risks in these areas.
  • Act as a trusted business partner, building strong relationships across the organisation as a go-to expert for technology, data, and product risk.
  • Collaborate closely with associated business areas and 2nd and 3rd line functions to ensure effective engagement and alignment.
  • Key Responsibilities:

    • Challenge, support, and work with 1st Line teams on risk identification, assessment, and control adequacy across digital and technology processes, as well as data and products.
    • Act as a key point of contact for the business, effectively engaging with the 1st Line as a Risk Business Partner.
    • Work with the 1st Line to collate and coordinate updates on risk profiles, ensuring aligned reporting for technology, data, and product risk within Group Risk Reporting.
    • Support, challenge, and guide the 1st Line through the RCSA process across technology, data, and product risk.
    • Act as Group Risk representative on business projects and initiatives, providing challenge and advice as a Risk Business Partner.
    • Attend relevant working groups and committees as required.
    • Partner with the 1st Line on operational risk event processes, providing guidance, training, and awareness, and ensuring robust remediation actions to strengthen the control environment.
    • Support enhancements to the Technology, Data, and Product Risk Control Framework by identifying and embedding key controls across the lifecycle.
    • Monitor the implementation of risk controls across business units and functions, gathering feedback to support continuous improvement.
    • Coordinate and prepare reports and presentations for governance forums as part of Group Risk Reporting.
    • Stay up to date with regulatory developments and wider industry changes, engaging with Group Risk and the wider business to assess impact and implications.

    Posted: April 5th, 2026