
Enable job alerts via email!
A leading pensions insurance specialist is seeking an Information Security Risk Manager to enhance security practices across the firm and its vendors. This role includes managing external assurance, driving thematic security reviews, and contributing to the strategic direction of technology partnerships. The ideal candidate will have a robust understanding of information security and experience in a financial services context.
Rothesay is the UK's largest pensions insurance specialist, purpose-built to protect pension schemes and their members' pensions. With over £70 billion of assets under management, we secure the pensions of more than one million people and pay out, on average, approximately £300 million in pension payments each month. Rothesay is dedicated to providing excellence in customer service alongside prudent underwriting, a conservative investment strategy and the careful management of risk.
We are trusted by the pension schemes of some of the UK's best known companies to provide pension solutions, including British Airways, Cadbury, the Civil Aviation Authority, the Co-Operative, Morrisons, Smiths Industries and Talent.
At Rothesay, we are striving to transform our industry. We believe deeply in creating real security for the future and our leadership in finding new and better ways to do that is the key to our success. To do that, we need the very brightest original thinkers to bring creativity as well as rigour. Rothesay is a rewarding place to work, where quality people can thrive and prosper.
Rothesay is investing heavily in a modern, secure, cloud-native technology stack, backed by executive sponsorship and a multi-year strategic transformation. As part of this journey, we're expanding our Information Security team to embed security and good risk management into every component of the stack.
This is an opportunity to join a high-impact Information and Technology Risk Management team helping drive strong security practices in our business and with our strategic partners. If you are passionate about securing integrated systems spanning a multiple firms and providers, building relationships across security teams to achieve mutually secure environments, and designing complex recovery plans including multiple organisations, we want to hear from you.
You'll be a member of the Information and Technology Risk Management team, working with a team of experts to drive assurance and risk management activities across the firm.
Your primary focus will be managing our external assurance practice. Your responsibilities will include:
The role is essential for ensuring implementation of the firmwide strategy within the Information Security team.
Other activities include project management, accurately and convincingly representing technical risk and security priorities, measuring key indicators, improving awareness of good security practices, and reporting.
Required:
Desirable:
We're not just looking for someone to implement controls - we're looking for someone who wants to influence how we build securely, empower vendor owners to have productive conversations about security, and help shift security left in a meaningful, pragmatic way.