IT Risk and Governance Analyst – Preston, Lancashire – 3 month contract
We are seeking an analytical mind, with an eye for detail, procedures, and technical acumen, to help the business implement and run a new IT risk management framework. This is a multi-faceted role supporting both a Technology Transformation Programme as well as maintaining oversight over current operational technology and applications.
- Assist the implementation of risk identification control strategies: Work with multiple teams to create learning material, templates, and facilitate workshops.
- Support horizon scanning exercises: Identify new and emerging risks, working with Legal and Compliance teams to monitor regulatory changes.
- Manage changes to risk taxonomy: Support updates to the reference library for technology risk identification and assessment.
2. Risk and Event Analysis
- Review, triage, and analyze internal and external technology issues and risk events, providing updates for a knowledge base.
- Assist with change reviews, Risk Control Self-Assessment exercises, control testing, and thematic deep dives.
- Support vendor risk assessments, controls assurance, and compliance attestations with the Third Party Risk & Assurance Specialist.
3. Risk Controls and Management
- Assist in developing the technology governance framework and controls reference library.
- Support the management of the IT controls library, including reviewing change requests and analyzing control performance.
- Support GRC platform operations, including writing runbooks and engaging feedback for service improvements.
4. Risk Governance and Compliance
- Manage the service interface for Technology Service Governance, including FAQs and metrics analysis.
- Keep records of governance decisions and track policy and strategy exceptions.
- Support audits, certifications, and resolution of audit findings.
5. Reporting & Documentation
- Prepare reports on technology risk and governance performance.
- Maintain documentation for procedures, project updates, and client interactions.
- Research and develop new technology risk visualizations.
- Collaborate with Technology Service teams to promote learning and awareness campaigns.
- Research new technology and risk modeling techniques to improve services.
- Support the development of team members within the Technology Services Governance team.
Qualifications, Skills, and Experience
- Experience in enterprise technology services, support, or administration, including ITIL and asset management.
- Understanding of enterprise IT environments, including cloud, cybersecurity, and corporate applications.
- Experience deploying and operating IT controls and procedures.
- Knowledge of IT Governance, Risk, and Compliance frameworks.
- Experience creating reports with PowerBI, Tableau, or similar tools.
- Ability to automate tasks using PowerAutomate, Python, or similar scripting languages.