Referment is working with a financial technology business providing investment platform services, model portfolios and financial planning software to financial advisers. Its services support advisers in managing clients' investments and financial plans, including retirement planning.
This permanent Risk Manager role sits in the second line of defence within the Risk and Compliance team, reporting directly to the Chief Risk and Compliance Officer. You'll embed the enterprise risk management framework and take long-term ownership of it, strengthening key risk indicators, operational resilience and third-party oversight.
The role combines practical framework maintenance with work across business units, Finance, senior leadership and governance committees. You'll need to move work forward at pace while retaining the rigour needed for risk assessments, incident investigations, resilience testing and Board reporting.
The Role
Risk Framework
- Maintain top-down and bottom-up risk assessments and risk registers, engaging stakeholders across the business.
- Support the maintenance of risk appetite statements and their approval by the Board.
- Review, enhance, calibrate and maintain key risk indicators across all business areas, ensuring thresholds align with risk appetite.
Third-Party and Operational Risk
- Implement third-party risk frameworks and oversight proportionate to the scale and complexity of the business.
- Support the quarterly risk assessment cycle across business units.
- Maintain and enhance incident investigation processes, ensuring timely escalation, root cause analysis, closure of actions and reporting.
Operational Resilience and Business Continuity
- Review and maintain the Business Continuity Plan and associated Disaster Recovery arrangements so they reflect the business's operating model, including its investment platform.
- Support the annual operational resilience self-assessment, including mapping important business services, setting impact tolerances and establishing testing arrangements.
- Coordinate scenario testing of business continuity and disaster recovery arrangements, document outcomes and track remediation actions.
- Assess the operational resilience implications of new business initiatives and platform migrations, providing second-line input to project governance.
Governance and Reporting
- Prepare risk-focused Board and committee papers, including standing reports for the Risk and Compliance Committee.
- Support the ICARA process, including scenario stress testing and wind-down planning, in coordination with Finance and the Chief Risk and Compliance Officer.
- Help embed governance, including supporting the development of Terms of Reference for risk-related committees.
- Take ongoing ownership of the risk management framework.
Stakeholder Engagement
- Collaborate with senior leadership and first-line business owners to embed risk processes in day-to-day operations.
- Maintain clear documentation covering all aspects of the risk framework.
What We're Looking For
- At least six years' experience in a risk management role within an FCA-regulated investment firm.
- Demonstrable experience designing and embedding enterprise risk management frameworks, including risk registers, key risk indicators, risk appetite statements, operational resilience and third-party risk.
- Strong working knowledge of SYSC, PRIN and prudential requirements, including ICARA and MIFIDPRU.
- Hands-on operational resilience experience covering important business services mapping, impact tolerance-setting, and business continuity and disaster recovery maintenance and testing.
- Familiarity with Consumer Duty, SM&CR and third-party risk management.
- Experience working across second-line functions with first-line business owners.
- Excellent written communication skills and the ability to prepare Board-level documentation.
- The ability to work independently and at pace in an evolving environment.
Desirable Experience
- Experience within a discretionary fund manager, model portfolio service provider or investment platform business.
- Familiarity with third-party oversight frameworks.
- Experience using governance, risk and compliance platforms or data tools to support risk reporting.
- Professional qualifications such as IRM or CISI are desirable, but not essential.
Benefits
- pension scheme
- annual leave plus bank holidays
- a non-contractual bonus scheme
- insurance plans
- funding for relevant professional qualifications and memberships
- wellbeing support
- Flexible hours are available depending on team requirements.
This could suit a second-line enterprise or operational risk professional from an investment business who combines framework design with hands-on resilience, third-party oversight and governance reporting.
#Referment