Technology Risk Officer – Border to Coast
Highly attractive salary and benefits (shared openly at first conversation)
Working Type
Hybrid
Work Hours
37.5
Responsibilities
Evidence adherence to information security, operational resilience and outsourcing requirements, including FCA and ISO27001 expectations
Qualifications
Ind Standard
Skills
A strong understanding of technology and infrastructure risk: information security, cloud, third party and resilience
Contact number
01132990570
Vitality HI - Emp Assistance Prog - Hols =30 days a year + BH - Prof development inc funded quals
Additional Benefits
CI cover - Excellent Pension scheme - Life assurance of six-times salary - Hybrid working
Region
West Yorkshire
Technology Risk Officer
Border to Coast Pensions Partnership is one of the UK's largest pension pools and the largest asset manager outside London and Edinburgh. Owned by 18 Local Government Pension Scheme partner funds, we manage approximately £120 billion of assets on behalf of more than two million members.
As a customer-owned and customer-focused organisation, our purpose is to make a difference for the Local Government Pension Scheme. Integrity, collaboration and sustainability are at the heart of how we work, and we are continuing to invest in our technology, data and innovation capabilities to support our long-term strategic ambitions.
Our client is an FCA regulated asset manager whose continued growth places an ever greater premium on trust. With an outsourced ICT model and a network of key service providers, the business requires a technology risk and control environment capable of ensuring that we are a sustainable organisation that can deliver for clients over the long term.
This first line appointment provides that assurance. You will oversee technology risk across the IT estate, supporting the identification and mitigation of risk in daily operations, and evidencing the organisation's adherence to information security, operational resilience and outsourcing requirements.
What you will be doing
- Provide first line technology risk oversight across IT infrastructure, supporting risk identification, mitigation and control effectiveness
- Act as the bridge to second line risk, compliance and assurance, ensuring technology risks are documented, challenged and reported
- Evidence adherence to information security, operational resilience and outsourcing requirements, including FCA and ISO27001 expectations
- Coordinate internal and external audits, from control design evidence to remediation tracking and management responses
- Assess and report on technology and infrastructure risk, including third party, cloud and service resilience, escalating where required
- Produce clear risk reporting, management information and assurance outputs for management, risk forums and audit committees
- Keep ICT risk and compliance oversight effective, internally and with outsourced partners
- Support senior technology leadership in meeting risk, cyber and assurance standards
- Oversee third and fourth parties so compliance and resilience controls remain robust
- Monitor the cyber and information security controls that protect data assets and satisfy regulatory requirements
- Watch the changing cyber threat landscape and challenge the operating model to keep data resilient
- Contribute to continued ISO2701 accreditation and the security standards set out in the ICT strategy
- Drive cyber due diligence across key service providers, advising contract managers so suppliers operate to agreed levels of security
- Support operational resilience activity wherever technology risk, information security, supplier oversight or ICT controls are involved
- Identify and escalation risk across your area of responsibility
What you will need
- A strong understanding of technology and infrastructure risk: information security, cloud, third party and resilience
- Working knowledge of regulatory and audit expectations, including FCA, ISO27001, outsourcing and operational resilience, and how to evidence compliance
- A clear grasp of the three lines of defence model, operating comfortably across first line delivery and second line oversight
- Demonstrable experience in technology risk, information security, ICT governance, audit or assurance within demanding, complex business environments
- A track record of assessing technology controls and tracking remediation through to closure
- Familiarity with internal and external audit, producing the evidence that supports assurance activity
- Practice producing risk reporting, management information or committee level documentation
- An analytical, methodical eye for control design and control gaps
- The confidence to manage stakeholders across IT, risk, compliance, audit and senior management
- Clear, concise writing across risk documentation, management information and audit responses
- Strong planning and organisation under conflicting priorities, with high levels of integrity
- A degree or equivalent experience, with continued development in ICT, technology risk, information security, audit, assurance or operational resilience
It would also help if you have
- Financial services knowledge
- Experience of electronic document record management systems
- Previous technology risk work within a financially regulated company
- Direct involvement with FCA operational resilience, outsourcing or information security requirements
- Hands on ISO27001 and cyber security
- Day to day contact with outsourced ICT providers or key service providers
- Certification in information security, technology risk, audit, cyber security, ISO27001, IT service management or operational resilience
- Broader corporate awareness spanning health and safety, ICT systems, information management, data protection, procurement and outsourcing oversight