Job Description
As a world‑leading bank, we value innovative thinking and strive to be best‑in‑class. The Technology & Cyber Risk Management Lead in our Technology & Cyber CCOR organisation will materially contribute to the Technology Compliance programme. You will apply deep knowledge of European and Global technology and cybersecurity laws, rules and regulations to support the design, implementation and oversight of the 2nd Line of Defence risk management program for technology and cybersecurity risks.
Job Responsibilities
- Provide guidance to Technology on people, process, programs, projects and products related to regulatory requirements for resiliency, outsourcing, data loss prevention, Privacy, AI and cloud technology.
- Review regulations and impact assessments, advising relevant owners on policy and procedure development within the legal entity and across other group entities.
- Keep abreast of emerging technologies and related regulatory and legislative changes and advise on implementation to operate securely and compliantly.
- Support the review of significant events, including security events, over a defined economic threshold using risk‑management framework metrics and reporting.
- Apply data analytics to critical systems of records, identifying potential issues and risk areas efficiently.
- Guide adoption of technologies such as Cloud and AI/ML.
- Participate in assessment of emerging risks through strategic business risk reviews, regulatory and market developments, and new business initiative approvals.
- Collaborate with regional or line‑of‑business conduct, compliance and operational risk leads.
- Build strong relationships with Technology stakeholders as their trusted strategic advisor.
Required Qualifications, Capabilities, and Skills
- Strong expertise in architecture, design and operation of highly complex systems for global financial market businesses.
- Strong analytical skills and growth mindset, staying current on innovative and emerging technologies.
- Professional experience in risk management, compliance, or technology‑related fields.
- Technical experience in technology, cybersecurity, governance, operational risk or technology compliance within financial services or equivalent tech industry role.
- Knowledge of Information Security and Risk Management standards such as NIST, ISO 27001/27002 and modern development practices.
- Ability to understand complex technical systems, synthesize risks and controls, and recommend adjustments.
- Understanding of technology risk management and control principles with ability to anticipate and mitigate risks.
- Strong organizational, project management, data analysis and stakeholder management skills, with demonstrated ability to manage expectations and deliver results with professionalism.
- Experience using AI tools to support data analytics and deliverable preparation.
Preferred Qualifications, Capabilities, and Skills
- EMEA technology regulatory knowledge, including EU regulation such as DORA, EU AI Act, NIS, etc.
- Professional IT and information security certifications (CISSP, CISA, CISM, CRISC, CGEIT) and cloud certifications (CCSP, AWS Certified Practitioner).
- Knowledge of innovative automation technologies and toolsets such as Alteryx, UiPath, Qlik Sense, Tableau.
- Experience implementing innovative risk oversight using modern data‑driven analytical techniques.
We are an equal opportunity employer and place a high value on diversity and inclusion. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs.