
IT Risk & Control Assurance Manager
- Staines, Surrey
- £60,300 per year
- Permanent
- Full-time
- Interpreting and communicating to the Business Unit changes to Risk Polices, Business/IT Strategy, legislation that impact the existing Risk and Control Framework.
- Identifying and assessing Technology Management and Information Security issues so that control environments are properly defined and residual risk regularly assessed.
- Developing and managing the execution of the controls assurance plan.
- Overseeing the team conducting the control testing for the relevant business unit (i.e., the IT Risk & Control testing specialists and testing analysts)
- Supporting Business Unit (BU) and IT management in the design of key controls to mitigate identified issues and reduce residual risk.
- Regular reporting of BU IT Risks and Risk Appetite position to local risk committees, Market Unit (MU) Technology Risk Committee as well contributing to relevant committee and Board papers as required.
- Work with the Risk, Control and Processes owners to develop a trusted and robust set of process, risk and control metrics to allow risks, controls and issues to be continuously monitored.
- Experience of managing Information Security and Technology Risk and Controls in a regulated financial services company is essential.
- Understanding of the risks and controls inherent in all technologies including Cloud Services and Deployment Models
- The ideal candidate would have formal training and hands-on experience of designing, operating or auditing IT Controls.
- Experience of design and implementation of control automation and continuous monitoring would be useful but not essential.
- Demonstrable experience in Information Technology audits or IT Assurance (e.g., CISSP, CISM, CISA, CRISC, CCAK)
- A sound understanding of British and International Security Standards (e.g., ISO/IEC 27001, ISO/IEC 27002, NIST, CIS-20, PCIDSS) and the UK regulatory environment (e.g., ICO, FCA, PRA and CQC).
- 25 days holiday, increasing through length of service, with option to buy or sell
- Bupa health insurance as a benefit in kind
- An enhanced pension plan and life insurance
- Onsite gyms or local discounts where no onsite gym available
- Various other benefits and online discounts