
Technology Risk Manager
- London
- Contract
- Full-time
- Process Documentation: Create and update process documentation across key technology processes to support governance, compliance, and operational consistency.
- SSSDLC Integration: Support the integration of security controls and risk assessments throughout the Secure Software/System Development Lifecycle.
- Controls Assurance: Review and challenge the design and operation of controls to ensure they mitigate risks effectively.
- Risk Register Monitoring: Maintain and update a register of Technology-related risk events, incidents, audit findings, exceptions, etc. Work with responsible areas to assess these, develop action plans, identify owners and track through to completion.
- Technology Knowledge: Work towards a detailed understanding of Technology and cyber risk frameworks (e.g. NIST / ISO27001 / COBIT / ITIL).
- SSSDLC Expertise: Understanding of the Secure Software/System Development Lifecycle, including secure design, development, testing, and deployment practices.
- Process Documentation: Experience in drafting, updating, and maintaining process documentation across key technology domains.
- Attention to Detail: Meticulous attention to detail is crucial for accurately managing open audit points, helping to document audit actions, and accurately track and report on the status of management actions.
- Organisational Skills: Strong organisational skills are necessary to effectively coordinate audit schedules, manage documentation, and prioritise tasks across the IT Department.
- Time Management: Excellent time management skills are essential for managing multiple audit engagements, meeting deadlines, and ensuring the smooth progression of audit activities.
- Communication Skills: Clear and concise communication skills are vital for effectively liaising with internal and external stakeholders, conveying audit-related information, and facilitating collaboration across the IT Department.
- Analytical Skills: Basic analytical skills are beneficial for analysing audit data, identifying trends, and generating insights to support audit reporting and decision-making processes within the Technology domain.