Risk & Assurance Manager - IT & Infosec
Role details
Job location
Tech stack
Job description
As Softcat's business continues to grow and evolve, so have the risks and the regulatory landscape. In response, Softcat Plc has recognised the need to further strengthen its Risk Management and Internal Controls and has created a second line Risk and Assurance function to strengthen the overall three lines model and improve the way in which risks are identified, managed and communicated across the organisation including Board and Audit Committee. The function is led by the Head of Risk and Assurance who reports to the Chief Financial Officer of Softcat Plc.
Success. The Softcat Way.
Softcat is a £1billion+ technology solutions business and trusted partner to names like Apple, Microsoft and Adobe. Offering a growing portfolio of services including software licensing, cyber security and IT infrastructure, we give our technical teams the tools and support to make exciting things happen. This is where to achieve more for your career.
Lead the charge on IT Risk & Assurance
This role focuses on managing and enhancing the IT and Information Security risk landscape. Reporting directly to the Head of Risk and Assurance, you will play a key role in embedding effective risk management practices across Softcat's technology and cybersecurity domains.
As a Risk & Assurance Manager, you'll be responsible for:
- Partnering with senior IT, Security, and business leaders to embed risk management practices into operational processes and strategic initiatives.
- Owning and maintaining IT Risk and Control Matrices (RCMs), ensuring they remain current, comprehensive, and aligned with industry standards and audit expectations.
- Reviewing effectiveness of first line functions in testing and validation of key IT controls (e.g., access management, change control, incident response, vulnerability management), ensuring effectiveness and consistency.
- Leading in the review and enhancement of IT and infosec risk and control frameworks (e.g., ISO 27001, ITIL, ISO22301, NIST), ensuring alignment with business objectives and regulatory requirements.
- Coordinating and representing IT risk in internal, external audits and certification processes (e.g., ISO 27001, Cyber Essentials, ISO22301, etc.), acting as the primary point of contact.
Requirements
- Minimum 5 years of experience in second-line risk management or internal audit, with a strong focus on IT or Information Security.
- Experience in consultancy or professional services, with a proven ability to support complex transformation or change programmes is preferred.
- Demonstrated leadership in delivering IT risk or audit initiatives, including managing projects, mentoring team members, and driving outcomes.
- Strong knowledge of industry frameworks and standards, such as ISO 27001, NIST, CIS Controls, and regulatory requirements like GDPR.
- Proven ability to engage and influence stakeholders across IT, Information Security, and business functions, building trusted relationships at all levels.
We also acknowledge that the confidence gap and imposter syndrome are a real thing and can get in the way of us meeting fantastic talent, so please don't hesitate to apply - we would love to hear from you!
Benefits & conditions
We recognise that everyone is different and that the way in which people want to work and deliver at their best is different for everyone too. In this role, we can offer the following flexible working patterns:
- Hybrid working - 3 days in the office and 2 days working from home
- Working flexible hours - flexing the times you start and finish during the day
- Flexibility around school pick up and drop offs
Working with us
Wherever you work, we want you to experience the freedom and autonomy to realise your potential. You will feel supported by a team that celebrates individuality, encourages different perspectives, and embraces every background.