> Markdown version of [/jobs/ext/2392090-group-senior-it-risk-manager](https://www.wearedevelopers.com/jobs/ext/2392090-group-senior-it-risk-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Group Senior IT Risk Manager - **Company:** Bupa - **Location:** London, UK - **Experience:** Expert - **Salary:** £90,000.0 - **Contract:** Permanent contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Encodings, Cyber Security, Data Centers, ISO/IEC 27002 - **Published:** August 4, 2026 - **Apply:** https://bupa.wd3.myworkdayjobs.com/EXT_CAREER/job/Angel-Court-London/Group-Senior-IT-Risk-Manager_R1226301 ## About the Role We're looking for an experienced and credible technology risk leader who combines strategic thinking with practical delivery. * Significant experience in IT Risk, Technology Risk, Cyber Risk, Operational Resilience or a similar discipline gained within a large, complex organisation. * Demonstratable experience designing, implementing and embedding risk frameworks, controls and governance processes at enterprise scale. * Strong understanding of recognised frameworks such as ISO 31000, ISO 27002, NIST, COBIT and ITIL. * The ability to translate complex technical risks into meaningful business insights and practical action plans. * Exceptional collaboration and stakeholder management skills, with the confidence and credibility to influence senior leaders and challenge constructively where required. * The ability to work independently whilst fostering strong cross-functional collaboration, proactively identifying risks, opportunities and solutions to deliver business objectives. * Professional certifications such as CISSP, CISM or CRISC are highly desirable ## Description We're looking for a Senior IT Risk Manager to help shape and strengthen our approach to technology risk, resilience, and governance across the Group. This is a highly visible leadership role within our Group Information Security Office, reporting to the Group Head of Cyber Governance, Risk & Compliance and working closely with the Group Director of Operational Resilience. The successful candidate will lead the development and evolution of our Group-wide IT risk management framework, ensuring robust governance, effective controls, and a consistent approach to risk management across multiple business units. You'll have the opportunity to influence senior stakeholders across the business, helping ensure our technology environment remains secure, resilient, and aligned to our strategic ambitions How you'll help us make health happen: * Lead the development, implementation, and maintenance of the Group-wide IT risk management framework, Policy and Standards, ensuring alignment with business objectives, the Enterprise Risk Management Framework and regulatory requirements. * Identify, assess, and monitor IT risks across all business units, collaborating with stakeholders to ensure risks are appropriately managed and mitigated. * Design and support the implementation of controls and processes to manage IT resilience risks, including regular reviews of their effectiveness, along with related key risk indicators. * Partner with Market Unit technology and Second Line teams to define and support their implementation of controls and processes to ensure the resilience of data centres critical to the delivery of our critical services. * Work closely with the Group Director of Operational Resilience to ensure consistency in risk management practices and reporting. * Facilitate risk assessments, including thematic and ad-hoc reviews, to identify emerging threats and vulnerabilities in the Group's IT environment. * Prepare and deliver clear, concise risk reports for senior management, regulatory, and board-level audiences. * Champion a culture of risk awareness, providing training and guidance to business units on IT risk management best practices. * Collaborate with cross-functional teams to assess the impact of new technologies, regulatory changes, and industry standards on the Group's IT risk profile ## Related Videos - [The Sustainability Race: AI's Promises, Pitfalls and Potential](https://www.wearedevelopers.com/videos/100155-the-sustainability-race-ai-s-promises-pitfalls-and-potential) - [A Brief History of Data Storage](https://www.wearedevelopers.com/videos/974-a-brief-history-of-data-storage) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Building the Nervous System of AI - Michael Kagan (NVIDIA)](https://www.wearedevelopers.com/videos/2133-building-the-nervous-system-of-ai-michael-kagan-nvidia) - [JSON and Beyond](https://www.wearedevelopers.com/videos/968-json-and-beyond) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) ## Related Articles - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette) - [Best Companies to Work For in The UK: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/186-best-companies-to-work-for-in-the-uk-top-25-companies-in-2023) - [Top HR Tech Conferences in 2024](https://www.wearedevelopers.com/magazine/303-top-hr-tech-conferences-in-2024) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)