Interim Head of Technology Risk
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
This is a rare opportunity to shape how technology, cyber and information security risk is understood and managed across a complex, multi-jurisdiction business. You’ll act as a trusted advisor to the Chief Risk & Compliance Officer and senior executives, providing credible challenge and forward-looking insight that directly informs Board-level decisions and strategic investment.
If you’re a technology risk leader who can operate confidently across the Three Lines of Defence, influence at the most senior level, and stay composed when it matters most, this one’s worth a look.
What you’ll do:
- Provide risk assurance and strategic advisory on technology, cloud, information assets and cyber security to the Group CRO, Board and relevant committees.
- Lead and evolve the Group’s Technology & Information Security GRC strategy, driving consistent adoption across every entity.
- Set enterprise-wide policy and standards that meet regulatory requirements for technology, information security and digital resilience across the UK, Europe and the USA.
- Own the second-line view on emerging technology roadmaps, ensuring alignment with Group strategy and competitive positioning.
- Act as senior leadership liaison for the Group’s Crisis Management Plan and cyber resilience strategy - including accountability for the cyber insurance mandate.
- Serve as the primary point of contact with UK and European regulators on technology risk, digital resilience and information security.
- Lead governance for technology and security change programmes, including oversight of cyber incidents, coordination of response, and support for recovery - with clear senior management reporting throughout.
Requirements
- Senior leadership experience across multiple organisations, with a genuine ability to build and develop high-performing teams.
- A track record leading risk, assurance or quality functions in complex technology environments - designing controls, monitoring and high-quality reporting frameworks that work in practice.
- Deep expertise in technology and information security risk: risk assessment, control design, governance frameworks and cyber resilience.
- Significant experience in highly regulated sectors, including oversight of technology and digital regulatory obligations for consumer-facing products and services.
- The presence to influence senior executives, technical leaders and cross-functional teams - a clear, confident, persuasive communicator in the room and on the page.
- Resilience under pressure, with the composure to bring stability and confidence to teams through high-stakes situations.
Technical experience:
- Designing, implementing and embedding enterprise-level risk and control frameworks aligned to organisational and regulatory requirements.
- Building and directing assurance programmes end to end - planning, execution, reporting and remediation across complex technology estates.
- Strong grounding in IT governance principles and established methodologies (e.g. COBIT, ITIL, NIST) applied at scale.
- Hands-on experience with quantitative risk methodologies such as FAIR, and the ability to turn quantitative insight into strategic prioritisation.
- Solid awareness of CISO-level governance frameworks and security control standards - policies, baselines and operational controls.
Certifications:
Relevant professional certification in technology risk or IT control assurance is highly desirable - for example CISM, CISSP, CRISC, CISA, CCSK or CCAK.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
IT Salaries in UK
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
UK Business Culture and Etiquette
Best Companies to Work For in The UK: Top 25 Companies in 2023Â