Our Technology Risk and Resilience team helps firms navigate a fast-moving regulatory landscape while managing robust, future-proof technology estates. From shaping digital resilience frameworks under the Digital Operational Resilience Act (DORA) to helping firms enhance their technology risk maturity, we combine deep sector insight with leading technology to solve problems alongside our clients. This role focuses on managing technology risk and resilience for clients.
Eligibility / Qualification Required:
Key Responsibilities:
- Managing the progress and planning of engagements from contracting to conclusion.
- Leading technology risk and resilience assessments, including control walkthroughs, gap analysis, and remediation planning aligned to frameworks such as COBIT, ITIL, NIST CSF, ISO 27001/22301.
- Driving large-scale transformation programs, including Target Operating Model (TOM) design and implementation, ensuring resilience objectives are embedded in technology change and operations.
- Facilitating workshops with senior stakeholders to assess resilience maturity and define improvement plans.
- Supporting assessments of client operations to identify improvement opportunities and implement new ways of working.
- Writing reports for clients, regulators, and other internal and external stakeholders.
- Leading engagements in the context of risk advisory and assurance, ensuring alignment with regulatory requirements and resilience objectives.
- Using platforms like ServiceNow for resilience-related analysis and reporting.
- Acting as a key link to the wider ETIC ecosystem, leveraging centrally developed AI tools and assets to enhance risk monitoring, resilience testing, and regulatory compliance.
- Advising on cloud adoption and DevOps practices from a risk and resilience perspective, ensuring secure, compliant, and recoverable environments.
- Supporting business development activities such as preparing responses to tenders, creating proposal documents, and contributing to market-facing thought leadership.
- Conducting market research to support the development of new client relationships and opportunities.
- Coaching junior members of the team, providing support, training, and feedback.
- Leading and supporting activities that contribute to the engagement of the broader team beyond specific client engagements.
Essential Skills & Experience:
- Demonstrable track record in technology risk, digital resilience, IT audit, or cyber-resilience (in-house or consulting).
- Deep understanding of UK/EU regulatory drivers (e.g., FCA/PRA Operational Resilience Policy, DORA, SYSC 8, PS 21/3, CP4/24) and relevant industry frameworks (COBIT, ITIL, ISO 27001/22301, NIST CSF).
- Hands-on experience leading multi-workstream projects, producing C-suite deliverables, and managing budgets.
- Strong analytical skills with the ability to translate complex technical issues into clear, business-focused recommendations.
- Excellent written and verbal communication skills; comfortable presenting to ExCo / Audit & Risk Committee level.
- Experience in Tech Ops and Tech Change, including transformation from design through delivery and TOM implementation.
- Familiarity with ServiceNow for resilience-related analysis and automation.
- Full understanding of technology risk models and resilience frameworks.
- Demonstrable experience of using AI in current role for risk and resilience use cases.
Required Certifications:
- CRISC
- CISA
- CISM
- CISSP
- CBCI
- ISO 22301 Lead Implementer/Auditor
- PRINCE2/ AgilePM
Required Technical Skills:
- AWS Devops
- DevOps
- Microsoft Azure
Preferred Experience:
- Experience with cloud-service-provider assurance (AWS Well-Architected reviews, Azure CAF, SOC 2).
Optional Skills (Beneficial):
Accepting Feedback, Active Listening, Amazon Web Services (AWS), Analytical Thinking, Architecture Frameworks, Business Process Modeling, Cloud Infrastructure, Cloud Infrastructure Architecture Design, Cloud Virtualization, Coaching and Feedback, Communication, Creativity, Embracing Change, Emotional Regulation, Empathy, Enterprise Architecture, Enterprise Integration, Firewall (Network Security), Google Cloud Platform (GCP), Inclusion, Intellectual Curiosity, IT Infrastructure, IT Operations, IT Service Management (ITIL) and more.
How to Apply:
Application instructions, including required documents and submission method, are not provided in the job description.
View Official Posting & Apply