Morgan McKinley are partnering with a leading Financial Services Group looking for an experienced Technology Risk & Resilience Expert.
If you have 10 plus yrs experience operating in a second line or independent risk oversight role overseeing Technology Risk, IT Risk, Cyber Risk in a financial institution pls reach out for more information on this excellent opportunity.
In this role you will;
- Provide independent second line oversight and credible challenge of Technology Risk (Information Technology and Information Security) within the firm, ensuring effective integration of technology risk into the overarching second line Risk Management Framework, including alignment with DORA, third-party risk, and service resilience expectations.
- Assess, challenge, and provide assurance over how technology risks are identified, managed, and reported by the first line.
Duties include;
- Defining and embedding a Technology Risk (IT & Information Security) appropriately within the Operational Risk Taxonomy and Framework, ensuring clear, documented delineation of 1LOD vs 2LOD accountability in line with company's governance models.
- Providing independent 2LOD oversight of the Technology Risk Management Framework, assessing its alignment and interdependency with first-line control frameworks (e.g. Third-Party Risk Management, IT Controls, Cybersecurity, etc.) and ensuring coherence with second line Operational Risk and Resilience frameworks.
- Supporting the maturation of a consistent service-based view of technology risk by challenging 1LOD mapping of applications, infrastructure and third-party ICT services to internal and client-facing business services.
- Review and challenge first line identification and assessment of technology risks, including (i) application risk (ii) infrastructure dependencies (iii) information security risks and (iv) third-party technology dependencies, ensuring consistency with the company's risk taxonomy and regulatory expectations.
- Assess the quality, completeness, and consistency of Technology Risk Registers, control inventories, incident remediation activities and impact analysis.
- Providing credible 2LOD challenge where risk assessments, severity ratings, or residual risk conclusions are not sufficiently supported.
Operational Resilience
Supporting integration of technology risk into the firm's Operational Risk & Resilience frameworks, including regulatory/jurisdictional aligned frameworks including:
- mapping of technology dependencies to important business services
- assessment of ICT/technology-related incidents and materiality thresholds
- aligning on incident classification and escalation decisions with reporting standards ensuring impacts both technically and operationally are appropriately assessed and captured on associated incident reporting portals.
- Providing second line review and challenge of technology related incidents, including severity, client impact, and regulatory reporting considerations.
- Contributing and support with resilience testing and scenario analysis from a technology dependency perspective.
- Third Party & Technology Dependency Risk
Change & Control Environment Oversight
Governance & Reporting
Qualifications Education Requirements
- Post-secondary degree in technology, business or a related discipline plus qualification in CRISC, CISSP, CISM
- Fluency with frameworks such as NIST CSF, ISO 27001 / 27002, COBIT to facilitate an oversight role
- Professional qualification in risk or a related discipline would be preferred but not essential
Work Experience
- 10+ years' experience operating in a second line or independent risk oversight role overseeing Technology Risk, IT Risk, Cyber Risk in a financial institution or compatible industry
- Experience within governance, oversight programs of IT Architecture, Application and EUC development and deployment
- Strong knowledge of: (i) technology risk concepts (ii) information security risk (iii) third-party technology risk (iv) operational resilience principles (v) corporate insurance
- Familiarity with information management frameworks through the lens of technology risk (inclusive of cyber and information security)
- Experience engaging credibly with senior technology and business stakeholders
- Strong written and verbal communication skills, particularly in translating technical issues into business risk
Essential Functional/Technical Skills and Knowledge Requirements
- Experience with DORA, operational resilience, or similar regulatory regimes
- Experience working in fund services, asset servicing, or regulated financial services
- Exposure to multi-entity or cross-jurisdictional regulatory environments
- Proactive, solution-oriented mindset with the ability to work effectively in a fast-paced environment.
- Advanced proficiency in Microsoft Excel and experience of onboarding new systems / technology are preferred
- Strong IT skills with strengths in Microsoft Office products
All interested candidates should send CVs
