We are seeking a highly skilled and experienced Technology Risk & Resilience Manager to become a vital part of our second line risk team in London, United Kingdom or Dublin, Ireland. In this crucial position, your responsibilities will include:Providing independent second line oversight and constructive challenge regarding Technology Risk (Information Technology and Information Security) throughout the organization, ensuring that technology risk is effectively integrated into our comprehensive second line Risk Management Framework, in alignment with DORA, third-party risk, and service resilience expectations.While this role will not own or operate technology risk controls, you will be responsible for evaluating, challenging, and providing assurance regarding the identification, management, and reporting of technology risks by the first line.Key ResponsibilitiesSecond Line Oversight & Framework IntegrationEstablish and integrate Technology Risk (IT & Information Security) within the Operational Risk Taxonomy and Framework, ensuring a clear, documented distinction between 1LOD and 2LOD accountability in accordance with the company’s governance models.Deliver independent second line oversight of the Technology Risk Management Framework, evaluating its alignment and interdependencies with first-line control frameworks (e.g., Third-Party Risk Management, IT Controls, Cybersecurity) and ensuring consistency with second line Operational Risk and Resilience frameworks.Facilitate the development of a consistent service-based perspective on technology risk by scrutinizing 1LOD mappings of applications, infrastructure, and third-party ICT services related to internal and client-facing business services.Risk Identification, Assessment & ChallengeReview and critically assess first line identification and evaluation of technology risks, including (i) application risk, (ii) infrastructure dependencies, (iii) information security risks, and (iv) third-party technology dependencies, ensuring alignment with the company’s risk taxonomy and regulatory standards.Evaluate the quality, completeness, and consistency of Technology Risk Registers, control inventories, incident remediation efforts, and impact analyses.Provide credible second line challenges when risk assessments, severity ratings, or residual risk conclusions lack adequate support.Operational ResiliencePromote the integration of technology risk into the firm’s Operational Risk & Resilience frameworks, ensuring compliance with regulatory/jurisdictional frameworks, including:i) Mapping technology dependencies to critical business servicesii) Assessing ICT/technology-related incidents and materiality thresholdsiii) Collaborating on incident classification and escalation decisions with reporting standards to ensure that both technical and operational impacts are appropriately evaluated and documented in associated incident reporting systems.Provide second line assurance and guidance...
Feb 17, 2026