companyMUFG Investor Services logo

Technology Risk & Resilience Manager - Second Line

On-site Full-time

Clicking Apply Now takes you to AutoApply where you can tailor your resume and apply.


Unlock Your Potential

Generate Job-Optimized Resume

One Click And Our AI Optimizes Your Resume to Match The Job Description.

Is Your Resume Optimized For This Role?

Find Out If You're Highlighting The Right Skills And Fix What's Missing

Experience Level

Mid to Senior

Qualifications

Education RequirementsA post-secondary degree in technology, business, or a related field, along with qualifications in CRISC, CISSP, or CISM. Proficiency with frameworks such as NIST CSF, ISO 27001/27002, and COBIT to effectively fulfill an oversight role. A professional qualification in risk or a related field is preferred but not mandatory. Work ExperienceOver 10 years of experience working in a second line or independent risk oversight role focusing on Technology Risk, IT Risk, or Cyber Risk within a financial institution or a similar industry. Experience in governance and oversight of IT Architecture, Application, and End User Computing (EUC) development and deployment. Strong comprehension of: (i) technology risk concepts, (ii) information security risk, (iii) third-party technology risk, (iv) principles of operational resilience, and (v) corporate insurance. Familiarity with information management frameworks.

About the job

We are seeking a highly skilled and experienced Technology Risk & Resilience Manager to become a vital part of our second line risk team in London, United Kingdom or Dublin, Ireland. In this crucial position, your responsibilities will include:

  • Providing independent second line oversight and constructive challenge regarding Technology Risk (Information Technology and Information Security) throughout the organization, ensuring that technology risk is effectively integrated into our comprehensive second line Risk Management Framework, in alignment with DORA, third-party risk, and service resilience expectations.
  • While this role will not own or operate technology risk controls, you will be responsible for evaluating, challenging, and providing assurance regarding the identification, management, and reporting of technology risks by the first line.

Key Responsibilities

Second Line Oversight & Framework Integration

  • Establish and integrate Technology Risk (IT & Information Security) within the Operational Risk Taxonomy and Framework, ensuring a clear, documented distinction between 1LOD and 2LOD accountability in accordance with the company’s governance models.
  • Deliver independent second line oversight of the Technology Risk Management Framework, evaluating its alignment and interdependencies with first-line control frameworks (e.g., Third-Party Risk Management, IT Controls, Cybersecurity) and ensuring consistency with second line Operational Risk and Resilience frameworks.
  • Facilitate the development of a consistent service-based perspective on technology risk by scrutinizing 1LOD mappings of applications, infrastructure, and third-party ICT services related to internal and client-facing business services.

Risk Identification, Assessment & Challenge

  • Review and critically assess first line identification and evaluation of technology risks, including (i) application risk, (ii) infrastructure dependencies, (iii) information security risks, and (iv) third-party technology dependencies, ensuring alignment with the company’s risk taxonomy and regulatory standards.
  • Evaluate the quality, completeness, and consistency of Technology Risk Registers, control inventories, incident remediation efforts, and impact analyses.
  • Provide credible second line challenges when risk assessments, severity ratings, or residual risk conclusions lack adequate support.

Operational Resilience

  • Promote the integration of technology risk into the firm’s Operational Risk & Resilience frameworks, ensuring compliance with regulatory/jurisdictional frameworks, including:

i) Mapping technology dependencies to critical business services

ii) Assessing ICT/technology-related incidents and materiality thresholds

iii) Collaborating on incident classification and escalation decisions with reporting standards to ensure that both technical and operational impacts are appropriately evaluated and documented in associated incident reporting systems.

  • Provide second line assurance and guidance...

About MUFG Investor Services

MUFG Investor Services stands as a trusted partner to many of the world’s largest public and private funds, delivering asset servicing and operational solutions tailored for alternatives. With over $1 trillion in client assets under administration, we provide a wide array of services including fund administration, banking, payments, fund financing, foreign exchange overlay, corporate and regulatory services, custody, and business consulting. Operating from 17 locations globally, we aid clients in mitigating risk, enhancing efficiency, and navigating the complexities of today’s investment management landscape. As a division of Mitsubishi UFJ Financial Group (MUFG), one of the world’s largest financial institutions with approximately $3 trillion in assets, we combine deep industry expertise with the strength and stability of a leading financial institution. To discover more, visit us at www.mufg-investorservices.com.

Similar jobs

Tailoring 0 resumes

We'll move completed jobs to Ready to Apply automatically.