**Tech Risk and Controls Lead: Strengthen tech control environment and reduce risk**
As our **VP-level Tech Risk & Controls Lead** in **Cybersecurity & Technology Controls**, drive tech risk management, set control expectations, and maintain regulatory compliance. Key responsibilities include owner risk identification, control effectiveness monitoring, issue management, and stakeholder partnership. Required qualifications: 5+ years in tech risk management, knowledge of ISO 27001, CRI Profile, and relevant certifications a plus. Leverage AI tools for evidence synthesis and executive-ready reporting.
Full Job Description
Location: LONDON, United Kingdom
Tech Risk & Controls Lead (VP) Cybersecurity & Technology Controls
Join our team to strengthen the firms technology control environment, reduce technology risk, and maintain strong regulatory and operational outcomes.
As a Tech Risk & Controls Lead (VP) in Cybersecurity & Technology Controls (or [Insert LOB/Sub-LOB]), you will be accountable for the day-to-day execution of the tech risk and controls agenda. You will translate regulatory obligations and firm standards into clear control expectations for technology and process owners. You will monitor control health, lead targeted assessments where required, drive issues to durable remediation, and produce concise, executive-ready reporting on control effectiveness and risk posture.
Key responsibilities
Own technology risk management for your scope, including identifying material risks, assessing impact, and communicating clear, actionable outcomes.Set and enforce control expectations by translating regulatory obligations, industry standards, and firm requirements into practical guidance for technology-aligned process owners.Monitor and challenge control effectiveness across key technology risk domains (e.g., cybersecurity, data security/governance, resilience, third-party, change management); identify gaps and recommend enhancements.Lead control assessments when required, including regulatory and industry-driven assessments, and ensure strong evidence quality and audit readiness.Drive issue and action-plan management end to end: root cause analysis, remediation plans, prioritization, escalation, closure validation, and sustained control improvement.Run controls governance and reporting for senior stakeholders, including control performance, issue themes, and key measurements; translate technical findings into business impact and decisions.Partner across stakeholders including LOB technologists, Product Owners, Business Control Managers, Location CISO, Regulatory Engagement Management, CCOR, Internal Audit, and compliance/risk teams.Use enterprise-authorized AI capabilities to accelerate evidence synthesis and draft executive-ready reporting, with strong validation habits, auditability, and disciplined handling of sensitive data.Coach and develop junior team members as applicable, setting a high bar for quality, timeliness, and regulatory awareness.Required qualifications, capabilities, and skills
Bachelors degree in Computer Science, Cybersecurity, Data Science, or a related discipline (or equivalent experience).5+ years of relevant experience (technology risk management, cybersecurity, technology audit, controls, or assessments), ideally in financial services.Strong knowledge of risk and control frameworks and regulatory expectations; practical familiarity with relevant standards (e.g., ISO 27001, CRI Profile) and, where in scope, requirements such as Swift CSP, CHAPS CRM, HKMA CRAF, Japan CSSA.Demonstrated ability to evaluate control design and operating effectiveness, identify gaps, and drive remediation to completion.Strong judgment and stakeholder management skills, including the ability to influence senior technology and business leaders.Demonstrated experience using enterprise-authorized AI tools in risk/controls workflows, including validating AI-assisted outputs and escalating when uncertain.Preferred qualifications
Certifications such as CISM, CRISC, CISSP (or similar).Experience in payments environments and familiarity with payments-related regulatory standards and cybersecurity control requirements.
Lead in managing tech risks and controls, ensuring compliance and operational integrity in a dynamic risk landscape.