CrawlJobs Logo

IT Risk Manager

United Kingdom, London · Job Posted January 10, 2026
Apply Position
Job Link Share

Job Description

This role is a key part of the First Line of Defence (FLOD) for Collinson Insurance. Its purpose is to ensure IT and data risks are assessed, managed, and mitigated in line with regulatory requirements and best practice. The role will: · Provide guidance and expertise on FLOD activities for technology and data, ensuring compliance with regulatory, industry, and best practice standards. · Act as the primary contact for IT risk matters, supporting the Head of Engineering in maintaining adherence to IT General Controls, FCA/PRA guidelines, MFSA requirements, DORA, and related regulations. · Coordinate with internal and external second and third line of defence functions, and on the compliance teams across the enterprise.

Job Responsibility

  • FLOD Accountability: Own all FLOD activities, processes, and improvements for technology and data assets, collaborating with relevant stakeholders
  • Control Design & Assurance: Ensure internal controls for IT and data risks are designed, implemented, and maintained. Provide assurance of control effectiveness through indicators and reviews
  • Reporting: Deliver regular updates on IT and data control health to committees, boards, and relevant third parties
  • Education & Consultation: Advise on best practice control design and risk management across technology, product, and service teams
  • Risk Assessment: Conduct focused risk assessments for new and existing services and technologies
  • Agile Engagement: Participate in planning and design sessions, helping prioritise IT, security, and data risk items
  • Policy & Control Implementation: Identify and implement appropriate controls, maintain draft policies, and improve risk posture through remediation and mitigation strategies
  • Collaboration: Work closely with Group CISO, Insurance and Group Risk & Compliance, and Internal Audit teams
  • Continuous Improvement: Stay updated on regulatory and industry changes, mature the IT and data risk framework, and pursue recognised accreditations
  • Incident Management: Ensure robust security and data incident practices, lead resolution of priority incidents (P1/P2), and coordinate with internal and external stakeholders

Requirements

  • Strong practical knowledge of IT security technologies and business solutions, including firewalls, IDS/IPS, identity and access management, SIEM, remote working, and cloud technologies (AWS and Azure)
  • Solid understanding of application security threats, current and emerging information security risks, and organisational challenges in addressing them
  • In-depth knowledge of IT risk frameworks and experience deploying them for business advancement, regulatory compliance, and security management (e.g., ISO 27000, COBIT, NIST 800)
  • Familiarity with legislation and regulations impacting information security, such as GDPR
  • Ability to work within and leverage a security framework for continuous improvement
  • Demonstrable experience in a First Line of Defence (FLOD) role, ideally as an IT Risk Analyst or Manager in a regulated industry (preferably Insurance)
  • Proven track record of delivering continuous improvements in IT and Data Risk areas
  • Comfortable operating in a fast-paced, commercially focused environment
  • Strong communication skills to explain security and risk concepts to both technical and non technical audiences
  • Ability to build relationships, influence decisions, and overcome organisational barriers to achieve goals
  • Excellent analytical skills, with the ability to challenge norms and take a pragmatic approach, balancing commercial needs with security and data protection requirements
  • Ability to identify, assess, and communicate risks, driving objective, fact-based decisions that optimise risk mitigation and business performance

Nice to have

Professional certifications such as CISSP, CISM, and/or CISA are desirable

Looking for more opportunities?

Search for other job offers that match your skills and interests.

Similar Jobs for

IT Risk Manager

8 matching positions

It Senior Manager / It Manager, Risk Advisory Services

Forvis Mazars is a leader in audit, tax and advisory services worldwide, operati...
Location
Location
Hong Kong , Hong Kong
Salary
Salary:
Not provided
Forvis Mazars
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Bachelor's degree in computer science, Information Management, Accounting, or other related disciplines
  • Manager should possess 5+ years' working experience within IT Audit, Cybersecurity, IT Information Security or IT Risk
  • more experienced may be considered for the position of Senior Manager
  • Professionally qualified in CISA, CPA other specialist skills/qualifications
  • Strong command of written and oral communication skills (English, Mandarin & Chinese)
  • Strong teamwork ability and able to work independently
  • Good interpersonal, communication and problem-solving skills
Job Responsibility
Job Responsibility
  • Analyse and evaluate client's IT risks and controls, provide IT risk reduction recommendations, and assist in implementing solutions
  • Conduct benchmarking and gap analysis with IT risk-related industry frameworks (i.e. NIST, ISO, COBIT, C-RAF etc.) and provide recommendations
  • Assist with scoping, financial management, delivery risk management and the initial review of deliverables
  • Conduct fieldwork and manage small project teams to deliver value-added assurance services to clients
  • Identify and communicate IT audit findings to senior management and clients
  • Provide IT general controls and application controls audit support to external audit
  • Determine the objectives, scope and extent of each IT audit and ensure that the IT audit is professionally and efficiently completed within deadlines
  • Perform security and vulnerability assessment, assist in compliance monitoring review to identify control weaknesses and recommend remedial actions
  • Provide an advisory role to business units and IT groups to assess security requirements and controls
  • to enforce security control policies as planned
What we offer
What we offer
  • medical and dental insurance
  • life insurance
  • 5-day working week
  • discretionary performance bonus
  • birthday leave
  • marriage leave
  • employee activities
  • Fulltime
Read More
Arrow Right

IT Manager / IT Project Manager

The IT Manager / IT Project Manager will play a crucial role in planning, execut...
Location
Location
United States , Arlington
Salary
Salary:
Not provided
mmcgrp.com Logo
MMC Group LP
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Bachelor's degree in IT, Computer Science, Business, or related field
  • 7+ years of IT project management experience across full project lifecycles
  • Proven leadership of cross-functional teams and vendor partners
  • Experience with NetSuite, WMS, and distribution/warehouse environments preferred
  • Strong knowledge of project management tools (JIRA, Trello, hybrid methodologies)
  • Successful track record delivering projects on time and within budget
Job Responsibility
Job Responsibility
  • Manage end-to-end IT projects from initiation through completion
  • Assist in defining project scope, objectives, timelines, and deliverables
  • Develop and maintain detailed project schedules, plans, and budgets
  • Coordinate internal teams, third‑party vendors, and cross‑functional stakeholders
  • Monitor project progress using project management tools
  • provide regular status reports
  • Identify and mitigate project risks and issues
  • Ensure all projects meet company standards, policies, and best practices
  • Lead project meetings: kickoffs, status updates, and post‑implementation reviews
  • Support implementation of IT strategies that increase efficiency and business value
What we offer
What we offer
  • Medical, dental, and vision coverage
  • Life and disability insurance
  • Additional voluntary benefits
  • Fulltime
Read More
Arrow Right

Assistant Manager – IT Risk Advisory

Audit & Risk are working with a well-established top 10 firm with over 180 years...
Location
Location
United Kingdom , London or Bristol
Salary
Salary:
Not provided
auditandriskrecruitment.com Logo
Audit & Risk Recruitment
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Ideally be ACA, ACCA or CISA qualified or looking to qualify
  • Previous experience in Tech Assurance /Controls Assurance, Risk Assurance and ITGC controls
  • Internal Audit experience would be a plus
  • Previous experience working in Financial/Professional Services
Job Responsibility
Job Responsibility
  • Work closely with other Assistant Managers, Managers, Senior Managers and Directors to build on the capacity and capability of the Risk Advisory team
  • Support clients in delivering internal audit, risk management and controls and technology assurance solutions
  • Provide a broad range of assurance and advisory activities to help clients manage the risk over their business processes
  • Work with some of the UK’s most interesting companies
  • Have a role in developing the future of the Firm’s Risk Advisory practice
What we offer
What we offer
  • Positive work-life balance
  • Great exposure across various IT Audit projects
  • Aiding in Internal Audit/Operational Audit projects
  • Joining a growing and ambitious professional services team with a strong emphasis on its people and their development
  • Fulltime
Read More
Arrow Right

It Risk Programme Manager

You are an experienced IT Risk Program Manager, or Technology Governance profess...
Location
Location
Netherlands , Amsterdam
Salary
Salary:
Not provided
levy-professionals.com Logo
Levy Professionals
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 10+ years of experience in IT project, programme, or delivery management roles
  • Proven experience leading IT risk, controls, audit remediation, governance, or compliance initiatives
  • Strong understanding of IT controls, IAM, vulnerability management, security risks, and risk management frameworks
  • Experience working within complex enterprise data environments such as data lakes or data warehouses
  • Strong stakeholder management, communication, planning, and execution skills across multiple teams and initiatives
Job Responsibility
Job Responsibility
  • Lead and drive an IT Risk & Control improvement programme across a complex data landscape
  • Coordinate remediation activities for audit findings and proactively identify new IT risks and control gaps
  • Define and execute end-to-end improvement plans, ensuring sustainable implementation of controls and governance processes
  • Coordinate incoming data-related change initiatives, managing dependencies, risks, priorities, and stakeholder alignment
  • Provide clear reporting on progress, risks, blockers, and delivery status to senior stakeholders
  • Fulltime
Read More
Arrow Right

IT Risk Programme Manager

Location
Location
Netherlands , Amsterdam
Salary
Salary:
Not provided
levy-professionals.com Logo
Levy Professionals
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 10+ years of experience in IT project, programme, or delivery management roles
  • Proven experience leading IT risk, controls, audit remediation, governance, or compliance initiatives
  • Strong understanding of IT controls, IAM, vulnerability management, security risks, and risk management frameworks
  • Experience working within complex enterprise data environments such as data lakes or data warehouses
  • Strong stakeholder management, communication, planning, and execution skills across multiple teams and initiatives
Job Responsibility
Job Responsibility
  • Lead and drive an IT Risk & Control improvement programme across a complex data landscape
  • Coordinate remediation activities for audit findings and proactively identify new IT risks and control gaps
  • Define and execute end-to-end improvement plans, ensuring sustainable implementation of controls and governance processes
  • Coordinate incoming data-related change initiatives, managing dependencies, risks, priorities, and stakeholder alignment
  • Provide clear reporting on progress, risks, blockers, and delivery status to senior stakeholders
  • Fulltime
Read More
Arrow Right

It Risk Programme Manager

Location
Location
Netherlands , Amsterdam
Salary
Salary:
Not provided
levy-professionals.com Logo
Levy Professionals
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 10+ years of experience in IT project, programme, or delivery management roles
  • Proven experience leading IT risk, controls, audit remediation, governance, or compliance initiatives
  • Strong understanding of IT controls, IAM, vulnerability management, security risks, and risk management frameworks
  • Experience working within complex enterprise data environments such as data lakes or data warehouses
  • Strong stakeholder management, communication, planning, and execution skills across multiple teams and initiatives
Job Responsibility
Job Responsibility
  • Lead and drive an IT Risk & Control improvement programme across a complex data landscape
  • Coordinate remediation activities for audit findings and proactively identify new IT risks and control gaps
  • Define and execute end-to-end improvement plans, ensuring sustainable implementation of controls and governance processes
  • Coordinate incoming data-related change initiatives, managing dependencies, risks, priorities, and stakeholder alignment
  • Provide clear reporting on progress, risks, blockers, and delivery status to senior stakeholders
Read More
Arrow Right

IT Risk Programme Manager

You are an experienced IT Risk Program Manager, or Technology Governance profess...
Location
Location
Netherlands , Amsterdam
Salary
Salary:
Not provided
levy-professionals.com Logo
Levy Professionals
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 10+ years of experience in IT project, programme, or delivery management roles
  • Proven experience leading IT risk, controls, audit remediation, governance, or compliance initiatives
  • Strong understanding of IT controls, IAM, vulnerability management, security risks, and risk management frameworks
  • Experience working within complex enterprise data environments such as data lakes or data warehouses
  • Strong stakeholder management, communication, planning, and execution skills across multiple teams and initiatives
Job Responsibility
Job Responsibility
  • Lead and drive an IT Risk & Control improvement programme across a complex data landscape
  • Coordinate remediation activities for audit findings and proactively identify new IT risks and control gaps
  • Define and execute end-to-end improvement plans, ensuring sustainable implementation of controls and governance processes
  • Coordinate incoming data-related change initiatives, managing dependencies, risks, priorities, and stakeholder alignment
  • Provide clear reporting on progress, risks, blockers, and delivery status to senior stakeholders
  • Fulltime
Read More
Arrow Right

IT Governance & Risk Manager

The IT Risk & Governance Manager, who reports into the Head of Risk, is responsi...
Location
Location
United Kingdom , London
Salary
Salary:
Not provided
auditandriskrecruitment.com Logo
Audit & Risk Recruitment
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Minimum of 5 years of experience in IT risk management, IT Governance, or a related field
  • Strong understanding of IT risk management principles and practices
  • In-depth knowledge of IT risk management and control frameworks e.g COBIT, ITIL
  • Ability to analyse complex IT environments and identify potential risks
  • Excellent organizational and project management skills
  • High attention to detail and accuracy
  • Strong leadership and influencing skills
Job Responsibility
Job Responsibility
  • Identify, assess, and prioritize IT risks, including cybersecurity, data privacy, and operational risks
  • Design and implement effective IT controls to mitigate identified risks
  • Monitor and evaluate the effectiveness of IT controls and risk management strategies
  • Ensure compliance with relevant laws, regulations, and industry standards (e.g., GDPR, ISO 27001)
  • Prepare and present IT risk reports to senior management and the board of directors
  • Conduct training and awareness programs on IT risk and controls
  • Fulltime
Read More
Arrow Right