Head of IT Risk & Controls
Core
Establish and lead the first-line IT Risk & Controls capability within Technology & Transformation to embed risk ownership, strengthen governance, and ensure a secure, resilient technology environment.
Role type
Head of IT Risk & Controls (Strategic Leadership)
Builds
First-line technology risk management practices, control processes, assurance readiness, and reporting routines aligned to enterprise risk and cyber frameworks.
Domain
Financial Services / Technology Risk & Governance
Required skills
Leading technology risk and IT audit functions, enterprise risk management, cloud environment governance, cyber security practices, building first-line control practices, executive stakeholder influence, translating complex risk concepts to business outcomes.
Preferred skills
Pragmatic and commercially minded approach to risk management, passion for enabling innovation through strong foundations.
Technologies
Cloud environments, Cyber security frameworks, Enterprise risk management frameworks.
Responsibilities
Lead first-line Technology Risk & Controls function across the Group; Embed and mature first-line technology risk management practices and control processes; Partner with business, risk, compliance, and cyber leaders to identify, assess, treat, and escalate technology risks; Maintain first-line oversight of technology control environments including cyber security, operational resilience, and third-party risk; Support first-line compliance with regulatory and internal governance obligations; Provide practical first-line advice to executives on technology, cyber, and operational risk impacts.
Seniority
Senior, hands-on IC