Summary
Scope Ratings is looking for an ICT Risk Manager as part of the ICT Risk management function, and will be responsible for executing the ICT risk management framework on a day-to-day basis, including running the ICT risk assessment cycle, maintaining the function's registers, coordinating resilience testing and producing the function's reporting.
ICT Risk Management owns the ICT risk management framework and provides independent oversight of its implementation. The function incorporates oversight of Information Security, ICT business continuity and ICT third-party risk management.
Duties & responsibilities
- Draft and maintain the ICT risk management framework, the underlying policies and methodologies.
- Design the function's processes and workflows, including vendor assessment, finding management and change risk review, in collaboration with business and technology functions.
- Respond to client security questionnaires and ad-hoc security and resilience disclosure requests, and maintain a library of standard responses.
- Identify opportunities to streamline and automate the function's processes.
- Build and maintain effective relationships with business, technology and control functions, supporting them in identifying ICT risks, including vendor assessments, business impact analyses (BIAs) and control documentation.
- Design and run ICT business continuity and resilience exercises, including scenarios, facilitation and capturing lessons learned.
- Run the ICT security testing programme, including penetration testing (scoping, rules of engagement, vendor triage, oversight, finding triage), vulnerability scanning, social engineering and phishing simulations, and breach scenario exercises.
- Maintain the cyber threat landscape through active monitoring of threat intelligence sources, ISAC participation and sectoral information sharing, and translate threat intel into scenarios and risk profile updates.
- Consolidate findings from audits, risk assessments, security testing and incidents into a single ICT findings view, and track remediation through to closure across business and technology functions, escalating delays and blockers to the Head of ICT Risk Management.
- Write executive summaries and briefings on ICT risk topics for the Resilience Committee, Senior and Executive Management and the Boards.
Professional & personal qualifications
- 4+ years of experience in a risk, security, or resilience discipline, such as ICT/technology risk, information security, or operational resilience, within financial services or another regulated industry.
- Experience drafting policies, methodologies and process documentation.
- Practical experience in one or more of the following: running ICT risk assessment cycles, commissioning or overseeing security testing programmes (including penetration testing and vulnerability management), designing and facilitating business continuity exercises, reviewing and challenging incident investigations and problem management led by first-line teams.
- Experience working with first-line business and technology functions on risk or security-related topics.
- Working knowledge of security or resilience frameworks, such as DORA, the EBA Guidelines on ICT and Security Risk Management, and of recognised standards including ISO/IEC 27001 and NIST Cybersecurity Framework.
- Awareness of the threat landscape relevant to financial services and of current developments in cyber, AI and ICT third-party risk.
- Preferred experience in third-party or vendor risk management, or in a related discipline involving vendor oversight, such as procurement, vendor governance, or supplier relationship management.
- Preferred working knowledge of secure software development practices and the controls embedded in application, model and infrastructure-as-code development lifecycles.
- Preferred certification in information security or ICT risk management demonstrating expertise across security programmes and operational risk practices, such as CISM or CRISC.
- Fluent in English (written and spoken)