Head of Technology, Risk Management and Governance

6 months ago


Edinburgh, United Kingdom SSE Full time

SSE has big ambitions to be a leading energy company in a low carbon world. Following our commitment to invest £18 billion in low carbon projects to 2027, we have significant growth plans and are well on our way to achieving our ambition to build a world that's more sustainable and inclusive for you, your family, the community you live in and for generations to come.

Join us on our journey to net zero and help us power change.

**About the Role**

**Base Location**: Flexible, however our preference is that you will be based in one of our key UK or Ireland sites, which includes but is not limited to:

- Edinburgh, Glasgow, Perth, and Reading.

**Salary**: Highly competitive and based on experience + car /car allowance + performance-related bonus + a range of benefits to support your finances, wellbeing and family.

**Working Pattern**: Permanent | Full Time with Flexible First options available

The Head of Technology Risk Management and Governance will lead the Group Technology Risk management and Governance function within IT. They will be accountable for continually improving the provision of GRC services and assure against significant loss of service, financial loss and reputational damage.

This is senior and visible role within the SSE organisation, where the role holder will be accountable for ensuring the SSE Group discharges its technology and cyber risk obligations whilst also ensuring that all risks and controls are managed and ultimately the Group is not adversely impacted.

The role holder will work collaboratively with senior IT, Business stakeholders and governance and control boards (Group Audit and Risk Committees and BU Excos) to define, communicate and measure key risk and controls for IT, maintained in line with business risk appetite. At SSE we operate a three lines of defence model, this role will interface with Group Risk and Audit (3rd line) whilst being accountable overseeing the effectiveness of the first and second lines of defence.

Key Accountabilities
- Provide management and leadership of the Governance, Risk and Compliance Function including accountability for Tech and Cyber Risk.
- Accountable for the Technology Risk framework covering Technology Resilience, Cyber and Data Management governance, risk and assurance objectives.
- Ensuring that IT, Cyber and Supply Chain risk management is comprehensive and aligned to SSE’s business strategy and risk appetite.
- Accountable for compliance management for Technology, Cyber and Supply Chain risks that may impact SSE IT operations, change the delivery of the IT business strategy, or present a threat to SSE’s risk appetite or compliance status.
- Make recommendations on design and build of robust GRC solutions and controls to enable delivery of the IT / business strategy. You will also drive audit and testing assurance programmes to ensure IT, Cyber and Third Party controls are compliant with regulatory requirements as well internal standards and policies.
- Accountable for first line risk and assurance governance objectives, ensuring accurate management information and reporting from Operational committees through to Board.
- Develop and deliver automated metrics and reports that provide a real time compliance ‘dashboard’ for use at all levels of the organisation and enables tangible and visible risk reduction.

**What do I need?**

To be considered for this role, we would love you to have:

- Considerable experience of previously leading an IT GRC function.
- Experience in establishing technology and security governance and controls to protect the organisation's information resources, in the most effective and efficient manner, in pursuit of its business objectives.
- Significant experience in managing and assessing the effectiveness and coverage of organisational Technology and Security Policies, ensuring they are up to date, complete, and aligned to business risk. You should also have significant experience in defining and collecting metrics operationally and assurance metrics for regular reporting to the Governance Committees and Executive Leadership Teams.
- Experience of partnering with business stakeholders to capture, monitor changes in scope, and regularly audit high-risk organisational third parties to deliver improved risk outcomes.
- Experience in providing leadership, direction, and guidance in assessing and evaluating information security risks, monitoring compliance to security standards and appropriate policies (SANS, CIS, NIST, Cyber Essentials etc.)

**About our Business**

SSE IT underpins the technology needs of all the different businesses that make up the SSE group. From emerging technologies to data and analytics to cyber security - we power SSE's growth and enable it to generate value, while keeping it secure. As a trusted business partner that helps SSE lead in a low carbon world, we are proud of our service. Working for SSE IT is all about equipping SSE for now and the future.

**What's in it for


  • Head of IT Risk

    6 months ago


    Edinburgh, United Kingdom Phoenix Group Full time

    **Job Title, Grade**:Head of IT Risk & Assurance, Senior Leadership **Job Type**:Permanent **Location**:This role could be based in either our Edinburgh or Wythall offices with time spent working in the office and at home. There will be a limited degree of UK travel to supplier sites and there may also be very occasional international travel. **Flexible...


  • Edinburgh, United Kingdom Head Resourcing Full time

    Head of IT Edinburgh – hybrid Up to £72,000 + benefits This role is a 6 month fixed-term contract but can go permanentHead Resourcing are pleased to be working with a well-established professional body based in Edinburgh as they look to recruit a Head of IT for an initial period of 6 months. Our client strives to be a world class professional body,...


  • Edinburgh, United Kingdom Head Resourcing Full time

    Head of IT Edinburgh – hybrid Up to £72,000 + benefits This role is a 6 month fixed-term contract but can go permanentHead Resourcing are pleased to be working with a well-established professional body based in Edinburgh as they look to recruit a Head of IT for an initial period of 6 months. Our client strives to be a world class professional body,...


  • Edinburgh, Edinburgh, United Kingdom Diligenta Full time

    Role SummaryDiligenta is seeking an experienced Risk Manager to join our team. As a Risk Manager, you will play a critical role in supporting the Head of Enterprise Risk in providing oversight of risks impacting the business. Your expertise will help drive growth and protect the company's reputation.Key Responsibilities:- Support the Head of Function on...


  • Edinburgh, United Kingdom Computershare Full time

    **Location: Edinburgh, Bristol, London** This is a hybrid position primarily based in one of our Edinburgh, Bristol or London offices. We’re committed to your flexibility and wellbeing and our hybrid strategy currently requires two days a week in the office, giving you the option to work remotely for some of your working week. Find out more about our...


  • Edinburgh, United Kingdom Computershare Full time

    **Location: Edinburgh, Bristol, London** This is a hybrid position primarily based in one of our Edinburgh, Bristol or London offices. We’re committed to your flexibility and wellbeing and our hybrid strategy currently requires two days a week in the office, giving you the option to work remotely for some of your working week. Find out more about our...


  • Edinburgh, Scotland, Scotland, United Kingdom Head Resourcing Full time

    Head of IT Edinburgh – hybrid Up to £72,000 + benefits This role is a 6 month fixed-term contract but can go permanentHead Resourcing are pleased to be working with a well-established professional body based in Edinburgh as they look to recruit a Head of IT for an initial period of 6 months. Our client strives to be a world class professional body,...


  • Edinburgh, Edinburgh, United Kingdom HSBC Full time

    We are seeking a highly experienced individual to join the 2LOD HSBC UK ERM team in the role of ERM Resilience Risk Steward for Technology and Cyber Security Risk (TCS). This position will focus on Information Technology (IT) Risk.The primary responsibilities of this role include providing specialist IT advice, guidance, and challenge across all IT related...

  • Head of Performance

    6 months ago


    Edinburgh, United Kingdom Audit Scotland Full time

    Are you an experienced professional in the field of performance management and corporate governance who thrives on making a difference and is passionate about ensuring public services are run properly for the people of Scotland? Audit Scotland expects public bodies to have high quality performance and governance arrangements - and we set high standards for...

  • Technology Risk

    6 months ago


    Edinburgh, United Kingdom Bridge of Hope Full time

    We are AMS. We are a global total workforce solutions firm; we enable organisations to thrive in an age of constant change by building, re-shaping, and optimising workforces. Our Contingent Workforce Solutions (CWS) service partner with Tesco Bank to support contingent recruitment hiring. On behalf of Tesco Bank, AMS are now looking for a **Technology...


  • Edinburgh, United Kingdom RBS International Full time

    Our people work differently depending on their jobs and needs. From hybrid working to flexible hours, we have plenty of options that help our people to thrive. This role is based in the United Kingdom and as such all normal working days must be carried out in the United Kingdom. Join us as a Head of Depositary Risk - In this vital and highly visible role,...


  • City of Edinburgh, United Kingdom Head Resourcing Full time

    Head of IT Edinburgh – hybrid Up to £72,000 + benefits This role is a 6 month fixed-term contract but can go permanent Head Resourcing are pleased to be working with a well-established professional body based in Edinburgh as they look to recruit a Head of IT for an initial period of 6 months.Our client strives to be a world class professional body,...


  • Edinburgh, Edinburgh, United Kingdom Gresham Hunt Full time

    About the Role:We are seeking an experienced Technology Risk Leader to join our team at Gresham Hunt in Edinburgh. As a leading financial services group, we operate in a rapidly changing regulatory environment.Your Key Responsibilities:Develop and implement effective Technology and Cloud Controls to ensure operational efficiency across our...


  • Edinburgh, Edinburgh, United Kingdom CV Library Full time

    Job Title: Director of Operational Risk GovernanceWe are seeking an experienced Director of Operational Risk Governance to join our team at CV Library. This is a challenging and rewarding role that will see you working closely with the business, products, and risk function to identify, assess, and manage operational risks.About the RoleThe successful...


  • Edinburgh, Edinburgh, United Kingdom Sanderson Recruitment Plc Full time

    About the RoleThis is an exciting opportunity to join our team as a Risk Management Specialist and contribute to our company's success. As a Risk Management Specialist, you will be responsible for supporting the Head of Enterprise Risk in providing oversight of risks that impact our business. You will work closely with senior managers across IT, Finance,...


  • Edinburgh, United Kingdom JPMorgan Chase & Co Full time

    **JOB DESCRIPTION** About us**: **International Consumer Banking (ICB)**: JPMorgan Chase & Co. is expanding its business and is investing in innovative ways to attract customers, deepen engagement and drive increased satisfaction through delightful interactions with digital products and experiences. Our team is at the heart of driving this transformation,...


  • Edinburgh, Edinburgh, United Kingdom NatWest Full time

    Job Title: Technology Risk and Compliance LeadNatWest is recruiting for a Technology Risk and Compliance Lead to lead technology controls testing and reviews, and drive risk framework and policy compliance.Key Responsibilities:Support management in risk assessment and develop strategies for risk mitigation.Drive SOX risk assessment technology and control...

  • Technology Risk

    2 months ago


    Edinburgh, United Kingdom NatWest Full time

    Join us as a Technology Risk & Controls ManagerIf you have a background in risk and control assessment, testing technology controls then join our team in helping to anticipate and assess the potential impacts of risk across the bank We’ll look to you to lead and perform technology controls testing and reviews, proactively driving the assessment and...

  • Technology Risk

    2 months ago


    Edinburgh, United Kingdom CV-Library Full time

    Join us as a Technology Risk & Controls Manager If you have a background in risk and control assessment, testing technology controls then join our team in helping to anticipate and assess the potential impacts of risk across the bank We’ll look to you to lead and perform technology controls testing and reviews, proactively driving the assessment and...


  • Edinburgh, Edinburgh, United Kingdom Trustpilot Full time

    At Trustpilot, our vision is to be the universal symbol of trust. We bring consumers and businesses together through reviews, with a focus on openness, independence, and impartiality.SalaryWe offer a competitive compensation package with a base salary ranging from $90,000 to $120,000 per annum, depending on experience.About the RoleThis mid-level Governance,...