IS Risk Manager
1 week ago
Job Type: IS Risk Manager, Permanent, Information Security & Cyber Risk Specialist Band 1, UK
Location: Hybrid: this role could be based in either our Edinburgh, London or Birmingham offices, with time spent working weekly in both the office and at home. The amount of time working from the office is variable based on business need.
Flexible working: All of our roles are open to part-time, job-share and other types of flexibility. We will discuss what is important to you and balancing this with business requirements during the recruitment process. You can read more about Phoenix Flex here.
Closing Date: 12th December 2025
Salary and benefits: Up to £70,000, dependent upon experience, plus 16-32% bonus potential, private medical cover, 38 days annual leave, excellent pension, 12x salary life assurance, career breaks, income protection, 3x volunteering days and much more.
Who are we?
We want to be the best place that any of our 6,600 colleagues have ever worked.
We're Phoenix Group, we're a long-term savings and retirement business. We offer a range of products across our market-leading brands, Standard Life, SunLife, Phoenix Life and ReAssure. Around 1 in 5 people in the UK has a pension with us. We're a FTSE 100 organisation that is tackling key issues such as transitioning our portfolio to net zero by 2050, and we're not done yet.
The role
Non-Financial Risk is part of Group Risk and has a fantastic opportunity for a talented individual to join the team as an Information Security & Cyber Risk Manager within the newly forming IT/IS/Resilience and Supplier Risk Oversight Team. The role is to provide Second Line Subject Matter Expert (SME) advice, oversight and challenge on Line 1's design and operation of their Information Security, Information Management and Cyber related standards, risks and controls.
The role holder will, in addition to regular oversight of the Information Security, Information Management and Cyber Risk control environments, both lead and support the delivery of a rolling programme of Thematic and Risk based focused reviews, following a structured methodology. This will involve shaping the scope of reviews, preparing for and performing field work, validation of proposed findings and provision of insightful recommendations to Line 1 through clear written reporting.
Key Accountabilities:
- Provide ongoing oversight and challenge to Line 1 led Information Security, Information Management and Cyber Risk control management
- Analyse and interpret key risk indicators and risk and control reporting to help determine where Line 2 effort is best focused, and to develop formal Line 2 opinions on Information Security, Information Management and Cyber matters
- Provide insight, oversight and challenge within assigned monthly Forums
- Lead Line 2 led Information Security, Information Management and Cyber Risk Thematic/Risk Reviews throughout the full lifecycle, including Planning/Terms of Reference, Fieldwork, Findings Validation and Reporting stages
- Provide oversight and challenge on material Projects and Programmes
- Oversee Line 1 activity to ensure adherence to the Group's Risk Management Framework, providing advice and guidance as required
- Support the broader team with assigned Line 2 activity relating to Information Technology, AI, Operational Resilience and Third-Party Management
- Develop and build relationships with Line 1 and Line 3 peers and senior stakeholders
What are we looking for?
- Essential: Proven experience managing Information Security, Information Management and Cyber Risk (including third party oversight), in either a second or third-line capacity, within a high regulated UK industry such as Financial Services
- Essential: Strong stakeholder, relationship management and influencing skills. An accomplished communicator who is comfortable, respectful and calm during sometimes challenging situations where differences of risk opinion need to be clearly positioned and justified. Able to analyse situations in a timely manner, producing clear, insightful and succinct written reports.
- Preferred: Professional qualification in Information Security, Information Management or Cyber Security e.g., from IRM, BCS, ISACA or ISC2 organisations.
- Preferred: Knowledge of Artificial Intelligence (AI) – naturally curious about AI and the advantages it can bring to organisations, in balance with controlling risks
- Preferred: Knowledge of cloud computing, shared responsibility models and associated common risks
- Preferred: A career background of having worked in IT for large UK corporations, with a solid baseline understanding of Information Security, Information Management and Cyber Risk Management, and control frameworks
We want to hire the whole version of you.
We are committed to ensuring that everyone feels accepted and welcome applicants from all backgrounds. If your experience looks different from what we've advertised and you believe that you can bring value to the role, we'd love to hear from you.
If you require any adjustments to the recruitment process, please let us know so we can help you to be at your best.
Please note that we reserve the right to remove adverts earlier than the advertised closing date. We encourage you to apply at the earliest opportunity.
Find out more about #LifeAtPhoenix
- Guide for Candidates:
- Find or get answers from our colleagues:
#LI-TT2
#LI-HYBRID
#LI-REMOTE
-
Risk Manager
1 week ago
Edinburgh, Edinburgh, United Kingdom Head Resourcing Full time £40,000 - £80,000 per yearHybrid – Edinburgh Salary – up to £70,000 Role – Third Party Risk ManagerHead Resourcing have partnered with an established private banking client in Edinburgh who are looking to recruit a Third Party Risk Manager.About the Role:Reporting into the CIO, this role plays a key role in the management of the Bank's supply chain, with primary...
-
Risk and Controls Manager
1 day ago
Edinburgh, Edinburgh, United Kingdom JPMorganChase Full time £200,000 - £400,000 per yearRisk and Controls Manager - JP Morgan Chase - Edinburgh - 12 months contract - ONSITE - PAYEWe are seeking an experienced Risk and Controls Manager to join Chase UK, JP Morgan's digital consumer bank, in Edinburgh, for an initial 12 months contract. You should have previous risk and controls experience within the financial services industry with strong...
-
Business Risk Management
7 days ago
Edinburgh, Edinburgh, United Kingdom Jobs via eFinancialCareers Full time £90,000 - £120,000 per yearWho We Are Looking ForThe Vice President (VP) will play a leadership role in the first line risk management of client deals, focusing on the assessment of risk during the deal lifecycle and the execution of process and control reviews. This role supports the integration of lift-out's into the firm's risk ecosystem, ensuring alignment with internal control...
-
Senior Risk Manager
5 days ago
Edinburgh, Edinburgh, United Kingdom Turner & Townsend Full time £60,000 - £100,000 per yearCompany Description Turner & Townsend is a global professional services company with over 22,000 people in more than 60 countries.Working with our clients across real estate, infrastructure, energy and natural resources, we transform together delivering outcomes that improve people's lives. Working in partnership makes it possible to deliver the world's most...
-
Business Risk Management
2 weeks ago
Edinburgh, Edinburgh, United Kingdom State Street Full time £60,000 - £120,000 per yearWho we are looking forThe Vice President (VP) will play a leadership role in the first line risk management of client deals, focusing on the assessment of risk during the deal lifecycle and the execution of process and control reviews. This role supports the integration of lift-out's into the firm's risk ecosystem, ensuring alignment with internal control...
-
Business Risk Management
2 weeks ago
Edinburgh, Edinburgh, United Kingdom State Street Full time £60,000 - £120,000 per year*Who We Are Looking For*The Vice President (VP) will play a leadership role in the first line risk management of client deals, focusing on the assessment of risk during the deal lifecycle and the execution of process and control reviews. This role supports the integration of lift-out's into the firm's risk ecosystem, ensuring alignment with internal control...
-
Enterprise Risk Management
3 days ago
Edinburgh, Edinburgh, United Kingdom BlackRock Full timeAbout this role BlackRock, the world's largest asset manager, is committed to empowering a growing number of individuals to achieve financial prosperity. As a global investment manager, we invest on behalf of our clients, from large institutions to parents, grandparents, doctors, and teachers who entrust their savings to us. Our promise is to offer them the...
-
Cyber Security Risk Manager
5 days ago
Edinburgh, Edinburgh, United Kingdom Bright Purple Full time £70,000 per yearSenior Cyber Security Risk ManagerHybrid, EdinburghUp to £70,000 + benefitsBenefitsIn return for your expertise and commitment, you'll receive:Annual bonusFlexible hybrid workingExcellent healthcare and pension schemeLife assuranceElectric Vehicle SchemeAbout the RoleThis is a brilliant opportunity for an experienced Cyber Security Risk professional to take...
-
Technology Risk
1 week ago
Edinburgh, Edinburgh, United Kingdom RBS Full time £60,000 - £120,000 per yearAdditional Job Description Join us as a Technology Risk & Controls ManagerWe'll look to you to apply effective risk management and decision-making capability, anticipating and assessing the potential impacts of risk associated with technology across the relevant business areaYou'll partner with our business and Service Management teams to manage our risks...
-
Model Risk Senior Manager
5 days ago
Edinburgh, Edinburgh, United Kingdom Tesco Bank Full time £60,000 - £90,000 per yearGeneral informationJob Title:Model Risk Senior ManagerRef #:9425Location:EdinburghDepartment:BAR - Financial RiskBusiness Area:Financial RiskWorking time:Full-TimeDate Published: Serving our customers, communities, and planet a little better every day.Salary– Up to £90,000 + annual bonus & benefitsLocation- EdinburghOffice Attendance- Our roles are...