Head of Risk, Cyber
10 hours ago
Head of Risk – Cyber & Technology
Who we're looking for
We are looking for an experienced cyber and technology risk professional with strong technical skills combined with the ability to communicate with and influence both technical and non-technical senior management.
About Schroders
We're a global investment manager. We help institutions, intermediaries and individuals around the world invest money to meet their goals, fulfil their ambitions, and prepare for the future.
We have around 6,000 people on six continents. And we've been around for over 200 years but keep adapting as society and technology changes. What doesn't change is our commitment to helping our clients, and society, prosper.
The base
We moved into our new HQ in the City of London in 2018. We're close to our clients, in the heart of the UK's financial centre and we have everything we need to work flexibly.
Team Overview
The Non-Financial Risk function is comprised of several key teams:
- Operational Risk
- Cyber, Technology & Resilience Risk
- Compliance Assurance
- Risk & Compliance Frameworks, Governance & Reporting
- Physical Security
The Cyber, Technology & Resilience Risk team operates as part of the second line of defence, providing oversight across Schroders. This team develops and maintains the tools and frameworks necessary for overseeing cyber, technology, and resilience risks. It collaborates closely with Global Technology, Information Security, and first-line business units to ensure such risks are clearly defined, assessed, managed, and reported.
Key responsibilities include:
- Overseeing cyber risks via the Information Security Risk Oversight Committee and through review of KRIs and KCIs.
- Collaborating with information security teams to ensure effective articulation, assessment, and management of cyber risks.
- Providing oversight of technology risk through risk control assessments and engagement on strategic technology initiatives.
- Monitoring cyber and technology-related risk events to ensure thorough root cause analysis and appropriate remediation.
- Programme management of the annual operational resilience self-assessment cycle, ensuring all in-scope entities self-assessments are board-approved.
- Programme management of the annual Business Continuity programme.
- Undertaking due diligence on critical third-party continuity and resilience capabilities.
- Maintaining and regularly testing crisis and incident management frameworks.
- Responding to client due diligence requests regarding Business Continuity and Operational Resilience.
What you'll do
This position is responsible for managing this team and ensuring its effective delivery of its responsibilities.
Primary responsibilities include:
- Provide technical 2nd line oversight of Cyber and Technology, ensuring risks are identified and escalated to appropriate senior stakeholders. Work with the 1st line to improve their controls and improve risk management.
- Facilitate the ongoing effectiveness of the Information Security Risk Oversight Committee (ISROC) as the primary governance forum for overseeing the management of Cyber Risk across the Group by:
- Using a risk based approach to identify appropriate topics for inclusion on the agenda;
- Ensuring high quality submissions are provided as requested;
- Ensuring senior stakeholders are fully briefed on key topics prior to the committee; and
- Providing direct challenge to first line senior management at the committee when required.
- Line manage this specialist capability (3 full time staff) to provide challenge and oversight to Information Security and Technology whilst also supporting broader responsibilities for maintaining and enhancing the firm's business continuity and resilience frameworks.
- In response to requests from senior management or governance committees (including the Group Risk Committee and ISROC) undertake risk based reviews of key cyber security and technology processes and controls. Ensuring that findings are appropriately risk assessed and management identify appropriate plans to mitigate the risk.
- Develop strong and effective working relationships across all 3 lines of defence to facilitate effective identification, management and remediation of cyber and technology risks.
- Review and interpret Red/ Purple Team test results identifying key messages and being able to articulate them to non-technical audiences via briefings.
- Demonstrate strong understanding of what are effective response and recovery strategies for cyber incidents.
- Apply insights from experience within leading financial services firms to drive enhancements across cyber and technology risk.
- Draft entity board-level reports for senior leadership and governing bodies.
- Present confidently at governance committee meetings, when required.
The knowledge, experience and qualifications you need
- Degree-level education.
- At least 10 years of relevant experience in Technology and Cyber Risk, gained in a Control/ Risk function, such as Internal Audit, First or Second Line Risk or Control functions.
- Strong technical skillset in Cyber Risk.
- Financial Services experience, preferably in Asset or Wealth Management.
- Proactive approach with strong written communication skills and attention to detail; ability to produce clear, accurate reports tailored to the audience.
- Strong analytical, logical, and problem-solving abilities.
- Effective interpersonal and influencing skills with a collaborative, team-oriented mindset.
The knowledge, experience and qualifications that'll help
- Relevant technical qualifications in Information Security or Technology Risk for example CISA, CISM or CISSP.
- Working knowledge of Asset or Wealth Management.
- Consulting or Big Four experience.
- Experience in working in a first line Technology or Cyber Security Function
- Experience in Investment Banking or Retail Banking within a first line or second line risk capacity.
We recognise potential, whoever you are
Our purpose is to provide excellent investment performance to clients through active management. Diversity of thought, facilitated by an inclusive culture, will allow us to make better decisions and better achieve our purpose. This is why inclusion and diversity are a strategic priority for us and why we are an equal opportunities employer. You are welcome here, regardless of your age, disability, gender identity, religious beliefs, sexual orientation, socio-economic background, or any other protected characteristic.
-
Head of Risk, Cyber
2 days ago
London, Greater London, United Kingdom Schroders Full time £80,000 - £120,000 per yearJob DescriptionHead of Risk – Cyber & TechnologyWho We're Looking ForWe are looking for an experienced cyber and technology risk professional with strong technical skills combined with the ability to communicate with and influence both technical and non-technical senior management.About SchrodersWe're a global investment manager. We help institutions,...
-
Cyber Risk Consultant
14 hours ago
London, Greater London, United Kingdom LT Harper - Cyber Security Recruitment Full time £40,000 - £55,000 per yearCyber Security ConsultantLocation:Hybrid -Sponsorship:Not availableSalary:£40k–£55kIf you've got around2ish years of client-facing cyber consulting experienceand you're ready to step up, learn fast, and take on more responsibility, this role is for you.We're building a next-generation cybersecurity consultancy that stands out by giving clients clear,...
-
Cyber Risk Consultant
14 hours ago
London, Greater London, United Kingdom LT Harper - Cyber Security Recruitment Full time £40,000 - £45,000 per yearCyber Security Consultant - Remote UKLocation:UK Remote -Sponsorship:Not availableSalary:£40k–£45kIf you've got around 1ish years of client-facing cyber consulting experienceand you're ready to step up, learn fast, and take on more responsibility, this role is for you.We're building a next-generation cybersecurity consultancy that stands out by giving...
-
Analyst - Cyber Threat Intelligence
7 hours ago
London, Greater London, United Kingdom Orpheus Cyber Full time £60,000 - £120,000 per yearThere is a new and exciting opportunity for a Cyber Threat Intelligence Analyst, or Associate Threat Intelligence Analyst (DOE) to join our team.Orpheus is a specialist CTI provider that uses its understanding of the threat landscape to power its consulting, managed service, cyber risk ratings, and data services. We are also accredited to the highest level...
-
Head of Information and Cyber Security
4 hours ago
London, Greater London, United Kingdom Sadler Recruitment Full time £960,000 - £1,008,000 per yearJob Description: Role: Head of Cyber SecurityLocation: Hybrid 1 day per week in London (flexible)Salary: £80,000 - £84,000 + benefitsOverviewThis is a pivotal leadership role in shaping and strengthening the cybersecurity landscape of a values-driven, non-profit organisation. The organisation is recognised as a top 100 Employer, historically named as...
-
Cyber Risk Analyst
6 days ago
London, Greater London, United Kingdom Lockton Full time £40,000 - £80,000 per yearGeneral information Reference LocationUnited Kingdom, London, London Work PlaceHybrid RegionUK Job ProfileLockton - Experienced Professional TitleCyber Risk Analyst Description Lockton Re helps businesses understand, mitigate, and capitalize on risk. We're pushing the reinsurance industry forward with smarter solutions that leverage new technologies...
-
Cyber Risk Manager
2 weeks ago
London, Greater London, United Kingdom Convex Insurance Full time £60,000 - £120,000 per yearDepartment:RiskLocation:London, UKDescriptionThe Enterprise Risk Management ('ERM') team sits within the Group Risk Management function, which is comprised of three 'pillars': Insurance Risk, Financial & Market Risk, and ERM. Convex has a strong focus to be market leaders in the use of data and technology.The primary role of the, newly created, Cyber...
-
Associate, Cyber Risk
6 days ago
London, Greater London, United Kingdom Kroll Full time £30,000 - £50,000 per yearDescriptionIn a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll Lens. Our sharp analytical skills, paired with the latest technology, allow us to give our clients clarity—not just answers—in all areas of business. We embrace diverse backgrounds and global perspectives, and we...
-
Technology & Cyber Risk Manager
1 week ago
London, Greater London, United Kingdom Hong Kong Exchanges and Clearing Limited (HKEX) Full time £90,000 - £120,000 per yearTechnology & Cyber Risk ManagerShift Pattern:Standard 40 Hour Week (United Kingdom)Scheduled Weekly Hours:40Corporate Grade:D - Assistant Vice PresidentReporting Line:(UK Division) Risk - 2nd LineLocation:UK-LondonWorker Type:PermanentAbout the London Metal ExchangeThe London Metal Exchange (LME) is the world centre for industrial metals trading. Most of the...
-
Technology & Cyber Risk Manager
1 week ago
London, Greater London, United Kingdom Hong Kong Exchanges and Clearing Limited (HKEX) Full time £60,000 - £120,000 per yearShift Pattern:Standard 40 Hour Week (United Kingdom)Scheduled Weekly Hours:40Corporate Grade:D - Assistant Vice PresidentReporting Line:(UK Division) Risk - 2nd LineLocation:UK-LondonWorker Type:PermanentAbout The London Metal ExchangeThe London Metal Exchange (LME) is the world centre for industrial metals trading. Most of the world's global non-ferrous...