Job Description
We are seeking a Risk & Controls (R&C) professional to be embedded within the Technology function supporting investment and corporate business units. This role will be part of the R&C function which comprises team members driving R&C Strategy and Standards settings.
Operating within the First Line of Defence, this role partners with engineering, architecture, and platform teams to ensure technology risks are effectively managed and controls are embedded across systems and delivery processes. The role focuses on enabling secure, resilient, and well-governed platforms that support investment decision-making and operations.
What will you do as a VP Risk & Controls Officer?
Technology Risk Advisory
- Partner with technology teams to identify, assess, and manage risks across systems, platforms, and change initiatives
- Provide risk input into architecture, system design, and major technology programs
- Translate technical risks into clear business impact and mitigation actions
Controls Design & Implementation
- Design and embed controls across the technology lifecycle (SDLC, change management, access controls, data governance)
- Ensure controls are integrated into delivery workflows (e.g., DevOps, CI/CD)
- Maintain and enhance Operational Risk Self-Assessments (ORSA)
Operational Resilience & Incident Management
- Support system resilience, disaster recovery, and service continuity frameworks
- Oversee technology incidents, including root cause analysis and remediation tracking
- Ensure timely closure of control gaps and sustainable fixes
Monitoring & Reporting
- Develop and track Key Risk Indicators (KRIs) for technology risk
- Produce risk dashboards and insights for senior stakeholders
- Highlight emerging risks across systems, platforms, and dependencies
Third-Party Risk & Governance
- Support risk assessments and controls for vendors and service providers
- Ensure appropriate oversight of outsourced technology services
Stakeholder Engagement
- Act as a liaison between Technology (1st line), Risk (2nd line), and Internal Audit (3rd line)
- Build strong relationships with engineering and platform teams