IT Risks & Control Manager
Listed on 2026-09-26
-
IT/Tech
Cybersecurity, IT Business Analyst, Information Security & Data Protection, IT Consultant
Job Title
: IT Risks & Control Manager
Target
Start Date:
ASAP
Contract Type: Permanent, Part Time, Full Time, Job Share option available
Salary Range: £59,200 - £88,800
Location: Hybrid, Eastleigh
Closing Date for applications: Thursday 8th October
IT Risks & Control Manager: We’re looking for an experienced IT Risk and Controls Manager to join our Information Security Governance, Risk and Compliance team. In this senior specialist role, you’ll lead the identification, assessment, management and reporting of IT risks across Ageas, helping ensure technology risks are clearly understood, documented and managed in line with our risk appetite.
Reporting to the Governance, Risk and Compliance Lead, you’ll own the IT risk register, facilitate senior IT risk discussions and provide clear, high-quality reporting for governance forums and second-line risk teams.
- Lead IT risk and control assessments using recognised frameworks such as ISO/IEC 27001 and NIST-aligned controls.
- Own and maintain the IT risk register, ensuring risks, controls and treatment plans are accurate and up to date.
- Assess the design and effectiveness of IT controls and support timely remediation, acceptance or escalation of risks.
- Facilitate IT risk meetings with senior technology leaders, providing clear insight and practical recommendations.
- Produce meaningful risk reporting covering trends, control effectiveness and key issues for governance forums.
- Support internal and external audits by providing evidence aligned to recognised control frameworks.
- Work with Security Architecture, Engineering and Operations teams to ensure risks are managed through effective, proportionate controls.
- Strong experience in IT risk management, technology risk or information security risk.
- Good knowledge of IT control frameworks, particularly ISO/IEC 27001 and NIST-aligned controls.
- Experience maintaining IT risk registers and working with GRC tools.
- Confidence facilitating senior stakeholder discussions and governance meetings.
- Ability to translate technical risk and control issues into clear, decision-ready insight.
- A pragmatic, structured and risk-based approach, with strong attention to detail.
It would be great if you also have -
- Certifications such as CRISC, CISM, CISSP or ISO 27001 Lead Implementer/Auditor.
- Experience working in a regulated or high-assurance environment.
- Experience mapping controls across ISO 27001, NIST and internal frameworks.
At Ageas we offer a wide range of benefits to support you and your family inside and outside of work, which helped us achieve,
Top Employer status in the UK.
Flexible Working- Smart Working @ Ageasgives employees flexibility around location (as long as it’s within the UK) and, for many of our roles, flexibility within the working day to manage other commitments, such as school drop offs etc. We also offer all our vacancies part-time/job-shares. We also offer a minimum of 35 days holiday (inc. bank holidays) and you can buy and sell days.
Supporting your Health- Dental Insurance Health Cash Plan, Health Screening, Will Writing, Voluntary Critical Illness, Mental Health First Aiders, Well Being Activities – Mindfulness.
Supporting your Wealth- 50% off esure and Sheilas' Wheels motor and home insurance, Annual Bonus Schemes, Annual Salary Reviews, Competitive Pension, Employee Savings, Employee Loans.
Supporting you at Work- Well-being activities, mindfulness sessions, Sports and Social Club events and more.
Supporting you and your Family- Maternity/pregnant parent/primary adopter entitlement of 16 weeks at full pay and paternity/non-pregnant parent/co-adopter at 8…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).