Technology Risk & Resilience Manager; Second Line
Listed on 2026-06-06
-
IT/Tech
Cybersecurity, Information Security, IT Consultant, IT Support
Location: Greater London
Technology Risk & Resilience Manager (Second Line)
- Full‑time
- Rank:
Director - Employment Type:
Permanent Full Time
MUFG Investor Services is a trusted partner to many of the world’s largest public and private funds, providing asset servicing and operational solutions built for alternatives. With over $1 trillion in client assets under administration, we offer fund administration, banking, payments, fund financing, foreign exchange overlay, corporate and regulatory services, custody, business consulting, and more. Operating from 17 locations worldwide, we help clients mitigate risk, enhance efficiency, and navigate the operational complexities of today’s investment management landscape.
As a division of Mitsubishi UFJ Financial Group (MUFG), one of the world’s largest financial institutions with approximately $3 trillion in assets, we combine deep expertise with the strength and stability of a leading financial institution.
We're looking for an experienced Technology Risk & Resilience Manager to join our second line risk in London, United Kingdom or Dublin, Ireland. In this pivotal role, you will:
- Provide independent second line oversight and credible challenge of Technology Risk (Information Technology and Information Security) within the firm, ensuring effective integration of technology risk into the overarching second line Risk Management Framework, including alignment with DORA, third‑party risk, and service resilience expectations.
- The role will not own or operate technology risk controls, but will assess, challenge, and provide assurance over how technology risks are identified, managed, and reported by the first line.
- Define and embed Technology Risk (IT & Information Security) appropriately within the Operational Risk Taxonomy and Framework, ensuring clear, documented delineation of 1
LOD vs 2
LOD accountability in line with the company’s governance models. - Provide independent 2
LOD oversight of the Technology Risk Management Framework, assessing its alignment and interdependency with first‑line control frameworks (e.g. Third‑Party Risk Management, IT Controls, Cybersecurity, etc.) and ensuring coherence with second‑line Operational Risk and Resilience frameworks. - Support the maturation of a consistent service‑based view of technology risk by challenging 1
LOD mapping of applications, infrastructure and third‑party ICT services to internal and client‑facing business services. - Review and challenge first line identification and assessment of technology risks, including application risk, infrastructure dependencies, information security risks and third‑party technology dependencies, ensuring consistency with the company’s risk taxonomy and regulatory expectations.
- Assess the quality, completeness, and consistency of Technology Risk Registers, control inventories, incident remediation activities and impact analysis.
- Provide credible 2
LOD challenge where risk assessments, severity ratings, or residual risk conclusions are not sufficiently supported.
- Support integration of technology risk into the firm’s Operational Risk & Resilience frameworks, including regulatory/jurisdictional aligned frameworks such as:
- Mapping of technology dependencies to important business services
- Assessment of ICT/technology‑related incidents and materiality thresholds
- Align on incident classification and escalation decisions with reporting standards ensuring impacts both technically and operationally are appropriately assessed and captured on associated incident reporting portals.
- Provide second line review and challenge of technology related incidents, including severity, client impact, and regulatory reporting considerations.
- Contribute and support resilience testing and scenario analysis from a technology dependency perspective.
- Provide 2
LOD oversight of technology‑related third‑party risks, ensuring:- Appropriate risk identification where services rely on externally procured applications or infrastructure
- Alignment between Technology Risk and Third‑Party Risk Management outcomes
- Review dependency and concentration risk associated…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: