Technology Risk Officer - Border to Coast Pension Partnership
Listed on 2026-10-04
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant
Border to Coast Pensions Partnership is one of the UK's largest pension pools and the largest asset manager outside London and Edinburgh. Owned by 18 Local Government Pension Scheme partner funds, we manage approximately £120 billion of assets on behalf of more than two million members.
As a customer-owned and customer-focused organisation, our purpose is to make a difference for the Local Government Pension Scheme. Integrity, collaboration and sustainability are at the heart of how we work, and we are continuing to invest in our technology, data and innovation capabilities to support our long-term strategic ambitions.
Our client is an FCA regulated asset manager whose continued growth places an ever greater premium on trust. With an outsourced ICT model and a network of key service providers, the business requires a technology risk and control environment capable of ensuring that we are a sustainable organisation that can deliver for clients over the long term.
This first line appointment provides that assurance. You will oversee technology risk across the IT estate, supporting the identification and mitigation of risk in daily operations, and evidencing the organisation's adherence to information security, operational resilience and outsourcing requirements.
What you will be doing- Provide first line technology risk oversight across IT infrastructure, supporting risk identification, mitigation and control effectiveness
- Act as the bridge to second line risk, compliance and assurance, ensuring technology risks are documented, challenged and reported
- Evidence adherence to information security, operational resilience and outsourcing requirements, including FCA and ISO
27001 expectations - Coordinate internal and external audits, from control design evidence to remediation tracking and management responses
- Assess and report on technology and infrastructure risk, including third party, cloud and service resilience, escalating where required
- Produce clear risk reporting, management information and assurance outputs for management, risk forums and audit committees
- Keep ICT risk and compliance oversight effective, internally and with outsourced partners
- Support senior technology leadership in meeting risk, cyber and assurance standards
- Oversee third and fourth parties so compliance and resilience controls remain robust
- Monitor the cyber and information security controls that protect data assets and satisfy regulatory requirements
- Watch the changing cyber threat landscape and challenge the operating model to keep data resilient
- Contribute to continued ISO
27001 accreditation and the security standards set out in the ICT strategy - Drive cyber due diligence across key service providers, advising contract managers so suppliers operate to agreed levels of security
- Support operational resilience activity wherever technology risk, information security, supplier oversight or ICT controls are involved
- Identify and escalation risk across your area of responsibility
- A strong understanding of technology and infrastructure risk: information security, cloud, third party and resilience
- Working knowledge of regulatory and audit expectations, including FCA, ISO
27001, outsourcing and operational resilience, and how to evidence compliance - A clear grasp of the three lines of defence model, operating comfortably across first line delivery and second line oversight
- Demonstrable experience in technology risk, information security, ICT governance, audit or assurance within demanding, complex business environments
- A track record of assessing technology controls and tracking remediation through to closure
- Familiarity with internal and external audit, producing…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).