About the job
Join our dynamic team as a Technology Risk & Resilience Manager in Dublin, where you will play a crucial role in the second line of defense for risk management. This position offers the opportunity to:
- Deliver independent oversight and constructive challenge on Technology Risk, including Information Technology and Information Security, ensuring seamless integration into the firm’s overarching Risk Management Framework, aligning with DORA, third-party risk, and service resilience standards.
- This role will evaluate, critique, and provide assurance regarding the identification, management, and reporting of technology risks by the first line of defense, without directly managing technology risk controls.
Key Responsibilities
Second Line Oversight & Framework Integration
- Define and integrate Technology Risk (IT & Information Security) within the Operational Risk Taxonomy, clearly documenting the responsibilities of the first and second lines of defense in accordance with governance models.
- Provide independent second line oversight of the Technology Risk Management Framework, ensuring its alignment and interdependence with first-line control frameworks, including Third-Party Risk Management, IT Controls, and Cybersecurity.
- Enhance the understanding of technology risk through consistent service-based assessments of applications, infrastructure, and third-party ICT services in relation to internal and client-facing business services.
Risk Identification, Assessment & Challenge
- Critically review the first line’s identification and assessment of technology risks, including application risk, infrastructure dependencies, information security risks, and third-party technology dependencies, ensuring alignment with the company's risk taxonomy and regulatory standards.
- Evaluate the quality and consistency of Technology Risk Registers, control inventories, incident remediation efforts, and impact analyses.
- Provide credible challenge where risk assessments, severity ratings, or residual risk conclusions lack adequate support.
Operational Resilience
- Facilitate the integration of technology risk into the firm’s Operational Risk & Resilience frameworks, ensuring compliance with regulatory standards, including:
i) Mapping technology dependencies to critical business services
ii) Assessing ICT/technology-related incidents and their materiality
iii) Ensuring proper incident classification and escalation in line with reporting standards, capturing both technical and operational impacts on incident reporting platforms.
