Overview
Lead third-party and intra-group risk management. Lead day-to-day oversight of third-party and intra-group service provider risks, including risk assessments, due diligence support, performance monitoring, issue management, and escalation of material concerns. Coordinate the operational resilience programme. Coordinate the operational resilience framework across the entity, including identification of important business services, mapping of supporting processes and dependencies, and assessment of vulnerabilities. Ensure operational resilience remains aligned with Digital Operational Resilience Act (DORA) requirements. Run scenario testing and resilience validation. Support the design and execution of resilience testing and scenario exercises to assess the entity's ability to remain within impact tolerances during disruption, and drive remediation of the gaps those exercises reveal. Own b
Full job description
Full Job Description
Lead third-party and intra-group risk management. Lead day-to-day oversight of third-party and intra-group service provider risks, including risk assessments, due diligence support, performance monitoring, issue management, and escalation of material concerns. Coordinate the operational resilience programme. Coordinate the operational resilience framework across the entity, including identification of important business services, mapping of supporting processes and dependencies, and assessment of vulnerabilities. Ensure operational resilience remains aligned with Digital Operational Resilience Act (DORA) requirements. Run scenario testing and resilience validation. Support the design and execution of resilience testing and scenario exercises to assess the entity's ability to remain within impact tolerances during disruption, and drive remediation of the gaps those exercises reveal. Own business continuity planning. Own the development, maintenance, and testing of business continuity and recovery plans for operations, ensuring plans remain current, practical, and aligned to outsourced service dependencies. Align frameworks to Enterprise Risk Management. Support the second line in ensuring alignment of the operational resilience, DORA, and business continuity management frameworks with the firm's Enterprise Risk Management Framework and Risk Register. Perform risk and control assessments across operational processes, including third-party dependencies, identifying gaps and driving timely remediation. Manage incidents and lessons learned. Track operational incidents, service disruptions, and third-party failures, ensuring root cause analysis, remediation actions, and lessons learned are captured and embedded. Deliver regulatory, executive, and Board reporting. Ensure the timely, accurate and complete production and delivery of regulatory reporting to the CBI and other applicable authorities. Consolidate reporting across operational functions into structured reporting packs for the Executive Committee and the Board, and develop and operationalise new reporting requirements as requested. Design and implement operational dashboards and analytics frameworks to provide insight into operational performance, risk indicators, and resilience metrics. Support audits and regulatory reviews. Support audits, regulatory reviews, and inspections by providing clear evidence of control and oversight across operational and outsourced activities. Partner across the entity and FD&E. Team closely with the IT Operational Resilience Manager so that business and technology resilience are managed as one joined-up picture, and partner with Risk, Compliance, and Internal Audit. Bachelor's Degree in Business, Operations, Risk, Finance, or related field AND relevant experience in operational risk, third-party risk, operational resilience, or business continuity OR equivalent experience Master's Degree in Business, Operations, Risk, Finance, or related field AND 6+ years experience in operational risk, third-party risk, operational resilience, or business continuity OR Bachelor's Degree in Business, Operations, Risk, Finance, or related field AND 8+ years experience in operational risk, third-party risk, operational resilience, or business continuity OR equivalent experience. Prior experience supporting audits, regulatory reviews, or inspections in a regulated environment. Prior experience in financial services, payments, technology, cloud services or online platforms sectors. Exposure to operational resilience or third-party risk management in regulated industries, CBI requirements, or PSD2.
Tips for this job
Practical Job and Scholarship guidance. These tips do not replace official rules or create new eligibility requirements.
- Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
- Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
- Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
- Apply through the original employer or official recruitment destination shown on this page.
Verification notes
Verified from public schema.org JobPosting structured data on the official source page. The complete published description, responsibilities, requirements and benefits were normalized when present; unstated facts were not inferred.
Job and Scholarship is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.
Microsoft Opportunities ↗Browse current Job and Scholarship listings from Microsoft Opportunities →