Overview
The Technology Risk & GRC Lead will oversee governance, risk management, compliance, and cyber security within a complex enterprise environment. Collaborating with teams across Technology, Cyber Security, Finance, and Digital, the role focuses on enhancing governance and control measures while implementing effective risk management practices. This position demands a strategic and pragmatic approach, with opportunities to engage with senior leadership and influence key initiatives.
Responsibilities
- Lead and coordinate technology risk, governance, and compliance activities across business and technology functions.
- Establish and enhance risk management frameworks, policies, standards, controls, and reporting processes.
- Facilitate risk assessments and control reviews across IT, cyber security, SAP, operational, and third-party environments.
- Drive compliance activities aligned with regulatory, legal, and industry requirements.
- Support internal audits, external audits, assurance reviews, and remediation programmes.
- Monitor control effectiveness and oversee corrective action plans.
- Partner with Cyber Security and Digital teams to strengthen security governance and technology risk management.
- Provide governance oversight across SAP and wider technology transformation programmes, including access governance and Segregation of Duties controls.
Requirements
- Proven experience as a Technology Risk Lead, GRC Lead, IT Risk Manager, or similar.
- Strong background in governance, risk management, compliance, audit, technology assurance, or cyber security governance.
- Experience operating across multiple business functions within complex enterprise environments.
- Strong understanding of risk registers, controls frameworks, policy management, and assurance processes.
- Knowledge of recognised frameworks such as ISO 27001, NIST, COBIT, or ITIL.
- Experience supporting large-scale technology, ERP, or SAP transformation programmes.
- Excellent stakeholder management, communication, and influencing skills.
- Desirable certifications include ISO 27001, CISSP, CISM, CISA, or similar.