Information risk plays an important role in protecting the firm, its clients and its information while enabling the responsible use of technology and innovation. The Information Risk team provides specialist oversight, advice and challenge across cyber and information security, technology, data privacy, artificial intelligence (AI) and other emerging technologies.
Purpose of RoleAs Information Risk Senior Manager, you will oversee these information risk categories in accordance with the firm's risk management framework and lead the Information Risk team. You will work with departments across the firm to build effective relationships and act as a trusted adviser, with client and regulatory expectations underlining the importance of the role.The role combines team leadership with strong technical and risk-management credibility. You will lead the firm's information risk assurance programme, oversee key frameworks and policies including ISO 27001 certification, contribute to cyber incident response, and provide clear advice and challenge on material technology change, AI and other emerging technologies.Responsibilities
Information Risk Leadership
- Oversee multiple information risk categories, including cyber and information security, technology, AI and data privacy risks, in accordance with the firm's risk management framework.
- Lead the firm's information risk assurance programme, including penetration testing, security and cyber resilience exercises, and other assurance activities across infrastructure, cloud services, applications, identity and access, data flows and third parties.
- Oversee the quality and efficiency of information risk activities and the associated risk management framework, policies and procedures, including the firm's ISO 27001 certification.
Leadership of the Information Risk team
- Lead the Information Risk team and agree its delivery plan with the Head of Business Risk. Allocate responsibilities and resources; coach and develop colleagues; manage performance and succession; and build a collaborative, high-trust team environment.
- Provide clear direction and support across the team, ensuring activity is prioritised effectively and that specialist expertise is used to provide high-quality advice, challenge and assurance.
- Contribute to other activities across the Business Risk Department to help the Department achieve its business plan objectives and support effective cross-team working.
Governance, insight and decision support
- Oversee reporting to relevant committees and internal or external boards on information risk matters, including contributing as a member of relevant committees and groups.
- Collaborate with the wider Business Risk Department and develop strategic relationships with other departments, ensuring information risk activity is aligned with the firm's risk appetite and wider priorities.
- Contribute to and continually improve the Cyber Security Incident Response Team, supporting effective preparation, response and learning from cyber security incidents.
Future capability
- Assess the security implications of AI and material business or technology change, working with delivery teams on proportionate controls and validating evidence of effectiveness rather than relying solely on documented intentions.
- Continue to develop information risk frameworks, policies and procedures to support the safe, secure and responsible adoption of AI and other emerging technologies.
What success looks like
- Trusted adviser: The Information Risk team is recognised as a credible and pragmatic source of specialist advice and challenge, helping colleagues make informed decisions within risk appetite.
- Effective risk oversight: Material cyber, technology, AI and data privacy risks are identified, assessed and communicated clearly, with proportionate action taken where exposures require improvement.
- High-quality assurance: The information risk assurance programme provides useful, evidence-based insight through penetration testing, security and cyber resilience exercises, and other targeted assurance activity.
- Strong governance: Information risk frameworks, policies, ISO 27001 arrangements and reporting remain effective, proportionate and responsive to client, regulatory and business expectations.
- High-performing team: The Information Risk team is collaborative, well prioritised and empowered, with strong specialist capability, clear accountability and meaningful development opportunities.
- Future-ready capability: The firm can adopt AI and other emerging technologies with confidence because information risks are understood and proportionate safeguards are embedded as technology and business models evolve.
Your knowledge and experience
- Relevant information security and/or technology qualifications, together with substantial experience in cyber or information security functions or roles with significant cyber/information security responsibilities.
- Experience using the NIST framework and applying structured risk or security frameworks to assess and manage information risk.
- Strong knowledge of and interest in cyber and information security, including current threats, trends, developments and emerging technologies, with an understanding of technology and data protection risks.
- Experience leading and developing others, with the credibility and communication skills to engage confidently with internal and external stakeholders on complex information risk matters.
The type of candidate that we're looking for
We are looking for an experienced and engaging information risk, cyber security or technology risk professional who can lead a specialist team and help shape how the firm manages a broad and rapidly evolving range of information risks. This is a varied role spanning cyber and information security, technology risk, AI and other emerging technologies, data privacy and assurance, with the opportunity to influence both day-to-day risk management and the firm's longer-term approach to technology and innovation. The successful candidate will bring strong technical and risk-management credibility, but equally important will be their judgement and ability to see the broader business context. They should be comfortable getting into the detail when required, while also being able to step back, identify the issues that matter most and translate complex technical risks into clear advice for senior stakeholders, committees and boards.
This role would suit someone who enjoys leading and developing others. They will create an environment where colleagues are trusted and empowered to take ownership, while providing clear direction, coaching and constructive challenge. They should be able to bring together different areas of expertise across the team, set priorities effectively and maintain high standards across a varied portfolio of work. We are particularly interested in someone who is curious about how technology is changing and what that means for the firm. They should have an interest in AI and other emerging technologies, build trusted relationships across the firm, provide independent challenge where needed, and continually improve how information risk is assessed, monitored and communicated.
Critical skills
- Nurture relationships
- Adaptability
- Enabling others
- Systems thinking
- Storytelling
Closing DateOctober 9, 2026
Should you choose to use AI tools to support your application, we ask that you do this thoughtfully. We encourage you to ensure your application reflects your own voice, experience, and motivations. We value authenticity and want to understand your individual strengths and perspectives.
At Baillie Gifford, we are committed to fostering an inclusive and respectful culture in which each of our colleagues can thrive and develop. We believe that our clients are best served by a diverse workforce with the experiences, ideas and perspectives that this brings.
If you are currently working at Baillie Gifford as an employee or contractor please apply to this job from the firm's Workday internal career site.


