Bupa Logo

Bupa

IT Risk & Control Assurance Manager

Posted 13 Days Ago
Be an Early Applicant
2 Locations
Mid level
2 Locations
Mid level
The IT Risk & Control Assurance Manager oversees risk management in IT and Information Security, ensuring compliance and control in regulated financial services.
The summary above was generated by AI

Job Description:

IT Risk & Control Assurance Manager

London, Staines or Brighton - (or Across UK Locations)

Hybrid Working + Flexible

Permanent

From £60,300pa (dependant on location and experience) and fantastic benefits

Full time - 37.5 hours

Here you’ll be welcomed. We champion diversity and we understand the importance of our people representing the communities and customers we serve. You’ll find an inclusive environment where you can be yourself and where everyone is driven by the same purpose – helping people live longer, healthier, happier lives and making a better world.

We make health happen

This role will be part of a team of four peers working across the BGIUK Market Unit under the guidance of a Head of IT Risk and Control with the primary purpose to support the identification, articulation, assessment and ongoing management of Information Security and Technology Management Risks and Controls for each Business Unit (UKI, BG, Care, Clinics, Dental, Cromwell and Enterprise Platforms). Regularly reporting Risk, risk appetite position and the status of all mitigating controls to both Business and Technology risk committees as appropriate.

The scope of this role covers all Technology Risks; IT Strategy and Architecture, Service Management/Stability, Capacity/Capability Management, Disaster Recovery and Crisis Management. This role will also integrate the output from the Information Security Risk and Transformation Risk teams into the overall risk reporting for each Business Unit.

You’ll help us make health happen through:

  • Interpreting and communicating to the Business Unit changes to Risk Polices, Business/IT Strategy, legislation that impact the existing Risk and Control Framework.
  • Identifying and assessing Technology Management and Information Security issues so that control environments are properly defined and residual risk regularly assessed.
  • Developing and managing the execution of the controls assurance plan.
  • Overseeing the team conducting the control testing for the relevant business unit (i.e., the IT Risk & Control testing specialists and testing analysts)
  • Supporting Business Unit (BU) and IT management in the design of key controls to mitigate identified issues and reduce residual risk.
  • Regular reporting of BU IT Risks and Risk Appetite position to local risk committees, Market Unit (MU) Technology Risk Committee as well contributing to relevant committee and Board papers as required.
  • Work with the Risk, Control and Processes owners to develop a trusted and robust set of process, risk and control metrics to allow risks, controls and issues to be continuously monitored.

Key Skills needed for this role:

  • Experience of managing Information Security and Technology Risk and Controls in a regulated financial services company is essential.
  • Understanding of the risks and controls inherent in all technologies including Cloud Services and Deployment Models
  • The ideal candidate would have formal training and hands-on experience of designing, operating or auditing IT Controls.
  • Experience of design and implementation of control automation and continuous monitoring would be useful but not essential.
  • Demonstrable experience in Information Technology audits or IT Assurance (e.g., CISSP, CISM, CISA, CRISC, CCAK)
  • A sound understanding of British and International Security Standards (e.g., ISO/IEC 27001, ISO/IEC 27002, NIST, CIS-20, PCIDSS) and the UK regulatory environment (e.g., ICO, FCA, PRA and CQC).

Benefits

Our benefits are designed to make health happen for our people. Viva is our global wellbeing programme and includes all aspects of our health – from mental and physical, to financial, social and environmental wellbeing. We support flexible working and have a range of family friendly benefits.

  • 25 days holiday, increasing through length of service, with option to buy or sell
  • Bupa health insurance as a benefit in kind
  • An enhanced pension plan and life insurance
  • Onsite gyms or local discounts where no onsite gym available
  • Various other benefits and online discounts

Bupa

We’re a health insurer and provider. With no shareholders, our customers are our focus. Our people are all driven by the same purpose – helping people live longer, healthier, happier lives and making a better world. We make health happen by being brave, caring and responsible in everything we do.

We encourage all of our people to “Be you at Bupa”, we champion diversity, and we understand the importance of our people representing the communities and customers we serve.  That’s why we especially encourage applications from people with diverse backgrounds and experiences.

As a Disability Confident employer, we offer a guaranteed interview for every disabled applicant who meets the minimum criteria for the job. We’ll make sure you are treated fairly and offer reasonable adjustments as part of our recruitment process to anyone that needs them.

Time Type:

Full time

Job Area:

Legal, Risk & Audit

Locations:

Angel Court, London, Staines - Willow House

Top Skills

Cis-20
Cloud Services
Iso/Iec 27001
Iso/Iec 27002
Nist
Pcidss

Similar Jobs

13 Hours Ago
London, Greater London, England, GBR
Mid level
Mid level
Fintech • Mobile • Payments • Software • Financial Services
As a Senior Presales Consultant at Wise, you will drive growth by consulting with product, sales, and delivery teams, understanding customer needs, and designing scalable payment solutions for partners. You'll present product value to executives, contribute to sales strategies, and analyze requirements while collaborating with financial institutions.
Top Skills: Local Payment NetworksRest ApisSwift
18 Hours Ago
Hybrid
London, Greater London, England, GBR
Senior level
Senior level
Financial Services
Lead cybersecurity assessments and exercises, oversee team operations, develop strategic plans, manage risks and improve resilience across the organization.
Top Skills: CC#C++DlpEdrFirewallsIds/IpsJavaPerlPythonRubyWeb Proxies
18 Hours Ago
Hybrid
London, Greater London, England, GBR
Senior level
Senior level
Financial Services
Lead the transformation of the technology controls catalogue, enhancing risk management and compliance across the organization through strategic innovation and stakeholder engagement.
Top Skills: Application ArchitectureInformation Security PrinciplesInfrastructure

What you need to know about the Edinburgh Tech Scene

From traditional pubs and centuries-old universities to sleek shopping malls and glass-paneled office buildings, Edinburgh's architecture reflects its unique blend of history and modernity. But the fusion of past and future isn't just visible in its buildings; it's also shaping the city's economy. Named the United Kingdom's leading technology ecosystem outside of London, Edinburgh plays host to major global companies like Apple and Adobe, as well as a growing number of innovative startups in fields like cybersecurity, finance and healthcare.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account