About the role
What will you do at Yammer?
Effective technology strategy and governance. Define the entity's technology strategy within an outsourced operating model, ensuring alignment with regulatory expectations, Group architecture, and business objectives. Establish the governance forums, standards, and decision rights needed to direct and challenge technology delivered on the entity's behalf.
Lead DORA and ICT risk management. Own the ICT risk management framework in line with the Digital Operational Resilience Act (DORA), including ICT risk identification and assessment, control design and validation, and oversight of outsourced ICT services. Maintain the ICT third-party register and ensure contractual, security, and control requirements are met and evidenced.
Build and run the technology operational resilience framework. Lead resilience planning — including impact tolerances, dependency mapping, and scenario testing — so that critical payment services can withstand, respond to, and recover from disruption within agreed tolerances. Hold regulatory accountability for technology.
Support technology-related inspections, audits, and regulatory submissions to the CBI and other applicable authorities, providing clear, evidenced responses on ICT risk, security, and resilience. Oversee ICT incidents and escalation. Ensure major ICT incidents are appropriately managed by providers, with independent internal assessment, timely escalation, and regulatory notification in line with DORA and CBI requirements.
Drive root cause analysis and confirm remediation is completed and sustained. Report to the Board and its committees. Deliver clear, decision-ready reporting on technology risks, resilience posture, and provider performance to the Board and relevant committees, using data and storytelling to adapt to audience and business need.
Provide change and architecture assurance. Provide oversight and constructive challenge on material technology changes delivered by the Group or vendors, ensuring change risk is assessed, resilience impacts are understood, and security and privacy principles are incorporated into planning. Partner across the entity and FD&E.
Team closely with the Operational Risk & Resilience Manager so that technology and business resilience are managed as one joined-up picture, and partner with Risk, Compliance, and Internal Audit. Working proficiency in a second European language is desirable but not required; all working communications can be conducted in English.
Required: A Bachelor's degree in Computer Science, Engineering, Information Systems, Business, or a related field, and relevant experience in technology risk, ICT or operational resilience, IT service management or technical program management; OR equivalent professional experience in lieu of the qualification.
Demonstrated experience leading complex technology risk, ICT resilience or IT governance programs end to end within a large, complex organisation, including control design, KPI design, service delivery management, and risk and remediation reporting to senior management. Proven ability to engage credibly with senior stakeholders, regulators or external auditors, with the ability to communicate complex technical, architectural and risk concepts clearly to non-specialist audiences.
Make your next move
Build a shortlist and prepare
Identify the requirements you can demonstrate, then choose examples from your work to discuss with the hiring team.
- Build a focused shortlist before you applyCompare role requirements with your experience and give each application a clear reason.
- Practice explaining your experience in an interviewRehearse your answers before meeting the hiring team.
Role information can change. Prepin can help you prepare, but does not submit an application for this role.