Job Title: Risk Lead
Work Location: Hybrid 2 days in office at Cambridge
Role Description:
-
Establish an Exam Technology Risk Management process that integrates nonproject risk with Corporate Risk reporting ensuring compliance and positioning Exam Technology as the preferred IT service supplier to Product Groups.
-
Collaborate with senior leads across CUP&A technology to promote best practices with practical implementation.
-
Work closely with Solution Area leadership teams to proactively manage all categories of IT Risk related to highstakes assessment products.
-
Support the organizations regulatory position by ensuring compliance with the Ofqual C1 condition and risk management frameworks.
-
Act as the Risk Champion within Exam Technology working with the Technical Responsible Officer (TRO) Head of Exam Assurance and leadership teams to identify manage and remediate IT risks.
-
Although focused on highstakes exam products the risk management outputs may be extended to mid and lowstakes assessment products.
Key Responsibilities:
-
Develop implement and manage Exam Technologys Risk Management framework strategies and procedures.
-
Design develop and manage realtime risk strategies.
-
Identify risk across highstakes assessment products and services.
-
Provide preventive instructions identify controls and propose solutions for violations.
-
Investigate and review actual or potential failures in businesscritical controls and processes.
-
Engage with thirdparty investigations (e.g. ISO 9001) and auditors to meet external requirements.
-
Lead risk assessment campaigns assurance reviews and produce risk assessment reports.
-
Assist in designing and launching new highstakes products from a risk perspective.
-
Lead and maintain risk evaluation processes supporting Group Wide Risk reporting.
Key Skills / Knowledge / Experience:
Essential Knowledge:
-
Familiarity with risk management frameworks: ISO 31000 NIST COSO
-
Knowledge of integrated risk and quality management systems
-
Understanding of cybersecurity fundamentals including threat modelling and incident response
-
Knowledge of incident management processes
-
Awareness of regulatory and audit requirements for IT risk and controls (e.g. GDPR)
-
Understanding of IT infrastructure: networks servers databases cloud services
Essential Skills and Experience:
-
Knowledge of risk and quality management systems
-
Ability to quickly assimilate and analyze complex technical information
-
Excellent written and verbal communication skills
-
Strong interpersonal negotiation and influencing skills
-
Confident presenting to senior audiences
-
Tact and diplomacy
-
Ability to work under pressure
-
Excellent judgment and strategic decisionmaking
-
Experience in technology environments
-
Background in the assessment sector
-
Experience working with senior management exercising autonomous judgment
-
Strong influencing skills
Person Specification:
-
Negotiating skills
-
Clientfacing experience
-
Excellent communication
-
Leadership experience