MUFG Investor Services Logo

MUFG Investor Services

Technology Risk & Resilience Manager (Second Line)

Posted 7 Days Ago
Be an Early Applicant
Hybrid
Dublin, IRL
Expert/Leader
Hybrid
Dublin, IRL
Expert/Leader
Provides independent second-line oversight and challenge of technology, information security, third-party, and operational resilience risks. The role assesses risk frameworks, registers, controls, incidents, change activities, vendor dependencies, and regulatory alignment, including DORA. It prepares governance reporting, supports resilience testing and risk appetite oversight, and translates technical risk into business insights for senior stakeholders across regulated financial services.
The summary above was generated by AI
Company Description

MUFG Investor Services is a trusted partner to many of the world’s largest public and private funds, providing asset servicing and operational solutions built for alternatives. With over $1 trillion in client assets under administration, we offer fund administration, banking, payments, fund financing, foreign exchange overlay, corporate and regulatory services, custody, business consulting, and more. Operating from 17 locations worldwide, we help clients mitigate risk, enhance efficiency, and navigate the operational complexities of today’s investment management landscape. As a division of Mitsubishi UFJ Financial Group (MUFG), one of the world’s largest financial institutions with approximately $3 trillion in assets, we combine deep expertise with the strength and stability of a leading financial institution. To learn more, visit us at www.mufg-investorservices.com.

Job Description

We're looking for an experienced Technology Risk & Resilience Manager to join our second line risk in London, United Kingdom or Dublin, Ireland. In this pivotal role, you will:

  • Provide independent second line oversight and credible challenge of Technology Risk (Information Technology and Information Security) within the firm, ensuring effective integration of technology risk into the overarching second line Risk Management Framework, including alignment with DORA, third-party risk, and service resilience expectations.
  • The role will not own or operate technology risk controls, but will assess, challenge, and provide assurance over how technology risks are identified, managed, and reported by the first line.

Key Roles & Responsibilities

Second Line Oversight & Framework Integration

  • Define and embed Technology Risk (IT & Information Security) appropriately within the Operational Risk Taxonomy and Framework, ensuring clear, documented delineation of 1LOD vs 2LOD accountability in line with company’s governance models.
  • Provide independent 2LOD oversight of the Technology Risk Management Framework, assessing its alignment and interdependency with first-line control frameworks (e.g. Third-Party Risk Management, IT Controls, Cybersecurity, etc.) and ensuring coherence with second line Operational Risk and Resilience frameworks.
  • Support the maturation of a consistent service-based view of technology risk by challenging 1LOD mapping of applications, infrastructure and third-party ICT services to internal and client-facing business services.

Risk Identification, Assessment & Challenge

  • Review and challenge first line identification and assessment of technology risks, including (i) application risk (ii) infrastructure dependencies (iii) information security risks and (iv) third-party technology dependencies, ensuring consistency with the company’s risk taxonomy and regulatory expectations.
  • Assess the quality, completeness, and consistency of Technology Risk Registers, control inventories, incident remediation activities and impact analysis.
  • Provide credible 2LOD challenge where risk assessments, severity ratings, or residual risk conclusions are not sufficiently supported.

Operational Resilience

  • Support integration of technology risk into the firm’s Operational Risk & Resilience frameworks, including regulatory/jurisdictional aligned frameworks including:

i) mapping of technology dependencies to important business services

ii) assessment of ICT/technology-related incidents and materiality thresholds

iii) align on incident classification and escalation decisions with reporting standards ensuring impacts both technically and operationally are appropriately assessed and captured on associated incident reporting portals.

  • Provide second line review and challenge of technology related incidents, including severity, client impact, and regulatory reporting considerations.
  • Contribute and support with resilience testing and scenario analysis from a technology dependency perspective.

Third Party & Technology Dependency Risk

  • Provide 2LOD oversight of technology-related third-party risks, ensuring:

i) appropriate risk identification where services rely on externally procured applications or infrastructure

ii) alignment between Technology Risk and Third-Party Risk Management outcomes

  • Review dependency and concentration risk associated with critical technology vendors.

Change & Control Environment Oversight

  • Provide oversight and challenge of technology-related change activities, including:

i) IT BAU change, including change risk assessments and post-implementation validations

ii) technology elements of business change

iii) changes impacting critical services or client-facing platforms

  • Conduct thematic reviews of incidents, audit findings, or control weaknesses, and assess whether these indicate systemic risk or control gaps.

Governance & Reporting

  • Draft and peer review committee papers and support where required the delivery of periodic reporting to management and governance forums.
  • Deliver on annual requirement to report and present the second line technology framework (i.e. annual DORA attestation) as well as contribute risk reporting on technology risk themes for senior management and risk committees.
  • Translate technical risk information into clear, business-relevant risk insights for non-technical stakeholders.
  • Support the Head of Risk in setting, monitoring, and challenging technology-related risk appetite. Stakeholder Engagement & Collaboration:
  • Partner with senior first line leaders and control functions to embed risk and resilience principles in business planning and oversee and support the development of technology risk reporting. ·
  • Candidate should be comfortable facing challenges from CISO/CIO/CTO levels in addition to demonstrated ability to manage relationships within a parent company structure involving cross-collaboration within Risk, such as Enterprise, Data, Operational Risk & Resilience.

 

Qualifications

Education Requirements

  • Post-secondary degree in technology, business or a related discipline plus qualification in CRISC, CISSP, CISM
  • Fluency with frameworks such as NIST CSF, ISO 27001 / 27002, COBIT to facilitate an oversight role
  • Professional qualification in risk or a related discipline would be preferred but not essential

Work Experience

  • 10+ years’ experience operating in a second line or independent risk oversight role overseeing Technology Risk, IT Risk, Cyber Risk in a financial institution or compatible industry
  • Experience within governance, oversight programs of IT Architecture, Application and EUC development and deployment
  • Strong knowledge of: (i) technology risk concepts (ii) information security risk (iii) third-party technology risk (iv) operational resilience principles (v) corporate insurance 
  • Familiarity with information management frameworks through the lens of technology risk (inclusive of cyber and information security)
  • Experience engaging credibly with senior technology and business stakeholders
  • Strong written and verbal communication skills, particularly in translating technical issues into business risk

Functional/Technical Skills and Knowledge Requirements

Essential

  • Experience with DORA, operational resilience, or similar regulatory regimes
  • Experience working in fund services, asset servicing, or regulated financial services
  • Exposure to multi-entity or cross-jurisdictional regulatory environments (e.g. Ireland / Cayman)
  • Proactive, solution-oriented mindset with the ability to work effectively in a fast-paced environment.
  • Advanced proficiency in Microsoft Excel and experience of onboarding new systems / technology are preferred
  • Strong IT skills with strengths in Microsoft Office products

Preferred

  • Proficiency in Power BI, Tableau, and Power Apps for data visualisation and dashboard creation.
  • Experience with Excel, SharePoint, and Microsoft 365 tools for workflow automation

Additional Information

Take a look at our careers site and you’ll find everything you’d expect from a career with the fastest-growing business at one of the world’s largest financial groups. Now take another look. Because it’s how we defy expectations that really defines us. You’ll feel that difference in all kinds of ways.  Our vibrant CULTURE. Connected team. Love of innovation, laser client focus, and next-level LEARNING & DEVELOPMENT.     

So, why settle for the ordinary?  Apply now for a Brilliantly Different career.   

We thank all candidates for applying; however, only those proceeding to the interview stage will be contacted. 

Similar Jobs

2 Hours Ago
Hybrid
2 Locations
Junior
Junior
Financial Services
Oversee daily, weekly, monthly, and ad hoc NAV production for alternative investment funds. Calculate and validate NAVs, investigate valuation movements and breaks, maintain controls, remediate risks, support audits and client due diligence, coordinate cross-functional teams, and improve operating processes. The role also involves stakeholder and client relationship management, governance support, and resource planning.
Top Skills: Alternative Investment Fund StructuresComplex Financial InstrumentsNav Calculation
2 Hours Ago
Hybrid
2 Locations
Entry level
Entry level
Financial Services
Manage end-to-end administration for private equity and debt funds, including accounting, audits, financial reporting, capital calls, distributions, investor statements, and client servicing. The role also oversees controls, change management, process improvements, data governance, and issue escalation while maintaining relationships with fund stakeholders and supporting reporting under US, Luxembourg, UK GAAP, and IFRS.
Top Skills: AlteryxArcesiumFis Investran
3 Hours Ago
In-Office
Grange, Ballyboughal, Dublin, IRL
Entry level
Entry level
Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
A 23-month rotational graduate programme at Pfizer’s Grange Castle biopharmaceutical manufacturing site. Graduates rotate across three business functions, gaining experience in biotechnology manufacturing and related science or engineering disciplines. Applicants must hold or be completing a Level 8 or Level 9 qualification, be available to start in September 2027, and be legally eligible to work in Ireland.
Top Skills: Biotechnology

What you need to know about the Dublin Tech Scene

From Bono and Oscar Wilde to today's tech leaders, Dublin has always attracted trailblazers, with more than 70,000 people working in the city's expanding digital sector. Continuing its legacy of drawing pioneers, the city is advancing rapidly. Ireland is now ranked as one of the top tech clusters in the region and the number one destination for digital companies, with the highest hiring intention of any region across all sectors.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account