About the Role
The Enterprise Technology Risk Management (ETRM) organization, as a Second Line of Defense, is responsible for thought leadership, oversight, monitoring, and advisement around the discovery and remediation of Technology Risk and Cybersecurity Risk. This role is critical to establishing a world-class Technology and Cyber Risk Management Oversight program that aligns business and technology strategies for effective decision-making.
Responsibilities
- Lead and support functions within the ETRM Service Catalogue, including real-time risk oversight, technology targeted risk assessments, Material Risk Identification, Regulatory Audit and Client Engagements, and Risk Reporting.
- Advise and/or support on technology risk and regulatory matters for the EMEA community.
- Collaborate with ETRM Risk professionals to align with broader Enterprise / Operational Risk Management Programs and mandates at global level.
- Develop and maintain EMEA relationships with Business and IT stakeholders.
- Partner with EMEA ERM team to assure the firm’s technology risks and non-compliance are proactively identified, prudently managed (monitored and effectively challenged).
- Develop effective communication channels for measuring and escalating technology risk exposure.
- Evaluate IT Security risks arising from control inefficiencies in EMEA Legal Entities (LE).
- Ensure reporting is properly balanced between perspectives of global ETRM opinion and the local Authorities.
- Participate in due diligence for new clients, vendors and M&A activities.
- Monitor emerging technology risks and trends in financial services.
- Deliver assignments and projects independently and on time.
- Prepare presentations for Management, Risk committees and Board meetings.
- Oversee governance, policy and framework execution across the EMEA region, ensuring alignment with global frameworks.
- Support the development of technology risk oversight and embed the ETRM and practices.
- Oversee communication with EMEA regulators in alignment with the ETRM program.
- Report with appropriate and timely information for the committees/Boards to effectively discharge their responsibilities.
- Foster a culture of effective challenge throughout the organization.
- Provide consulting on technology risk management and ongoing guidance aligned with ETRM strategy.
- Stay informed on regulatory developments and their impacts on State Street in EMEA.
- Conduct training on technology risk management.
Requirements
- Over 10 years of experience in the financial services or technology sectors.
- Exceptional interpersonal and communication skills.
- Ability to convey technology risks to non-technical audiences.
- Strong initiative, ability to perform well under pressure, and manage multiple diverse assignments.
- Prior experience with EMEA regulators (e.g., PRA, FCA and ECB) is highly desired.
- Experience in Cyber and Information Security, Cloud Risk Management (AWS, Azure), and Technology and Operational Resilience is required.
- In-depth knowledge of EMEA Technology Regulatory Requirements (e.g., FCA, PRA, ECB); Experience with regulatory exams and responses is strongly desired.
- Experience in EEA regulations such as DORA, BCBS 239 and the EU AI Act.
- Experience in IT audits or risk assessments, Information Technology General Controls (ITGC) and cybersecurity controls.
- Familiarity with Information Security Frameworks (e.g., NIST, ISO 27000, CSA Cloud Control Matrix) and ITIL practices.
- Experience in AI adoption and AI risk management.
- Ability to articulate technical issues to non-IT stakeholders and business perspective to IT stakeholders.
- Strong communication, negotiation, and presentation skills, with cross-cultural competencies.
- Strong project management, critical thinking, problem-solving, and decision-making abilities.
- Experience in IT risk management, compliance or audit, including control framework design & implementation.
- Experience with data analytics and GRC tools, including Tableau and Power BI, is a plus.
Skills
- Cyber and Information Security
- Cloud Risk Management (AWS, Azure)
- Technology and Operational Resilience
- EMEA Technology Regulatory Requirements
- Regulatory exams and responses
- EEA regulations (DORA, BCBS 239, EU AI Act)
- IT audits
- Risk assessments
- Information Technology General Controls (ITGC)
- Cybersecurity controls
- Information Security Frameworks (NIST, ISO 27000, CSA Cloud Control Matrix)
- ITIL practices
- AI adoption
- AI risk management
- Communication
- Negotiation
- Presentation
- Cross-cultural competencies
- Project management
- Critical thinking
- Problem-solving
- Decision-making
- IT risk management
- Compliance
- Audit
- Control framework design & implementation
- Data analytics
- GRC tools (Tableau, Power BI)
Location
- London
- Dublin
Work Type
- Hybrid
Experience Level
- 10+ years
Education Level
- Undergraduate or advanced degree in a technology discipline
Benefits
- Inclusive development opportunities
- Flexible work-life support
- Paid volunteer days
- Vibrant employee networks
About the Company
- Enterprise Technology Risk Management (ETRM) organization is part of Enterprise Risk Management organization in State Street Corporation (SSC).
- ETRM as Second Line of Defence (SLOD) is responsible for thought leadership, oversight, monitoring, and advisement around the discovery and remediation of Technology Risk and Cybersecurity Risk.
- Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability.
- We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.
- We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential.
- As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most.
- Join us in shaping the future.
Equal Opportunity
- As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.
