Description
Our purpose is to make great financial decision making a breeze for everyone, and that purpose drives us every day.
It’s why we’re on a mission to create an automated quoting engine, with the simplest of experiences, wrapped in a brand everyone loves!
We change lives by making it simple to switch and save money and that’s why good things happen when you meerkat.
We’d love you to be part of our journey.
Lead the operation of Technology’s First Line of Defence. Responsible for ensuring risk management is executed effectively - risks are identified and reported, controls are tested, issues are tracked, and Technology’s regulatory and policy obligations are met. Responsible for improving and modernising how risk is managed across Technology. This includes shifting from manual, reactive processes to more embedded, automated, and real-time approaches. As technologies like GenAI and cloud-native platforms accelerate change, the role ensures our risk and control system remains fit for purpose. Works across all Technology domains, including Engineering, Architecture, Cloud, Enterprise Technology, and Information Security. Perform as the key first-line interface for the Second Line of Defence, internal audit, and regulatory stakeholders.
Everyone is welcome.
We have a culture of creativity. We approach our work passionately, improve constantly and celebrate our wins at every turn. We are an inclusive workplace and our employees are comfortable bringing their authentic, whole selves to work. Everyone is welcome. Be you.
This means we’re excited to hear from people with a range of skills, experiences and ideas. We don’t expect you to tick all the boxes, but would love to hear what makes you great for this role.
Some of the great things you’ll be doing:
Operate the First Line of Defence
- Lead the execution of Technology’s First Line responsibilities, including risk identification, control testing, issue management, and mitigation tracking
- Own and maintain the Technology Risk Framework, ensuring alignment with policy, regulatory, and delivery expectations
- Prepare and deliver Technology Risk content for board reporting, internal governance, audits, and regulatory examinations
- Maintain the Technology domain in the Risk Management System, keeping controls, processes, and indicators current and effective
- Act as the primary point of contact for internal audit and the Second Line of Defence
Improve and Modernise the Risk System
- Identify opportunities to shift from manual risk management to embedded and automated processes
- Ensure the control environment can adapt to emerging technologies such as GenAI and cloud platforms
- Introduce practical improvements to control testing, risk reporting, and assurance
- Integrate risk measurement into delivery workflows, CI/CD pipelines, and monitoring tools
Enable Risk Ownership Across Technology
- Partner with Engineering Managers, Senior Engineering Managers, and other domain leads to build risk awareness into team practices
- Help teams understand and meet their risk responsibilities without unnecessary overhead
- Promote a culture where strong risk management is seen as part of effective technology leadership
Shape Oversight and Policy in Partnership with the Second Line
- Collaborate with the Second Line to align expectations, improve oversight rhythms, and shape relevant, practical policies
- Interpret regulatory requirements in a delivery and engineering context
- Contribute to governance that supports both compliance and pace
What we’d like to see from you:
- Strong knowledge of Technology Risk Management in regulated environments
- Experience leading operational first-line risk activity, including control testing and risk reporting
- Ability to influence senior stakeholders across domains without direct authority
- Clear and confident communicator across technical, regulatory, and executive settings
- Proven track record of preparing for and responding to audits and regulatory reviews
- Understanding of modern delivery environments such as CI/CD, cloud platforms, and infrastructure as code is preferred, but not essential
- Familiarity with tools or processes that support automated control and assurance is preferred, but not essential
- Working knowledge of SMCR, GDPR, or other financial regulatory frameworks is preferred, but not essential
- Relevant professional qualifications such as IRMCert, CISM, CISSP, CISA, PIIA, or CIPP/E is a nice to have
- Experience working in or alongside engineering or architecture teams is beneficial
There’s something for everyone.
We’re a place of opportunity. You’ll have the tools and autonomy to drive your own career, supported by a team of amazingly talented people.
And then there’s our benefits. For us, it’s not just about a competitive salary and hybrid working, we care about what matters to you. From a generous holiday allowance and private healthcare to an electric car scheme and paid development, wellbeing and CSR days, we’ve pretty much got you covered!
#LI-HL1
Read Full Description