We have an exciting opportunity for an IT Risk Manager to join us on a permanent contract, based in Luton! (Hybrid Working)
The IT Strategy & Architecture team provides leadership around easyJet’s technology strategy, the evolution of our enterprise IT architecture, solution architectures for complex change, cybersecurity architecture, our federated technical architecture practice, and areas such as end-to-end IT risk management.
Reporting to the Head of IT Risk & Resilience, the IT Risk Manager is responsible for implementing, embedding and continuously improving easyJet’s IT Risk Management practice.
We work collaboratively with a broad range of colleagues and stakeholders at all levels (from the C-suite to the frontline) and focus on striking a pragmatic balance between supporting in-flight initiatives and steering longer-term investment.
What you’ll be doing
• Planning, designing and implementing the overall risk management process as part of the maturing IT Risk framework that is applied across easyJet IT.
• Identifying, analysing and prioritising key areas of IT risk as well as articulating the impacts they may present to the easyJet business in order for informed, conscious decisions to be made.
• Interfacing with technical and non-technical stakeholders within easyJet to build and maintain valuable and productive working relationships and ensure that the benefits of managing IT Risk to the business are demonstrated.
• Facilitating risk workshops to support the identification and assessment of risks and controls
• Supporting the Internal Audit process including understanding and articulation amongst IT stakeholders of key IT risks underlying in any resulting actions.
• Maintaining risk artefacts (e.g. IT Risk Register, Bow Tie Risk Reporting etc.) to demonstrate the effects of managing IT risk (both via tactical and strategic planning).
• Providing IT risk SME advice, oversight and challenge to facilitate and drive action plan accountability for decreasing and mitigating risk.
• Coordinating the accountable risk owners to ensure mitigation activities are managed, effective and aligned with easyJet requirements.
• Reporting on risk in an appropriate way for different stakeholders including the IT Leadership Team, presenting and explaining the assessment of risk scenarios as well as mapping of capability controls, metrics and measures.
• Identify opportunities for IT process improvement using existing framework and controls.
• Managing IT capability and control requirements and analysing and articulating gaps both within IT, Data and Change and with other key stakeholders including Corporate Risk, Safety Risk and Digital Safety.