Technology Business Control Partner

NatWest Group

Technology Business Control Partner

Salary Not Specified

NatWest Group, Edinburgh

  • Full time
  • Permanent
  • Remote working

Posted 1 week ago, 19 Apr | Get your application in now before you miss out!

Closing date: Closing date not specified

job Ref: 3f47d7b8a49e49699092102872972a14

Full Job Description

Join us as a Technology Business Control Partner

  • If you have a technology related risk, audit or controls background, and are looking for a new challenge, then we'd like to hear from you

  • Day-to-day, you'll anticipate and assess the potential impacts of risk either across our Financial Crime Technology or Commercial & Institutional Chief Digital and Information Office business areas

  • Thrive in a position where you'll partner with our bank to manage our risks and controls within an agreed risk appetite, while using our risk framework to achieve your team's objectives

  • This is a hybrid role, so you'll work from home some of the time, but spend at least one day a week in the office


  • What you'll do

    You'll help with the delivery of the risk framework and apply risk management within our risk appetite for the business area, while providing support as a technology risk and control SME.

    We'll look to you to assist our business with managing its risks, including making sure that mechanisms are in place to identify and mitigate risk within a defined risk appetite. That way you can deliver relevant risk activities to build plans to sustain a control environment certification within risk appetite.

    Other key responsibilities will include:
  • Escalating emerging risks in a timely manner, while making sure actions are quickly defined and owned and delivering all aspects of risk management within the policy framework and operational risk requirements

  • Developing risk awareness, contributing to the prioritisation, design and implementation of controls that're in line with our operational risk principles.

  • Liaising with our business, internal audit, second line of defence and other functions, as well as with the wider risk and control teams

  • Collaborating with senior stakeholders across our bank to drive forward the development and delivery of remedial action plans where identified risks are considered out of appetite

  • Providing SME Technology Controls input and assisting with the design of controls (including automated controls) to support the development of a cost-effective and automated controls environment that meets regulatory and policy expectations and brings risks within appetite

  • Supporting corporate governance and risk committees, articulating risk profiles and control gaps and using the operational risk framework

  • Strengthening the level of ownership, while identifying and calling out areas of weakness and sharing best practices and material risk measures

    To be successful in this role, you'll have a background and good understanding of risks and controls relating to Technology and a good understanding of Investment banking. You'll need stakeholder management skills involving people, processes and technology issues, along with knowledge and a practical application of risk management principles.


  • Furthermore, you'll need:
  • A background within a technology risk and controls role or a risk or audit role and an understanding of IT general and automated controls, including technology control frameworks, such as COBIT

  • Knowledge of Commercial & Investment Banking business areas, associated products, processes and technologies

  • Excellent senior stakeholder management skills and experience of risk management, risk committees and risk frameworks

  • Experience of technology risk and control assessments and an understanding of IT general and automated controls to mitigate risks

  • The ability to think creatively when resolving problems to identify alternatives where established procedures may not exist

  • Industry recognised Technology Risk and Controls certification is preferred, such as CISA, CRISC

    In everything we do, we work to one aim. To make digital experiences which are effortless and secure.


  • So we organise ourselves around three principles: engineer, protect, and operate. We engineer simple solutions, we protect our customers, and we operate smarter.

    Our people work differently depending on their jobs and needs. From hybrid working to flexible hours, we have plenty of options that help our people to thrive.

    This role is based in the United Kingdom and as such all normal working days must be carried out in the United Kingdom.