JobConnect

Senior IT Governance, Risk & Compliance Specialist

About Us

Skybound Wealth Management is a global financial advisory company with employees across the UK, USA, Switzerland, Cyprus, Spain and UAE. We provide tailored financial advice to international clients, supported by expert teams across wealth planning, compliance and operations.

Role Overview

Skybound Wealth Management is building a dedicated internal global IT function to support a rapidly growing, multi-jurisdictional financial-services business.

We are looking for an experienced Senior IT Governance, Risk & Compliance Specialist to take ownership of the governance, risk and regulatory-control framework surrounding Skybound’s technology environment.

This is not a general corporate compliance role and it is not solely an audit or assurance position.

The successful candidate will sit within the IT function and work closely with Infrastructure, Cybersecurity, Risk, Compliance, Data Protection and external technology providers to ensure Skybound’s technology environment is appropriately controlled, documented, evidenced and regulator-ready.

The role requires someone who can understand a technical environment, identify weaknesses, translate regulatory requirements into practical IT controls, establish repeatable governance processes and provide clear evidence to management, auditors and regulators.

The successful candidate must be comfortable operating between technical teams, business stakeholders, auditors and regulators.

Key Responsibilities

IT Governance

  • Develop, maintain and continuously improve Skybound’s IT governance framework.

  • Establish clear control ownership across Infrastructure, Cybersecurity and wider technology operations.

  • Define governance processes and recurring review cycles for key technology controls.

  • Maintain a structured IT governance calendar covering reviews, certifications, testing, evidence collection and policy updates.

  • Ensure technology processes are documented, repeatable and consistently followed across relevant entities and jurisdictions.

  • Work with technical teams to ensure operational practice aligns with documented policy and governance requirements.

  • Establish appropriate management reporting covering IT risk, controls, remediation and governance.

IT Risk Management

  • Own and maintain the IT Risk Register.

  • Support and maintain the Cybersecurity Risk Register in conjunction with the Cybersecurity function.

  • Identify and assess technology, cybersecurity, resilience and third-party risks.

  • Define appropriate risk treatments, owners, actions and target dates.

  • Monitor remediation plans and ensure actions are evidenced through to closure.

  • Escalate material technology risks to the Head of IT and senior management.

  • Support risk assessments for new technology, infrastructure changes, vendors and major projects.

  • Ensure risk decisions, exceptions and accepted risks are appropriately documented and approved.

Regulatory Technology Compliance

Interpret technology-related regulatory requirements and translate them into practical controls, policies and evidence.

The role will support Skybound’s requirements across multiple regulated entities and jurisdictions, including areas such as:

  • Digital Operational Resilience Act (DORA)

  • Regulation S-P

  • GDPR and data-protection requirements

  • operational resilience

  • cybersecurity requirements

  • outsourcing and third-party technology risk

  • local regulatory requirements applicable to Skybound entities

Responsibilities will include:

  • reviewing applicable regulatory requirements;

  • mapping requirements to technology controls;

  • performing gap assessments;

  • coordinating remediation;

  • maintaining supporting evidence;

  • tracking regulatory actions;

  • supporting submissions and audit responses;

  • ensuring implemented controls remain effective over time.

The role will work closely with the company’s Compliance and Risk functions, but will own the technology governance and control implementation framework within IT.

Policies, SOPs & Control Documentation

  • Develop and maintain IT and cybersecurity policies in collaboration with Infrastructure and Cybersecurity teams.

  • Create practical Standard Operating Procedures for key IT processes.

  • Ensure policies accurately reflect the actual technology environment.

  • Maintain document ownership, approval, review dates and version control.

  • Ensure regulatory and policy requirements are translated into operational procedures.

  • Maintain a structured repository of IT governance documentation.

  • Regularly review policies and procedures following system, regulatory or organisational change.

Key documentation may include:

  • Information Security Policy

  • Access Control Policy

  • Joiner / Mover / Leaver procedures

  • Incident Response procedures

  • Acceptable Use Policy

  • Business Continuity and Disaster Recovery procedures

  • Vulnerability Management Policy

  • Privileged Access procedures

  • Third-Party Technology Risk procedures

  • Change Management procedures

  • Device and Endpoint Management procedures

  • IT Asset Management procedures

Audit & Regulatory Support

  • Act as a key technology contact for internal audits, external audits and regulatory reviews.

  • Coordinate technical responses to audit and regulatory questions.

  • Gather evidence from Infrastructure, Cybersecurity and third-party providers.

  • Review evidence for completeness and accuracy before submission.

  • Maintain recurring evidence for common control areas.

  • Track audit findings, recommendations and remediation activity through to closure.

  • Ensure technology teams understand audit findings and required actions.

  • Support management responses to audit and regulatory findings.

  • Develop an organised audit-evidence repository to reduce repeated manual work

The objective is for Skybound to be able to explain and evidence its own technology environment without being completely dependent on external providers.

Identity & Access Governance

  • Establish governance around user access and privileged access.

  • Coordinate periodic user-access reviews.

  • Coordinate administrator and privileged-role reviews.

  • Monitor joiner, mover and leaver control effectiveness.

  • Ensure access changes have appropriate approvals and evidence.

  • Review access exceptions and ensure they are documented and periodically reassessed.

  • Work with Infrastructure and Cybersecurity on governance surrounding:

  • Microsoft Entra ID

  • MFA

  • Conditional Access

  • privileged roles

  • authentication

  • service accounts

  • application access

The technical configuration may sit with Infrastructure or Cybersecurity, while governance, review and evidence sit with this role.

Cybersecurity Governance

The Cybersecurity function will own the technical implementation and operation of security controls.

This role will own the governance surrounding those controls.

Areas of collaboration will include:

  • cybersecurity policies

  • incident governance

  • vulnerability-management governance

  • penetration-test remediation tracking

  • security-control reviews

  • phishing and awareness governance

  • risk treatment

  • cybersecurity reporting

  • regulatory cybersecurity obligations

  • exceptions and compensating controls

For example:

Cybersecurity may implement and manage Microsoft Defender.

This role ensures:

  • the control requirement is defined;

  • ownership is documented;

  • the control is reviewed;

  • appropriate evidence is retained;

  • weaknesses are tracked;

  • regulatory requirements are met.

Third-Party & Outsourcing Risk

  • Develop and maintain technology vendor-risk governance.

  • Perform or coordinate due-diligence assessments for technology suppliers.

  • Maintain records of critical suppliers and outsourced technology services.

  • Assess supplier security, resilience, controls and regulatory impact.

  • Maintain oversight of Managed Service Providers and other critical vendors.

  • Track supplier risks and remediation actions.

  • Support DORA and other outsourcing / third-party risk requirements.

  • Ensure appropriate review cycles for critical providers.

  • Maintain evidence of supplier oversight.

This includes governance over outsourced technology services such as MSPs, cloud providers, cybersecurity vendors and other critical technology partners.

Business Continuity & Operational Resilience

  • Maintain IT governance around Business Continuity and Disaster Recovery.

  • Ensure critical technology services have documented recovery requirements.

  • Coordinate business-impact and technology-resilience reviews where required.

  • Establish testing schedules for BCP and DR controls.

  • Coordinate periodic resilience testing with Infrastructure and Cybersecurity teams.

  • Record results, weaknesses and remediation actions.

  • Maintain evidence demonstrating that recovery arrangements have been tested.

  • Support operational-resilience requirements under DORA and other applicable frameworks.

  • Track resilience risks and improvements.

Control Testing & Assurance

  • Develop a structured IT control-testing programme.

  • Test whether documented controls are actually being performed.

  • Conduct periodic sampling and evidence reviews.

  • Identify control failures and weaknesses.

  • Track corrective action.

  • Perform or coordinate control maturity assessments.

  • Support continuous improvement of the IT control environment.

Examples may include:

  • sampling leavers to confirm access was removed correctly;

  • testing privileged-access reviews;

  • reviewing device-compliance evidence;

  • checking vulnerability remediation;

  • reviewing backup / recovery testing;

  • verifying security exceptions;

  • validating third-party reviews.

IT Reporting & Management Information

Produce clear reporting for the Head of IT and senior management covering:

  • key technology risks;

  • cybersecurity risks;

  • open audit findings;

  • remediation activity;

  • policy status;

  • control-testing results;

  • regulatory actions;

  • access reviews;

  • third-party risk;

  • BCP / DR testing;

  • significant control exceptions.

The role should be capable of turning detailed technology and risk information into clear management-level reporting.

Key Projects

The successful candidate will be expected to lead or materially contribute to projects including:

  • DORA implementation and ongoing governance

  • Regulation S-P technology controls

  • Global IT Governance Framework

  • IT Policy Framework

  • Cybersecurity Policy Framework

  • IT Risk Register

  • Cybersecurity Risk Register

  • IT Control Framework

  • Audit Evidence Repository

  • Access Review Programme

  • Joiner / Mover / Leaver Governance

  • Third-Party Technology Risk Framework

  • Business Continuity / Disaster Recovery Governance

  • Operational Resilience Programme

  • Regulatory Technology Gap Assessments

  • IT Governance Calendar

  • Technology Supplier Review Programme

  • Audit and Regulatory Readiness

  • IT Control Testing Programme

  • Governance supporting Microsoft 365 entity / tenancy architecture

Required Experience

We are looking for approximately 5–8 years of relevant experience in one or more of the following areas:

  • IT Governance, Risk & Compliance

  • Technology Risk Management

  • IT Audit

  • Information Security Governance

  • Cybersecurity GRC

  • Information Security Compliance

  • Operational Resilience

  • Third-Party Technology Risk

  • IT Controls

  • Regulatory Technology Compliance

Experience in banking, financial services, payments, insurance, wealth management or another regulated environment is strongly preferred.

Candidates should have demonstrable experience in several of the following:

  • owning IT or cybersecurity risk registers;

  • preparing for and responding to audits;

  • managing IT controls;

  • developing policies and SOPs;

  • carrying out risk assessments;

  • implementing regulatory requirements;

  • coordinating remediation;

  • control testing;

  • third-party risk;

  • access governance;

  • BCP / DR;

  • audit evidence management.

Technical Understanding

This is not an infrastructure engineering position, but the successful candidate must be technically credible.

You should understand the purpose and control implications of technologies such as:

  • Microsoft 365

  • Microsoft Entra ID

  • Exchange Online

  • Microsoft Intune

  • Conditional Access

  • MFA

  • Microsoft Defender

  • Microsoft Sentinel / SIEM

  • Microsoft Purview

  • Mimecast / email security

  • endpoint management

  • vulnerability management

  • networks

  • firewalls

  • privileged access

  • backup and recovery

  • cloud environments

  • cybersecurity monitoring

You are not expected to configure all of these systems yourself.

You are expected to understand them well enough to:

  • challenge technical teams;

  • assess control effectiveness;

  • identify risk;

  • determine evidence requirements;

  • explain the control to an auditor or regulator.

Framework & Regulatory Knowledge

Experience with several of the following is preferred:

  • DORA

  • GDPR

  • Regulation S-P

  • ISO 27001

  • SOC 1 / SOC 2

  • NIST Cybersecurity Framework

  • COBIT

  • CIS Controls

  • PCI DSS

  • CSA STAR

  • ITIL

  • operational-resilience frameworks

  • business-continuity standards

Candidates are not expected to know every framework.

More important is the ability to take a regulatory or framework requirement and convert it into a practical, sustainable technology control.

Qualifications

A degree in one of the following or a related discipline is preferred:

  • Information Technology

  • Information Security

  • Cybersecurity

  • Information Systems

  • Risk Management

  • Computer Science

Relevant professional certifications are advantageous, including:

  • CISA

  • CRISC

  • CISM

  • CISSP

  • ISO 27001 Lead Auditor

  • ISO 27001 Lead Implementer

  • COBIT

  • relevant privacy, risk or resilience qualifications

Certifications are desirable but practical experience is more important.

Skills & Attributes

The successful candidate should demonstrate:

  • strong analytical capability;

  • excellent written documentation;

  • attention to detail;

  • strong organisation;

  • ability to manage multiple remediation items simultaneously;

  • confidence dealing with senior stakeholders;

  • ability to communicate with both technical and non-technical audiences;

  • ability to challenge constructively;

  • strong ownership;

  • good judgement;

  • ability to work independently;

  • ability to translate regulation into practical action.

What Good Looks Like

The strongest candidate will be able to take a requirement such as:

“Privileged access must be appropriately controlled.”

and turn it into:

  1. a documented control;

  2. a clear owner;

  3. a defined approval process;

  4. a recurring access review;

  5. appropriate technical implementation;

  6. documented exceptions;

  7. evidence retained for audit;

  8. testing to ensure the control is working;

  9. remediation where it fails;

  10. management reporting.

We are not looking for someone who simply maintains compliance spreadsheets or forwards audit questions to technical teams.

We are looking for someone who builds and maintains the governance framework around the technology environment.

Why This Role Matters

Skybound is moving from an IT model heavily dependent on external providers toward an internally owned global technology function.

The future structure will include dedicated capability across:

  • Infrastructure

  • Cybersecurity

  • IT Governance, Risk & Compliance

Infrastructure will build and operate the technology. Cybersecurity will implement and operate technical security controls.

The IT Governance, Risk & Compliance function will ensure those controls are appropriately designed, documented, governed, tested and capable of standing up to management, audit and regulatory scrutiny.

This role will therefore be central to building Skybound’s future global IT operating model.

Skybound Wealth Management is committed to fostering a diverse and inclusive workplace. We welcome applications from all qualified candidates regardless of background.

Skills

  • IT Governance
  • Risk Management
  • Regulatory Compliance
  • Control framework design
  • Audit Support
  • Stakeholder Management
  • Technical Writing

Related jobs

Skybound Wealth ManagementApply for this job