Posted 02 August, 2026
Senior Enterprise Risk Manager
REV & REGS LIMITED
London, ENG, GB
Full Time
Job Description
Rev & Regs are recruiting for a Senior Enterprise Risk Manager role for a dynamic commercial and retail bank focused on mortgages / lending.
\nThe role sits within the Second Line of Defence, reporting to the Head of Enterprise Risk, and has responsibility for managing a team of three direct reports. We are looking for a Manager or Senior Manager with recent Second Line experience overseeing Operational Resilience (OpRes) and Third-Party Risk Management (TPRM), together with a strong focus on data risk, cyber risk, and emerging risks such as AI, all from a Second Line perspective.
\nResponsibilities:
\n- \n
- Lead second line oversight of first line Operational Risk activities, including Risk and Control Self-Assessments (RCSAs), scenario analysis, and control effectiveness reviews. \n
- Deliver a structured programme of Key Control assurance, thematic reviews, and deep-dives to assess control effectiveness and identify systemic weaknesses. \n
- Own, maintain and continuously enhance the Group Operational Risk Management Framework (GORMF), and other Operational Risk policies and guidance. \n
- Lead the end-to-end delivery of a strategic GRC system implementation, including requirements definition, vendor selection, testing, and embedding. \n
- Develop and embed second line oversight of Operational Resilience, ensuring alignment with regulatory expectations (e.g. important business services, impact tolerances, and scenario testing). \n
- Own, maintain and continuously enhance the Group Operational Resilience Risk Framework and Group Third Party Risk Framework. \n
- Expand second line coverage across key non-financial risk domains, including: Third Party Risk, Management (TPRM), Cyber and Information Security Risk, Technology and IT Risk and Artificial Intelligence (AI) Risk. \n
- Provide independent challenge to ensure these risk domains are effectively governed, controlled, and integrated into the wider risk framework. \n
- Support the design, development, and implementation of a comprehensive Data Risk Framework, covering data governance, quality, privacy, lineage, and usage risks. \n
- Ensure the framework is embedded across the organisation, with clear roles, responsibilities, and controls aligned to regulatory expectations and best practice. \n
- Establish appropriate oversight, metrics, and reporting to support effective management of data-related risks. \n
Experience:
\nEssential:
\n- \n
- Significant experience (typically 10+ years) in Operational Risk or Enterprise Risk within Financial Services or a similarly regulated industry. \n
- Demonstrable second line experience with oversight and challenge responsibilities. \n
- Diverse knowledge of financial services with specific knowledge of current regimes pertaining to Operational Risk under the auspices of the PRA and FCA regulatory authorities. \n
- Practical experience in Operational Resilience (e.g. important business services, impact tolerances, scenario testing). \n
- Exposure to or oversight of TPRM, Cyber/IT Risk, and emerging risks such as AI. \n
- Demonstrated ability to partner effectively with first line business units while maintaining independence of oversight. \n
- Familiarity with risk systems, GRC tooling, analytics, and the use of dashboards/KRIs to drive insight. \n
- Demonstrates curiosity and proactively explores new risk areas (e.g. AI, data, digital resilience). \n
Desirable:
\n- \n
- Good understanding of data architecture, data governance, and data quality principles. \n
- Awareness of emerging technologies (e.g. AI/ML) and associated risk management approaches. \n
- Experience leading complex risk transformation or change programs \n
Salary: £100,000 plus bonus
\nLocation: Hybrid (3 days per week in City of London)
