IT Risk Manager
Greater London, London, Greater London, W1B, England, UK
Listed on 2026-03-09
-
IT/Tech
IT Consultant, Cybersecurity, IT Project Manager, IT Business Analyst
Collinson is the global, privately‑owned company dedicated to helping the world to travel with ease and confidence. The group offers a unique blend of industry and sector specialists who together provide market‑leading airport experiences, loyalty and customer engagement, and insurance solutions for over 400 million consumers.
Collinson is the operator of Priority Pass, the world’s original and leading airport experiences programme. Travellers can access a network of 1,500+ lounges and travel experiences, including dining, retail, sleep and spa, in over 650 airports in 148 countries, helping to elevate the journey into something special. We work with the world’s leading payment networks, over 1,400 banks, 90 airlines and 20 hotel groups worldwide.
We have been bringing innovation to the market since inception – from launching the first independent global VIP lounge access Programme, Priority Pass, to being the first to sell direct travel insurance in the UK through Columbus Direct and creating the first loyalty agency of its kind in the travel sector with ICLP. Today we still invest heavily in innovation to ensure that we continue to deliver superior customer experiences.
Key clients include Mastercard, American Express, Cathay Pacific, British Airways, LATAM, Flying Blue, Accor, Easy Jet, HSBC, Chase, HDFC.
Our mission is focused on doing good beyond profit, which for us means we seek out opportunities for our people to share in our success and that we give back to the communities and people within which we work.
Never short of ambition, the success of our business is delivered through the diverse and talented team of over 2,200 global colleagues.
Purpose of the jobThis role is a key part of the First Line of Defence (FLOD) for Collinson Insurance. Its purpose is to ensure IT and data risks are assessed, managed, and mitigated in line with regulatory requirements and best practice.
The role will:- Provide guidance and expertise on FLOD activities for technology and data, ensuring compliance with regulatory, industry, and best practice standards.
- Act as the primary contact for IT risk matters, supporting the Head of Engineering in maintaining adherence to IT General Controls, FCA/PRA guidelines, MFSA requirements, DORA, and related regulations.
- Coordinate with internal and external second and third line of defence functions, and on the compliance teams across the enterprise.
- FLOD Accountability:
Own all FLOD activities, processes, and improvements for technology and data assets, collaborating with relevant stakeholders. - Control Design & Assurance:
Ensure internal controls for IT and data risks are designed, implemented, and maintained. Provide assurance of control effectiveness through indicators and reviews. - Reporting:
Deliver regular updates on IT and data control health to committees, boards, and relevant third parties. - Education & Consultation:
Advise on best practice control design and risk management across technology, product, and service teams. - Risk Assessment:
Conduct focused risk assessments for new and existing services and technologies. - Agile Engagement:
Participate in planning and design sessions, helping prioritise IT, security, and data risk items. - Policy & Control Implementation:
Identify and implement appropriate controls, maintain draft policies, and improve risk posture through remediation and mitigation strategies. - Collaboration:
Work closely with Group CISO, Insurance and Group Risk & Compliance, and Internal Audit teams. - Continuous Improvement:
Stay updated on regulatory and industry changes, mature the IT and data risk framework, and pursue recognised accreditations. - Incident Management:
Ensure robust security and data incident practices, lead resolution of priority incidents (P1/P2), and coordinate with internal and external stakeholders.
- Strong practical knowledge of IT security technologies and business solutions, including firewalls, IDS/IPS, identity and access management, SIEM, remote working, and cloud technologies (AWS and Azure).
- Solid understanding of application security threats, current and emerging information…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: