Skip to main content
AfterDuty

Group Senior IT Risk Manager

Bupa · London, Greater London

Type
Full-time
Posted
Yesterday

Overview

Your experience in policing has given you a strong foundation in risk assessment, threat identification, and incident management, which are directly applicable to IT risk management. You are used to working under pressure, making decisions based on incomplete information, and communicating complex risks to senior stakeholders. While you may need to develop specific technical knowledge of IT frameworks like ISO 31000 or NIST, your core skills in evaluating threats, implementing controls, and ensuring compliance are highly transferable to this role.

About this role

Job Description

Group Senior IT Risk Manager

London

Full time - 35 hours per week

Hybrid & Flexible working options

Permanent role

We make health happen!

At Bupa, we're committed to helping people live longer, healthier, happier lives. As our business continues to evolve, technology plays an increasingly critical role in delivering trusted healthcare experiences for millions of our customers around the world.

We're looking for a Senior IT Risk Manager to help shape and strengthen our approach to technology risk, resilience, and governance across the Group. This is a highly visible leadership role within our Group Information Security Office, reporting to the Group Head of Cyber Governance, Risk & Compliance and working closely with the Group Director of Operational Resilience.

The successful candidate will lead the development and evolution of our Group-wide IT risk management framework, ensuring robust governance, effective controls, and a consistent approach to risk management across multiple business units. You'll have the opportunity to influence senior stakeholders across the business, helping ensure our technology environment remains secure, resilient, and aligned to our strategic ambitions

How you'll help us make health happen

  • Lead the development, implementation, and maintenance of the Group-wide IT risk management framework, Policy and Standards, ensuring alignment with business objectives, the Enterprise Risk Management Framework and regulatory requirements.
  • Identify, assess, and monitor IT risks across all business units, collaborating with stakeholders to ensure risks are appropriately managed and mitigated.
  • Design and support the implementation of controls and processes to manage IT resilience risks, including regular reviews of their effectiveness, along with related key risk indicators.
  • Partner with Market Unit technology and Second Line teams to define and support their implementation of controls and processes to ensure the resilience of data centres critical to the delivery of our critical services.
  • Work closely with the Group Director of Operational Resilience to ensure consistency in risk management practices and reporting.
  • Facilitate risk assessments, including thematic and ad-hoc reviews, to identify emerging threats and vulnerabilities in the Group's IT environment.
  • Prepare and deliver clear, concise risk reports for senior management, regulatory, and board-level audiences.
  • Champion a culture of risk awareness, providing training and guidance to business units on IT risk management best practices.
  • Collaborate with cross-functional teams to assess the impact of new technologies, regulatory changes, and industry standards on the Group's IT risk profile

Skills & experience required for this role

We're looking for an experienced and credible technology risk leader who combines strategic thinking with practical delivery.

  • Significant experience in IT Risk, Technology Risk, Cyber Risk, Operational Resilience or a similar discipline gained within a large, complex organisation.
  • Demonstratable experience designing, implementing and embedding risk frameworks, controls and governance processes at enterprise scale.
  • Strong understanding of recognised frameworks such as ISO 31000, ISO 27002, NIST, COBIT and ITIL.
  • The ability to translate complex technical risks into meaningful business insights and practical action plans.
  • Exceptional collaboration and stakeholder management skills, with the confidence and credibility to influence senior leaders and challenge constructively where required.
  • The ability to work independently whilst fostering strong cross-functional collaboration, proactively identifying risks, opportunities and solutions to deliver business objectives.
  • Professional certifications such as CISSP, CISM or CRISC are highly desirable

Benefits

Our benefits are designed to make health happen for our people. Viva is our global wellbeing programme and includes all aspects of our health - from mental and physical, to financial, social and environmental wellbeing. We support flexible working and have a range of family friendly benefits.

Joining Bupa in this role you will receive the following benefits and more:

  • 25 days holiday, increasing through length of service, with option to buy or sell
  • Car allowance
  • Performance related bonus
  • Bupa medical insurance
  • An enhanced pension plan and life insurance
  • Free health assessment
  • Annual performance-based bonus
  • Onsite gyms or local discounts where no onsite gym available
  • Various other benefits and online discounts

Why Bupa?

We're a health insurer and provider. With no shareholders, our customers are our focus. Our people are all driven by the same purpose - helping people live longer, healthier, happier lives and making a better world. We make health happen by being brave, caring and responsible in everything we do.

We encourage all of our people to ”Be you at Bupa”, we champion diversity, and we understand the importance of our people representing the communities and customers we serve. That's why we especially encourage applications from people with diverse backgrounds and experiences.

Bupa is a Level 2 Disability Confident Employer. This means we aim to offer an interview/assessment to every disabled applicant who meets the minimum criteria for the role. We'll make sure you are treated fairly and offer reasonable adjustments as part of our recruitment process to anyone that needs them.

Time Type

Full time

Job Area

Angel Court, London

Financial planning services, Employee mentoring programme, Private dental insurance, Referral programme, Health & wellbeing programme, Free flu jabs, Cycle to work scheme, Company pension, Additional leave, Paid volunteer time, Private medical insurance, Gym membership, Canteen

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background — match score 75/100

  • Risk & threat assessment
  • Working to legislation & regulation
  • Training & coaching delivery

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Full-time

    This role focuses on information security management, risk assessment, and incident response — areas where your experience in operational policing, threat assessment, and managing critical incidents translates directly. Your background in following strict procedures, handling sensitive information, and coordinating multi-agency responses aligns well with the security governance and compliance aspects of the job. While the role requires specific technical cyber security knowledge, your investigative mindset and ability to work under pressure are strong foundations that employers in this sector

    Posted Yesterday

  • Privacy Operations Manager

    Thomson Reuters · London

    Full-time

    Your experience managing sensitive information under strict legal frameworks like PACE, RIPA, and CPIA gives you a strong foundation for privacy compliance and data protection. The incident command and risk assessment skills you developed in policing translate directly to coordinating cyber incident response and conducting privacy impact assessments. Your ability to lead operational teams and work across agencies prepares you to embed privacy-by-design principles and manage global privacy operations.

    Posted 2 days ago

  • Your experience managing complex incidents, assessing threats, and coordinating multi-agency responses in policing directly prepares you for leading cyber security engagements and advising clients on risk and resilience. The role's focus on stakeholder management, conducting assessments, and developing security strategies mirrors the analytical and command skills you've honed, and your security clearance eligibility is a strong asset in this defence and security consultancy.

    Posted 5 days ago

  • Director - Business Audit

    Mastercard · London

    Full-time

    Our Purpose Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper.

    Posted 6 days ago