Skip to main content
AfterDuty

Technology and Data Risk Manager

Nest · London, Greater London

Salary
£80,000 – £85,000Estimated
Type
Full-time
Posted
9 days ago

Overview

Your incident command and threat assessment experience gives you a head start in second-line risk oversight.

About this role

Role Overview

The Technology & Data Risk Manager is a new second line of defence role within the Risk Directorate, responsible for providing independent oversight, assurance and expert challenge across technology, data, cyber security, and related operational risks. Reporting to the Head of Technical Risk and Data Protection Officer, the role supports the effective management of technology and data risks by ensuring first line teams identify, assess and mitigate risks in line with Nest’s risk appetite while enabling the organisation to deliver its strategic objectives securely and efficiently.

Working across the organisation, the role promotes strong risk management practices, providing expert challenge on technology, data protection, information security, and third-party risk matters. It plays a key role in strengthening governance, embedding a strong data protection and security culture, and supporting compliance with regulatory requirements and recognised standards, including UK GDPR, the Data Protection Act 2018 and ISO 27001.

The Technology & Data Risk Manager also helps the organisation anticipate and respond to emerging risks and opportunities, including developments in artificial intelligence, evolving cyber threats, and third-party dependencies. Through effective stakeholder engagement, assurance activity and risk reporting, the role contributes to maintaining a resilient, compliant, and well-controlled technology and data environment across Nest.

The minimum criteria for this role are

Essential

  • Sound knowledge of information security and data risk domains (access control, vulnerability management, logging and monitoring, incident response, secure development etc).
  • Experience in technology, data, security, or technical risk management including control frameworks such as ISO 27001 and NIST, ideally within a regulated or complex organisation.
  • Strong understanding of second line assurance and oversight, including how to challenge constructively while remaining independent.
  • Experience of assessing third‑party technical risk.

Desirable

  • Experience with product security and secure SDLC assurance.
  • Knowledge of AI risk, data ethics or emerging technology governance.
  • Working knowledge of UK GDPR and the Data Protection Act 2018.
  • Knowledge of threat intelligence, vulnerability disclosure, and security testing approaches.
  • Relevant professional certifications (e.g. CISM, CISSP, ISO 27001 LI/LA, CRISC, ITIL).

Don't worry if you think you don't have all the key skills, it might be worth taking the few minutes to apply as we're good at spotting potential. At Nest, you’ll have access to a range of learning opportunities to learn, grow and build the skills you need to be successful in your role and career.

Please download a full job description to find a full scope, deliverables, experience and personal**attributes**required for this role.

Flexible and agile working

Everyone's personal situation is different.

To make the most out of hybrid working, we've introduced different ways of working, which include (subject to role requirements):

  • hybrid of office (Canary Wharf, London) and home working (there will be an expectation to attend the office, once - twice a week, or more, as required)
  • vary working hours

Click here to see the benefits we offer at Nest.

For more information about our recruitment process click here

The Technical Risk team sits within the Risk Directorate, along with Risk, Risk Assurance, Risk Operations and Regulatory Risk, and Controls Oversight. The directorate supports the business in delivering its strategic priorities by overseeing that risk and controls are identified, prioritised and managed through an enterprise risk management framework. Nest operates a ‘three lines of defence’ model, with Risk sitting in the second line providing advice, guidance and challenge to the first line.

The Technical Risk team provides support to Nest specifically in relation to risks covering data, privacy, technology, cyber and financial crime. Support includes conducting investigations, regulatory reporting as well as training and awareness across Nest Corporation.

Organisational Overview

Nest is an award-winning workplace pension scheme, the largest in the country.

Set up by the government to give every worker in the UK somewhere to save, our first-class responsible investment practice and governance are the backbone of what we do, supported by all the functions you’d expect to find in a thriving business. We’re committed to creating a workplace where you can be your authentic self and offer an inclusive and flexible working environment.

Diversity, Equity and Inclusion

Everyone is welcome to apply for our roles, and we are determined to ensure that no applicant or employee receives less favourable treatment because of their age, disability, gender identity, marital status, national origin, pregnancy or caring responsibilities, race, religion/belief, sex, sexual orientation or socio economic background.

We also recognise the importance of diversity of thought and other forms of neurocognitive variation.

Nest is a Disability Confident Leader, which is the highest level of the Disability Confident Scheme. If you have a disability, please declare that you’re applying through the scheme.

We aim to offer an interview to those applicants who apply through the Disability Confident Scheme and best meet the minimum criteria. However, there may be some circumstances where this is not possible due to the volume of applications.

Please note that this advert may close early if we receive a sufficient number of satisfactory applications.

If you have any difficulty in sending your application or need the application pack in an alternative format, or you require any reasonable adjustments please contact: careers@nestcorporation.org.uk.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background

  • Evidence & case files
  • Financial crime & fraud
  • Intelligence & OSINT
  • Incident command & response
  • Investigative casework

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Full-time

    Your experience managing operational risk and leading incident reviews translates directly into shaping security culture and resilience.

    Posted 2 days ago

  • Information Security Analyst

    Europa Worldwide Group · London

    Full-time

    £40,000 – £45,000Estimated

    Your experience managing evidence, compliance, and risk under ISO standards translates directly into this security assurance role.

    Posted 2 days ago

  • Cyber Security & Compliance Analyst

    Shivom Consultancy Ltd · London

    Full-time

    Your incident management, evidence handling, and risk assessment from policing transfer directly to this role.

    Posted 2 days ago

  • £570 a dayEstimated

    Your experience managing security incidents and coordinating multi-agency responses transfers directly to this governance role.

    Posted 2 days ago