Creditspring
Senior Enterprise Risk Analyst

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
We are Creditspring
A new way of borrowing that focuses on its members and provides them with safe and efficient short-term financial products.
We're a fast-growing FCA-regulated consumer credit company. We have members, not customers and we take a lot of pride in that!
As one of the UK’s only subscription finance company in the market, we truly have a unique value proposition. Our mission is very clear; to improve the financial stability and resilience of our members. We do this through the products we provide, the partnerships we have, and our educational content. We want our members, and everyone in the UK to be able to better manage their finances and steer them away from high-cost, unregulated credit options.
About the role
To support day-to-day operation and continuous improvement of the Enterprise Risk Management Framework, acting as the lead administrator of the Protecht GRC system, which is used to capture, detail and manage risks across the business.
Responsibilities
- Act as the primary day-to-day point of contact for risk owners, supporting them through the RCSA cycle — scheduling, preparing materials, facilitating workshops and helping owners articulate risks, controls and actions clearly.
- Manage and support risk owner follow-up processes: update outstanding actions, controls testing and RCSA updates, escalating overdue or high-risk items appropriately.
- Monitor system-generated alerts from Protecht and work directly with risk owners to investigate, triage and resolve them in a timely manner.
- Act as lead user of the Protecht platform and its data: manage user permissions, workflows, risk and control libraries, taxonomies, and reporting/dashboard configuration.
- Be the organisation's go-to system expert for Protecht, providing training, troubleshooting and ongoing user support to risk, control and action owners across the business.
- Own system data quality — ensure risks, controls, actions and incidents are captured, updated and reviewed in line with agreed cycles.
- Horizon scan across the business to identify areas where Protecht is underused or used incorrectly, and take action to improve adoption and correct usage.
- Manage system enhancements, upgrades and releases, liaising with Protecht and internal stakeholders (e.g. IT) as needed.
- Build and maintain reports, dashboards and extracts from Protecht to support risk reporting and committee papers.
- Work with 2nd and 3rd line QA functions (Operational Risk, Credit Risk, Compliance) to support alignment with risk appetite, and to identify changes to current risks or new risks arising from their activities, escalating as appropriate.
- Document minutes of the Technology and Resilience Risk Committee meetings and collate the monthly risk pack in preparation for the meeting.
- Support the production of Key Risk Indicator (KRI) reporting and the quarterly risk pack for senior management and the Board.
- Support the maintenance of risk management policies, procedures and the Risk Management Framework documentation.
- Support incident management activity, including data quality in Protecht and thematic analysis for reporting.
- Support the business's response to internal/external audit and regulatory queries relating to risk management, and track remedial actions to completion.
- Support risk culture initiatives and training to raise risk awareness and engagement across the business.
- Undertake ad hoc tasks and projects as agreed with the Senior Operational Risk Manager
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
What you'll need to succeed
Essential:
- Experience administering a GRC/RMIS platform (e.g. Protecht, Symbiant, or similar). Protecht experience strongly preferred.
- Experience facilitating RCSAs or similar risk workshops with business stakeholders
- A minimum of 2-3 years working within in a regulated financial services/consumer credit business.
- Strong working knowledge of risk management frameworks, taxonomies and reporting (risks, controls, actions, incidents, KRIs).
- Keen attention to detail and excellent written and oral communication skills, able to work effectively with other to achieve results.
- Comfortable working with data and able to use data to identify issues or opportunities.
- Proactive and perceptive with the ability to identify tasks and escalate issues appropriately.
- Well-organised and self-sufficient with the ability to deliver within set timescales.
- Resilient, collaborative, and flexible with a pragmatic approach to problem-solving.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Desirable:
- Financial services risk management experience
- Experience working with the NIST Cybersecurity Framework (CSF) 2.0 methodology.
- A recognised risk management qualification (e.g. IRM) or working towards one.
Don’t meet all the listed requirements? Research shows that women and people of underrepresented groups often don't apply for jobs unless they're 100% qualified. As an equal opportunities employer, we know that diversity is a key part of our teams' successes - so if your experience doesn’t fit perfectly but this role excites you, we’d love for you to apply. We’re committed to Creditspring being an inclusive environment where employees feel welcomed, valued and listened to; we want you to thrive as your true self.
Please note that the People Team is contactable only via people@creditspring.co. Unsolicited emails to other team members will not be actioned.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location