Rodeo
Get started

Nest Pensions

Technology and Data Risk Manager

London
Posted about 22 hours ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Role Overview

The Technology & Data Risk Manager is a new second line of defence role within the Risk Directorate, responsible for providing independent oversight, assurance and expert challenge across technology, data, cyber security, and related operational risks.

Reporting to the Head of Technical Risk and Data Protection Officer, the role supports the effective management of technology and data risks by ensuring first line teams identify, assess and mitigate risks in line with Nest’s risk appetite while enabling the organisation to deliver its strategic objectives securely and efficiently.

Working across the organisation, the role promotes strong risk management practices, providing expert challenge on technology, data protection, information security, and third-party risk matters. It plays a key role in strengthening governance, embedding a strong data protection and security culture, and supporting compliance with regulatory requirements and recognised standards, including UK GDPR, the Data Protection Act 2018 and ISO 27001.

The Technology & Data Risk Manager also helps the organisation anticipate and respond to emerging risks and opportunities, including developments in artificial intelligence, evolving cyber threats, and third-party dependencies. Through effective stakeholder engagement, assurance activity and risk reporting, the role contributes to maintaining a resilient, compliant, and well-controlled technology and data environment across Nest.

The Minimum Criteria for This Role Are:

Essential

  • Sound knowledge of information security and data risk domains (access control, vulnerability management, logging and monitoring, incident response, secure development etc).
  • Experience in technology, data, security, or technical risk management including control frameworks such as ISO 27001 and NIST, ideally within a regulated or complex organisation.
  • Strong understanding of second line assurance and oversight, including how to challenge constructively while remaining independent.
  • Experience of assessing third-party technical risk.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Desirable

  • Experience with product security and secure SDLC assurance.
  • Knowledge of AI risk, data ethics or emerging technology governance.
  • Working knowledge of UK GDPR and the Data Protection Act 2018.
  • Knowledge of threat intelligence, vulnerability disclosure, and security testing approaches.
  • Relevant professional certifications (e.g. CISM, CISSP, ISO 27001 LI/LA, CRISC, ITIL).

Don't worry if you think you don't have all the key skills, it might be worth taking the few minutes to apply as we're good at spotting potential. At Nest, you’ll have access to a range of learning opportunities to learn, grow and build the skills you need to be successful in your role and career.

Flexible and Agile Working

Everyone's personal situation is different.

To make the most out of hybrid working, we've introduced different ways of working, which include (subject to role requirements):

  • Hybrid of office (Canary Wharf, London) and home working (there will be an expectation to attend the office, once - twice a week, or more, as required)
  • Vary working hours

Directorate/Department Overview

The Technical Risk team sits within the Risk Directorate, along with Risk, Risk Assurance, Risk Operations and Regulatory Risk, and Controls Oversight. The directorate supports the business in delivering its strategic priorities by overseeing that risk and controls are identified, prioritised and managed through an enterprise risk management framework. Nest operates a ‘three lines of defence’ model, with Risk sitting in the second line providing advice, guidance and challenge to the first line.

The Technical Risk team provides support to Nest specifically in relation to risks covering data, privacy, technology, cyber and financial crime. Support includes conducting investigations, regulatory reporting as well as training and awareness across Nest Corporation.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Organisational Overview

Nest is an award-winning workplace pension scheme, the largest in the country. Set up by the government to give every worker in the UK somewhere to save, our first-class responsible investment practice and governance are the backbone of what we do, supported by all the functions you’d expect to find in a thriving business. We’re committed to creating a workplace where you can be your authentic self and offer an inclusive and flexible working environment.

Diversity, Equity and Inclusion

Everyone is welcome to apply for our roles, and we are determined to ensure that no applicant or employee receives less favourable treatment because of their age, disability, gender identity, marital status, national origin, pregnancy or caring responsibilities, race, religion/belief, sex, sexual orientation or socio economic background.

We also recognise the importance of diversity of thought and other forms of neurocognitive variation.

Nest is a Disability Confident Leader, which is the highest level of the Disability Confident Scheme. If you have a disability, please declare that you’re applying through the scheme.

We aim to offer an interview to those applicants who apply through the Disability Confident Scheme and best meet the minimum criteria. However, there may be some circumstances where this is not possible due to the volume of applications.

Please note that this advert may close early if we receive a sufficient number of satisfactory applications.

If you have any difficulty in sending your application or need the application pack in an alternative format, or you require any reasonable adjustments please contact: careers@nestcorporation.org.uk.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Information Security
Data Risk Management
Cyber Security
ISO 27001
NIST
Third-Party Risk Assessment
UK GDPR
Data Protection Act 2018
Secure SDLC
AI Risk Governance
Risk Reporting
Stakeholder Engagement
Vulnerability Management
Incident Response
Access Control
Second Line Assurance

Location

London, England, United Kingdom

Sign up to applySee more jobs like this