Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Technology Risk Executive image - Rise Careers
Job details

Technology Risk Executive

Welcome to Hastings Direct 

We’re a digital insurance provider with a clear strategy to become the best and biggest player in the UK market. As a company, we’ve made huge investments in our technology, pricing, data and analytics capabilities over the past few years, along with nurturing our 4Cs culture and substantial investment in our people. And as an Assurance, Risk and Compliance team, we're doing the same. The fact you’re now reading this job advert means we’ve tempted you to find out more about #lifeatHD. If you like what you see, we hope you'll consider joining our team.  

We have high standards and understand some people may not apply for jobs unless they feel they tick every box. If you’re excited about joining us and think you have some of what we are looking for, even if you’re not 100% sure, we would love to hear from you.  

Role overview   

You will be supporting the Information Security manager in assuring Hastings’ compliance with its regulatory and legal obligations, by working with the business to help to identify and manage our technology, information and cyber security risks.  

You’ll also be supporting our Operational Resilience activities, undertaking due diligence on our third-party technology suppliers, and assisting with incidents and investigations.   

The role covers organisational security, people security, physical (site) security and technical security controls.  

Skills Knowledge & Experience 

  • Cyber Security KnowledgeYou’ll have a sound understanding of cyber and information security, including frameworks like NIST and ISO IEC 27002:202. It will be great if you also know about PCI-DSS V4.0 as well.

  • Clear Communication -You’ll be able to discuss these with technical and non-technical stakeholders in a way which is accessible and understood.  

  • Threat landscape – You'll understand the current threat landscape in respect of Cyber, Privacy and Security risks, and how that applies to a company like Hastings. 

  • Analytical thinking - You’ll be able to break down complex problems and be always looking for innovative, pragmatic solutions. 

  • Risk managementYou’ll have a good understanding of how to assess and manage technology risk. Even better if you have a solid understanding of Enterprise-Wide Risk frameworks.  

 

Qualifications 

  • A security certification such as CISM, CISMP, CISSP or equivalent would be desirable. 

  • A relevant IT or security-based degree or equivalent practical experience. 

Reward 

Salary – Attractive salary based on experience + car allowance (pay reviews also completed each year) 

Flexible Working – We champion a flexible and hybrid working approach so please speak to your recruiter to discuss in more detail, including days in the office and at home.   

Competitive Bonus Scheme - All colleagues are eligible for our annual 4Cs performance bonus, which is usually paid in March. The scheme is based on Hastings’ performance against our business goals and your own personal performance. 

Physical Wellbeing – as a Band 4 colleague, Hastings pay for you to receive private medical Insurance (also known as PMI) This gives you flexibility and convenience to see a specialist or consultant and allows you to decide when and where you will be seen. 

Financial Wellbeing – As well as providing you with 4x your salary with our life assurance cover and income protection at no extra cost, pension contribution match up to 10%, we are proud to provide you with an AWARD WINNING package which includes – discounts and cashback at everyday retailers and on our own products, fee free independent mortgage advice, and free access to financial wellbeing support. 

Mental Wellbeing programme – At Hastings Direct we understand that mental health cannot not be scheduled, that’s why we have a range of support to help you keep yourself well. We have the thrive mental health app, our colleague assistance programme available 24/7, our own, in-house mental health first aiders, support groups and a dedicated team to make sure we are covering your needs 

There's more! – 27 days annual leave + bank holidays, with the option to buy or sell one of your contracted weeks, access to our health care cash back plans, dental plans, discounted health assessments, Cycle to work and tech schemes, discounted and free onsite facilities, social events throughout the year and much more …. 

Our 4Cs principles are simple: we believe by creating the right culture for our colleagues and giving them the right tools to do their job, we’ll deliver good outcomes for every customer, helping us to grow the company profitably and sustainably and allowing us to invest in the communities we serve. 

At Hastings Direct, we’re committed to creating an inclusive environment where everyone has the opportunity to succeed. If you require any reasonable adjustments during the recruitment process, we encourage you to be open with us. Our recruitment team is here to provide the support you need to ensure a fair and accessible experience for all.

Job posting end date:

04/05/2025

Average salary estimate

$60000 / YEARLY (est.)
min
max
$50000K
$70000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Technology Risk Executive, Hastings Direct

Welcome to Hastings Direct, where we're not just a digital insurance provider; we're on a mission to redefine the UK market! As a Technology Risk Executive, you'll play a crucial role in our Assurance, Risk, and Compliance team, supporting our Information Security Manager to ensure we meet our regulatory and legal obligations. Think of yourself as the gatekeeper of our technology, information, and cyber security risks. Your work will be pivotal in assessing potential threats and ensuring our operational resilience through diligent management of third-party suppliers and tackling incidents with a proactive mindset. If you have a strong grasp of cyber security—from NIST to PCI-DSS V4.0—and the ability to communicate complex ideas simply, we want you on our team! At Hastings, we value analytical thinkers who constantly seek innovative solutions to challenges. Your background in risk management will be invaluable as you help safeguard our organization. We believe in providing our employees with a culture that fosters growth, which is why we offer a flexible working environment, competitive salary packages, and numerous perks to promote well-being. Whether you're engaging with diverse stakeholders or navigating the ever-evolving cyber landscape, your contributions will directly impact our success. We're excited for you to explore #lifeatHD and hope you’ll join us on this adventure!

Frequently Asked Questions (FAQs) for Technology Risk Executive Role at Hastings Direct
What are the main responsibilities of a Technology Risk Executive at Hastings Direct?

As a Technology Risk Executive at Hastings Direct, you will support the Information Security Manager in ensuring compliance with regulatory and legal obligations. Your main responsibilities will include identifying and managing technology, information, and cyber security risks, supporting operational resilience activities, conducting due diligence on third-party technology suppliers, and assisting with incident management and investigations.

Join Rise to see the full answer
What qualifications are needed for the Technology Risk Executive role at Hastings Direct?

For the Technology Risk Executive position at Hastings Direct, candidates should hold a relevant IT or security-based degree or equivalent practical experience. Additionally, possessing a security certification such as CISM, CISMP, or CISSP is desirable, along with a solid understanding of cyber security frameworks like NIST and ISO IEC 27002:202.

Join Rise to see the full answer
What skills are essential for the Technology Risk Executive role at Hastings Direct?

Essential skills for the Technology Risk Executive role at Hastings Direct include a strong understanding of cyber and information security, clear communication abilities to convey technical topics to non-technical stakeholders, analytical thinking skills for problem-solving, and knowledge of risk management practices, particularly in assessing technology risks.

Join Rise to see the full answer
What career growth opportunities exist for a Technology Risk Executive at Hastings Direct?

At Hastings Direct, a Technology Risk Executive will have abundant career growth opportunities, including access to continuous professional development programs, mentorship from experienced colleagues, and involvement in diverse projects. The company values its employees and fosters a culture aimed at empowering them to take on leadership roles.

Join Rise to see the full answer
How does Hastings Direct support employee wellbeing for a Technology Risk Executive?

Hastings Direct is committed to the well-being of its employees, providing a range of support programmes, including private medical insurance, financial wellbeing assistance, mental health resources, and flexible working options. As a Technology Risk Executive, you will also benefit from generous leave policies and access to wellness initiatives to ensure a balanced work-life environment.

Join Rise to see the full answer
Common Interview Questions for Technology Risk Executive
What experience do you have with cyber security frameworks relevant to this role?

When answering this question, highlight your knowledge of frameworks such as NIST and ISO IEC 27002:202. Provide specific examples from your previous roles where you've applied these frameworks to enhance security practices or comply with regulations.

Join Rise to see the full answer
How do you stay updated on the latest threats in the cyber landscape?

Discuss your strategies for staying informed about evolving cyber threats, such as subscribing to industry publications, participating in online forums, attending relevant conferences, and engaging with professional networks. Emphasize your proactive approach to learning and adaptation.

Join Rise to see the full answer
Can you explain a time when you identified a technology risk and how you managed it?

Use a STAR (Situation, Task, Action, Result) approach to describe a specific instance where you identified a technology risk. Detail the evaluation process you undertook, the steps you implemented to mitigate the risk, and the positive outcomes that resulted from your interventions.

Join Rise to see the full answer
How do you communicate technical security information to non-technical stakeholders?

When answering, highlight your communication skills. Discuss your methods for simplifying complex concepts into accessible language and using visual aids or analogies. Share an example where your effective communication led to improved understanding or decision-making.

Join Rise to see the full answer
What role does risk management play in the technology sector?

Explain the importance of risk management in safeguarding technology assets and ensuring compliance with regulations. Discuss how a proactive risk management strategy contributes to an organization's operational resilience and promotes trust among stakeholders.

Join Rise to see the full answer
Describe your experience working with third-party technology suppliers.

Discuss any previous experience conducting due diligence assessments, evaluating the security postures of third-party suppliers, and managing vendor relationships. Highlight your understanding of how these relationships can impact overall security and compliance.

Join Rise to see the full answer
How do you approach incident response and investigations?

Share your structured approach to incident response, which includes preparation, identification, containment, eradication, recovery, and lessons learned. Provide an example of a specific incident you managed, detailing your actions and the results.

Join Rise to see the full answer
What analytical tools or software are you familiar with for risk assessment?

Mention any analytical tools or software you've used for risk assessment, such as security information and event management (SIEM) systems, vulnerability management tools, and risk assessment frameworks. Emphasize how you've utilized these tools to improve security postures.

Join Rise to see the full answer
Why do you want to work at Hastings Direct as a Technology Risk Executive?

Articulate your interest in Hastings Direct by mentioning their commitment to innovation in the insurance sector, their robust support for employee wellbeing, and their inclusive culture. Align your career goals with the company's vision and values to show your enthusiasm for the role.

Join Rise to see the full answer
What do you believe are the biggest challenges facing technology risk professionals today?

Identify current trends impacting technology risk, such as the rise of sophisticated cyber attacks, compliance with stringent regulations, and the challenges of remote work. Discuss how you would address these challenges and contribute positively to Hastings Direct's resilience as a Technology Risk Executive.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Inclusive & Diverse
Mission Driven
Social Impact Driven
Passion for Exploration
Dare to be Different
Diversity of Opinions
Reward & Recognition
Empathetic
Feedback Forward
Work/Life Harmony
Collaboration over Competition
Growth & Learning
Transparent & Candid
Customer-Centric
Rise from Within
Friends Outside of Work
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Learning & Development
Work Visa Sponsorship
Employee Resource Groups
401K Matching
Paid Time-Off
Maternity Leave
Social Gatherings
Company Retreats
Photo of the Rise User
Solace Remote No location specified
Posted 3 days ago

Join Solace as a Lead Security Engineer and help build a secure healthcare advocacy platform that impacts patient outcomes.

Posted 7 days ago

As a Senior Cybersecurity Risk Analyst, you will lead initiatives to protect military systems by implementing cutting-edge security solutions.

Photo of the Rise User
Anduril Industries Hybrid Washington, District of Columbia, United States
Posted 14 days ago

Join Anduril Industries as a Security Engineer specializing in Mergers & Acquisitions to fortify security during the integration of acquired companies.

Photo of the Rise User
Broadway Gaming Remote No location specified
Posted 10 hours ago

Broadway Gaming seeks a talented Dev Ops engineer to orchestrate containerized applications and automate infrastructure provisioning.

Photo of the Rise User

Seeking an enthusiastic IT Architecture Intern to work alongside experienced professionals at Eversource Energy in Berlin, CT.

Photo of the Rise User
Kantar Hybrid US, Miami-Dade County, FL; Florida, Miami, FL
Posted 12 days ago

TechEdge seeks a Systems Operations Engineer to enhance operational support for its media-focused services in Miami.

Photo of the Rise User
Citi Hybrid Rutherford, New Jersey, United States
Posted yesterday
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony

Citi seeks an experienced Director for the Enterprise Risk Technology Data Lead position to manage Data Use Cases across risk management functions.

MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
HQ LOCATION
No info
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
April 12, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Cincinnati just viewed Global Supply Manager (Raptor Machining) at SpaceX
Photo of the Rise User
Someone from OH, Reynoldsburg just viewed Summer 2025 Financial Services Internship at Nationwide
Photo of the Rise User
Someone from OH, Brunswick just viewed Staff Software Engineer C++ / Computer Vision at ABBYY
Photo of the Rise User
Someone from OH, Columbus just viewed Label Machine Operator I - 2nd Shift at Avery Dennison
Photo of the Rise User
Someone from OH, North Ridgeville just viewed Java, Javascript, Python, NodeJS Software Engineer at Walmart
R
Someone from OH, Dublin just viewed Supply Chain Lead (Clinical Supply) at Resultance
Photo of the Rise User
Someone from OH, Columbus just viewed Scrum Master at Sysco Costa Rica
Photo of the Rise User
54 people applied to Cybersecurity Intern at Dewberry
X
Someone from OH, Cincinnati just viewed Senior Java Engineer (Remote) at Xenon7
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior, Software Engineer- Java at Walmart
Photo of the Rise User
6 people applied to Security Analyst at ANS
Photo of the Rise User
Someone from OH, Pickerington just viewed Senior Business Analyst (Salesforce) at Protolabs
H
Someone from OH, Akron just viewed Brand Marketing Manager at Huntington
R
Someone from OH, Hamilton just viewed Forklift Operator Warehouse at Ryder
Photo of the Rise User
Someone from OH, Cincinnati just viewed Ad Ops Specialist, Display at System1
Photo of the Rise User
Someone from OH, Cincinnati just viewed FQHC Billing & Collections Manager at OhioGuidestone
Photo of the Rise User
Someone from OH, Cleveland just viewed Enrollment Specialist- Remote at Adtalem Global Education
o
Someone from OH, Dayton just viewed Marketing and Communications Specialist at osu
Photo of the Rise User
Someone from OH, Columbus just viewed Construction Coordinator at Meijer
Photo of the Rise User
Someone from OH, Steubenville just viewed Legal & Compliance Internship at Smiths Group
Photo of the Rise User
Someone from OH, Warren just viewed Senior Front-End Developer at Worldly