Senior IT Governance, Risk & Compliance Specialist
About Us
Skybound Wealth Management is a global financial advisory company with employees across the UK, USA, Switzerland, Cyprus, Spain and UAE. We provide tailored financial advice to international clients, supported by expert teams across wealth planning, compliance and operations.
Role Overview
Skybound Wealth Management is building a dedicated internal global IT function to support a rapidly growing, multi-jurisdictional financial-services business.
We are looking for an experienced Senior IT Governance, Risk & Compliance Specialist to take ownership of the governance, risk and regulatory-control framework surrounding Skybound’s technology environment.
This is not a general corporate compliance role and it is not solely an audit or assurance position.
The successful candidate will sit within the IT function and work closely with Infrastructure, Cybersecurity, Risk, Compliance, Data Protection and external technology providers to ensure Skybound’s technology environment is appropriately controlled, documented, evidenced and regulator-ready.
The role requires someone who can understand a technical environment, identify weaknesses, translate regulatory requirements into practical IT controls, establish repeatable governance processes and provide clear evidence to management, auditors and regulators.
The successful candidate must be comfortable operating between technical teams, business stakeholders, auditors and regulators.
Key Responsibilities
IT Governance
Develop, maintain and continuously improve Skybound’s IT governance framework.
Establish clear control ownership across Infrastructure, Cybersecurity and wider technology operations.
Define governance processes and recurring review cycles for key technology controls.
Maintain a structured IT governance calendar covering reviews, certifications, testing, evidence collection and policy updates.
Ensure technology processes are documented, repeatable and consistently followed across relevant entities and jurisdictions.
Work with technical teams to ensure operational practice aligns with documented policy and governance requirements.
Establish appropriate management reporting covering IT risk, controls, remediation and governance.
IT Risk Management
Own and maintain the IT Risk Register.
Support and maintain the Cybersecurity Risk Register in conjunction with the Cybersecurity function.
Identify and assess technology, cybersecurity, resilience and third-party risks.
Define appropriate risk treatments, owners, actions and target dates.
Monitor remediation plans and ensure actions are evidenced through to closure.
Escalate material technology risks to the Head of IT and senior management.
Support risk assessments for new technology, infrastructure changes, vendors and major projects.
Ensure risk decisions, exceptions and accepted risks are appropriately documented and approved.
Regulatory Technology Compliance
Interpret technology-related regulatory requirements and translate them into practical controls, policies and evidence.
The role will support Skybound’s requirements across multiple regulated entities and jurisdictions, including areas such as:
Digital Operational Resilience Act (DORA)
Regulation S-P
GDPR and data-protection requirements
operational resilience
cybersecurity requirements
outsourcing and third-party technology risk
local regulatory requirements applicable to Skybound entities
Responsibilities will include:
reviewing applicable regulatory requirements;
mapping requirements to technology controls;
performing gap assessments;
coordinating remediation;
maintaining supporting evidence;
tracking regulatory actions;
supporting submissions and audit responses;
ensuring implemented controls remain effective over time.
The role will work closely with the company’s Compliance and Risk functions, but will own the technology governance and control implementation framework within IT.
Policies, SOPs & Control Documentation
Develop and maintain IT and cybersecurity policies in collaboration with Infrastructure and Cybersecurity teams.
Create practical Standard Operating Procedures for key IT processes.
Ensure policies accurately reflect the actual technology environment.
Maintain document ownership, approval, review dates and version control.
Ensure regulatory and policy requirements are translated into operational procedures.
Maintain a structured repository of IT governance documentation.
Regularly review policies and procedures following system, regulatory or organisational change.
Key documentation may include:
Information Security Policy
Access Control Policy
Joiner / Mover / Leaver procedures
Incident Response procedures
Acceptable Use Policy
Business Continuity and Disaster Recovery procedures
Vulnerability Management Policy
Privileged Access procedures
Third-Party Technology Risk procedures
Change Management procedures
Device and Endpoint Management procedures
IT Asset Management procedures
Audit & Regulatory Support
Act as a key technology contact for internal audits, external audits and regulatory reviews.
Coordinate technical responses to audit and regulatory questions.
Gather evidence from Infrastructure, Cybersecurity and third-party providers.
Review evidence for completeness and accuracy before submission.
Maintain recurring evidence for common control areas.
Track audit findings, recommendations and remediation activity through to closure.
Ensure technology teams understand audit findings and required actions.
Support management responses to audit and regulatory findings.
Develop an organised audit-evidence repository to reduce repeated manual work
The objective is for Skybound to be able to explain and evidence its own technology environment without being completely dependent on external providers.
Identity & Access Governance
Establish governance around user access and privileged access.
Coordinate periodic user-access reviews.
Coordinate administrator and privileged-role reviews.
Monitor joiner, mover and leaver control effectiveness.
Ensure access changes have appropriate approvals and evidence.
Review access exceptions and ensure they are documented and periodically reassessed.
Work with Infrastructure and Cybersecurity on governance surrounding:
Microsoft Entra ID
MFA
Conditional Access
privileged roles
authentication
service accounts
application access
The technical configuration may sit with Infrastructure or Cybersecurity, while governance, review and evidence sit with this role.
Cybersecurity Governance
The Cybersecurity function will own the technical implementation and operation of security controls.
This role will own the governance surrounding those controls.
Areas of collaboration will include:
cybersecurity policies
incident governance
vulnerability-management governance
penetration-test remediation tracking
security-control reviews
phishing and awareness governance
risk treatment
cybersecurity reporting
regulatory cybersecurity obligations
exceptions and compensating controls
For example:
Cybersecurity may implement and manage Microsoft Defender.
This role ensures:
the control requirement is defined;
ownership is documented;
the control is reviewed;
appropriate evidence is retained;
weaknesses are tracked;
regulatory requirements are met.
Third-Party & Outsourcing Risk
Develop and maintain technology vendor-risk governance.
Perform or coordinate due-diligence assessments for technology suppliers.
Maintain records of critical suppliers and outsourced technology services.
Assess supplier security, resilience, controls and regulatory impact.
Maintain oversight of Managed Service Providers and other critical vendors.
Track supplier risks and remediation actions.
Support DORA and other outsourcing / third-party risk requirements.
Ensure appropriate review cycles for critical providers.
Maintain evidence of supplier oversight.
This includes governance over outsourced technology services such as MSPs, cloud providers, cybersecurity vendors and other critical technology partners.
Business Continuity & Operational Resilience
Maintain IT governance around Business Continuity and Disaster Recovery.
Ensure critical technology services have documented recovery requirements.
Coordinate business-impact and technology-resilience reviews where required.
Establish testing schedules for BCP and DR controls.
Coordinate periodic resilience testing with Infrastructure and Cybersecurity teams.
Record results, weaknesses and remediation actions.
Maintain evidence demonstrating that recovery arrangements have been tested.
Support operational-resilience requirements under DORA and other applicable frameworks.
Track resilience risks and improvements.
Control Testing & Assurance
Develop a structured IT control-testing programme.
Test whether documented controls are actually being performed.
Conduct periodic sampling and evidence reviews.
Identify control failures and weaknesses.
Track corrective action.
Perform or coordinate control maturity assessments.
Support continuous improvement of the IT control environment.
Examples may include:
sampling leavers to confirm access was removed correctly;
testing privileged-access reviews;
reviewing device-compliance evidence;
checking vulnerability remediation;
reviewing backup / recovery testing;
verifying security exceptions;
validating third-party reviews.
IT Reporting & Management Information
Produce clear reporting for the Head of IT and senior management covering:
key technology risks;
cybersecurity risks;
open audit findings;
remediation activity;
policy status;
control-testing results;
regulatory actions;
access reviews;
third-party risk;
BCP / DR testing;
significant control exceptions.
The role should be capable of turning detailed technology and risk information into clear management-level reporting.
Key Projects
The successful candidate will be expected to lead or materially contribute to projects including:
DORA implementation and ongoing governance
Regulation S-P technology controls
Global IT Governance Framework
IT Policy Framework
Cybersecurity Policy Framework
IT Risk Register
Cybersecurity Risk Register
IT Control Framework
Audit Evidence Repository
Access Review Programme
Joiner / Mover / Leaver Governance
Third-Party Technology Risk Framework
Business Continuity / Disaster Recovery Governance
Operational Resilience Programme
Regulatory Technology Gap Assessments
IT Governance Calendar
Technology Supplier Review Programme
Audit and Regulatory Readiness
IT Control Testing Programme
Governance supporting Microsoft 365 entity / tenancy architecture
Required Experience
We are looking for approximately 5–8 years of relevant experience in one or more of the following areas:
IT Governance, Risk & Compliance
Technology Risk Management
IT Audit
Information Security Governance
Cybersecurity GRC
Information Security Compliance
Operational Resilience
Third-Party Technology Risk
IT Controls
Regulatory Technology Compliance
Experience in banking, financial services, payments, insurance, wealth management or another regulated environment is strongly preferred.
Candidates should have demonstrable experience in several of the following:
owning IT or cybersecurity risk registers;
preparing for and responding to audits;
managing IT controls;
developing policies and SOPs;
carrying out risk assessments;
implementing regulatory requirements;
coordinating remediation;
control testing;
third-party risk;
access governance;
BCP / DR;
audit evidence management.
Technical Understanding
This is not an infrastructure engineering position, but the successful candidate must be technically credible.
You should understand the purpose and control implications of technologies such as:
Microsoft 365
Microsoft Entra ID
Exchange Online
Microsoft Intune
Conditional Access
MFA
Microsoft Defender
Microsoft Sentinel / SIEM
Microsoft Purview
Mimecast / email security
endpoint management
vulnerability management
networks
firewalls
privileged access
backup and recovery
cloud environments
cybersecurity monitoring
You are not expected to configure all of these systems yourself.
You are expected to understand them well enough to:
challenge technical teams;
assess control effectiveness;
identify risk;
determine evidence requirements;
explain the control to an auditor or regulator.
Framework & Regulatory Knowledge
Experience with several of the following is preferred:
DORA
GDPR
Regulation S-P
ISO 27001
SOC 1 / SOC 2
NIST Cybersecurity Framework
COBIT
CIS Controls
PCI DSS
CSA STAR
ITIL
operational-resilience frameworks
business-continuity standards
Candidates are not expected to know every framework.
More important is the ability to take a regulatory or framework requirement and convert it into a practical, sustainable technology control.
Qualifications
A degree in one of the following or a related discipline is preferred:
Information Technology
Information Security
Cybersecurity
Information Systems
Risk Management
Computer Science
Relevant professional certifications are advantageous, including:
CISA
CRISC
CISM
CISSP
ISO 27001 Lead Auditor
ISO 27001 Lead Implementer
COBIT
relevant privacy, risk or resilience qualifications
Certifications are desirable but practical experience is more important.
Skills & Attributes
The successful candidate should demonstrate:
strong analytical capability;
excellent written documentation;
attention to detail;
strong organisation;
ability to manage multiple remediation items simultaneously;
confidence dealing with senior stakeholders;
ability to communicate with both technical and non-technical audiences;
ability to challenge constructively;
strong ownership;
good judgement;
ability to work independently;
ability to translate regulation into practical action.
What Good Looks Like
The strongest candidate will be able to take a requirement such as:
“Privileged access must be appropriately controlled.”
and turn it into:
a documented control;
a clear owner;
a defined approval process;
a recurring access review;
appropriate technical implementation;
documented exceptions;
evidence retained for audit;
testing to ensure the control is working;
remediation where it fails;
management reporting.
We are not looking for someone who simply maintains compliance spreadsheets or forwards audit questions to technical teams.
We are looking for someone who builds and maintains the governance framework around the technology environment.
Why This Role Matters
Skybound is moving from an IT model heavily dependent on external providers toward an internally owned global technology function.
The future structure will include dedicated capability across:
Infrastructure
Cybersecurity
IT Governance, Risk & Compliance
Infrastructure will build and operate the technology. Cybersecurity will implement and operate technical security controls.
The IT Governance, Risk & Compliance function will ensure those controls are appropriately designed, documented, governed, tested and capable of standing up to management, audit and regulatory scrutiny.
This role will therefore be central to building Skybound’s future global IT operating model.
Skybound Wealth Management is committed to fostering a diverse and inclusive workplace. We welcome applications from all qualified candidates regardless of background.
- Department
- Technology
- Locations
- Mumbai Office
- Remote status
- Hybrid
About Skybound Wealth Management
Skybound Wealth Management is an international wealth management group, operating across the UK, Switzerland, Europe, USA and Middle East. We provide financial advice to internationally connected individuals wherever they are in the world.