Contractor snapshot
Primary specialism
Other IT Specialism
Location / working location
London
Current availability
Available in 1-3 months
Confirmed 12 Aug 2026
Profile status
Active contractor profile
Professional profile
Senior Contract Lead with 15+ years delivering TPRM, technology third-party governance, material outsourcing and DORA/operational-resilience change across regulated financial services and the Lloyd's market — with third-party AI risk and ISO 42001 AI governance as a specialist differentiator. I translate PRA SS2/21, DORA, the EU AI Act, ISO 42001 and UK GDPR into practical operating models, supplier assurance, control frameworks and Board-ready MI — applying PRA SS1/23 as a model-risk benchmark for AI and model governance at insurers.
Core skills
TPRM
ICT Third-Party Risk Lead
DORA
Material Outsourcing
Operational Resilience
AI Governance & Third-Party AI Risk
ISO 42001 LA
AIGP
CISSP
CRISC
What I’m looking for next
Target roles: Senior TPRM / ICT Third-Party Risk Lead · DORA · Material Outsourcing · Operational Resilience · AI Governance & Third-Party AI Risk
TPRM / ICT Third-Party Risk Lead | DORA · Material Outsourcing · Operational Resilience | AI Governance & Third-Party AI Risk
Contract preferences
Working preferenceRemote · Hybrid
Will workLondon
IR35 preferenceOutside IR35 · Inside IR35
SeniorityPrincipal
Contract length6–12 months
IT experience10 years
Contracting experience10 years
Available from1 Oct 2026
Relevant work experience
Senior Cyber GRC & TPRM & AI Governance Lead (Contract) dmg media · Contract Feb 2026 - Present · 7 mos London Area, United Kingdom · Hybrid Rebuilt a risk-tiered vendor security-assurance framework, clearing an inherited backlog of 40+ high-risk vendors in eight weeks and closing 15+ critical control gaps across ISO 27001:2022, UK GDPR, NIS2 and CIS Controls. Reduced average vendor-assessment cycle time by approximately 30%, from 21 to 14 days, through a rebuilt risk-tiered methodology. Built the organisation’s first AI risk-assessment and control framework for editorial and operational use cases; mapped EU AI Act deployer obligations and Article 14 human-oversight requirements across 5+ active AI initiatives and three business divisions. Created ISO 27001:2022 and UK GDPR audit evidence packs and a 20-metric compliance dashboard used by senior leadership for InfoSec posture and audit-readiness reporting Hamilton Insurance IT GRC Manager (DORA, AI Governance, Model Risk, TPRM, Operational Resilience) Hamilton Insurance · Full-time May 2025 - Dec 2025 · 8 mos London Area, United Kingdom · Hybrid Built an ISO 42001-aligned AI management system and model-risk framework from zero maturity across eight business units, including model inventory, validation oversight, risk tiering and acceptable-use controls for M365 Copilot, enterprise GenAI/LLMs and underwriting AI. Identified and risk-tiered 15+ unsanctioned AI tools through browser telemetry, SSO logs and SaaS-licensing data; developed third-party AI risk methodology covering model transparency, output reliability, data leakage and responsible-AI controls. Designed major ICT incident notification workflows
Experience & credentials
Certifications, sector experience and security clearance are self-declared unless specifically marked as independently verified by IT Contractors UK.
Sector experienceFinancial Services
CertificationsAIGP (IAPP) · ISO 42001 Lead Auditor · ISO 27701 Lead Auditor · ISO 27001 Lead Auditor · CISSP · CCSP · ISSMP (ISC2) · CISM · CRISC (ISACA) · CIPP/E (IAPP) · TOGAF 9 · AWS SAA
Contact details are controlled by the contractor and are not displayed automatically.
Profile information is self-declared unless explicitly marked as verified.