Information Security Third Party Assurance Analyst

Reference: hgr25kpvuzrcpfmng6tp

We are seeking an Information Security Third Party Assurance Analyst to support the assessment and ongoing oversight of the organisation’s suppliers, partners and other external service providers. In this role, you will help ensure that third parties meet required information security, privacy, resilience and risk management standards before and throughout the relationship lifecycle. You will work closely with procurement, legal, technology, privacy, risk and business teams to provide clear, practical assurance and support informed risk-based decisions.

Your responsibilities will include reviewing supplier security questionnaires, independent assurance reports, policies, certifications and other evidence; assessing controls against recognised frameworks and internal requirements; identifying gaps, risks and areas requiring remediation; and documenting findings in a consistent and auditable manner. You will maintain accurate records of assessments, track remediation plans and follow up on outstanding actions. The role will also involve contributing to onboarding and periodic reviews, supporting risk acceptance processes, preparing management reporting and escalating material concerns where appropriate. You may assist with improving third-party risk procedures, assessment templates, guidance materials and reporting dashboards.

We are looking for experience in information security, supplier assurance, technology risk, audit, compliance or a closely related field. You should have a sound understanding of security controls and common frameworks such as ISO 27001, SOC 2, NIST or CIS, together with familiarity with data protection, business continuity, access management, vulnerability management and incident response. Strong analytical and organisational skills are essential, as is the ability to interpret technical evidence and communicate its implications clearly to both technical and non-technical stakeholders. Experience using governance, risk and compliance tools or managing multiple assessments simultaneously would be advantageous. Relevant professional qualifications or certifications are welcomed, although practical experience and a proactive, collaborative approach are equally valued.

COMPETITIVE SALARY
Added 03/09/2026
Reference: hgr25kpvuzrcpfmng6tp

Information Security Third Party Assurance Analyst

Windsor, England, United Kingdom Permanent Information Assurance

Other similar jobs

Application Security Engineer

Added 11/09/2026

We are seeking an Application Security Engineer to help strengthen the security of modern software applications throughout their development lifecycle. You will work closely with software engineers, architects, DevOps specialists and product teams to identify security risks early, promote secure engineering practices and support the delivery of resilient, high-quality applications. This role offers the opportunity to influence security strategy while remaining hands-on with technical assessment and remediation. Your responsibilities will include designing and maintaining application security processes, integrating security controls into CI/CD pipelines, and conducting code reviews, threat modelling, vulnerability assessments and penetration testing. You will investigate findings from automated...

Learn more

Director, IT Security Third Party Monitor & Compliance

Added 09/09/2026

We are seeking a Director, IT Security Third Party Monitor & Compliance to lead the governance, oversight, and continuous improvement of third-party information security and compliance activities. This senior role will establish and maintain a comprehensive framework for assessing suppliers, service providers, and strategic partners throughout the relationship lifecycle. You will ensure that third-party risks are identified, evaluated, documented, and managed in line with applicable regulatory obligations, internal policies, contractual requirements, and recognised industry standards. Key responsibilities include directing third-party security assessments, reviewing control evidence, monitoring remediation plans, and providing clear risk-based reporting to senior leadership and relevant governance committees....

Learn more

Third Party Security Due Diligence Lead

Added 09/09/2026

We are seeking a Third Party Security Due Diligence Lead to oversee the assessment and management of information security risks associated with suppliers, partners and other external service providers. In this role, you will lead the end-to-end due diligence process, ensuring that third parties meet defined security, privacy, resilience and compliance requirements before and throughout the relationship lifecycle. You will work closely with procurement, legal, privacy, technology, risk and business stakeholders to provide clear, practical and risk-based recommendations. Your responsibilities will include designing and maintaining third-party security assessment processes, reviewing security questionnaires and supporting evidence, and evaluating controls across areas...

Learn more

Third Party Cyber Risk Lead

Added 25/08/2026

We are seeking an experienced Third Party Cyber Risk Lead to strengthen the management of cyber security risks across a complex supplier and partner ecosystem. In this role, you will develop and oversee a proportionate third-party cyber risk management framework, helping ensure that suppliers meet security expectations throughout the procurement, onboarding, monitoring, renewal and offboarding lifecycle. You will work closely with procurement, legal, information security, technology, risk and business stakeholders to embed effective controls and provide clear, practical advice. Your responsibilities will include conducting and overseeing supplier cyber risk assessments, reviewing security questionnaires and independent assurance reports, identifying control gaps,...

Learn more

Third Party Cyber Risk Lead

Added 25/08/2026

We are seeking an experienced Third Party Cyber Risk Lead to strengthen the management of cyber security risks across our external supplier and partner ecosystem. In this role, you will lead the development and delivery of a robust third-party cyber risk management programme, helping ensure that suppliers meet required security, resilience, privacy and regulatory standards. You will work closely with procurement, legal, technology, information security, risk and business teams to embed effective controls throughout the supplier lifecycle. Your responsibilities will include defining and maintaining third-party cyber risk policies, standards, procedures and assessment methodologies; conducting risk assessments and due diligence for...

Learn more

Cyber Operations & 3rd Party Security Manager

Added 01/09/2026

We are seeking a Cyber Operations & 3rd Party Security Manager to lead the development, operation and continual improvement of cyber security capabilities across a complex technology and supplier landscape. This role will help protect critical systems, information and services by overseeing security operations, coordinating incident response and ensuring that third-party relationships meet appropriate security standards. You will work closely with technology, risk, compliance, procurement and business stakeholders to embed practical, proportionate and effective security controls. Key responsibilities will include managing day-to-day cyber operations, monitoring security events and vulnerabilities, coordinating responses to incidents and supporting investigations, remediation and lessons learned....

Learn more

Security Assurance Solutions Architect, AWS Security Assurance Services

Added 09/09/2026

We are seeking a Security Assurance Solutions Architect to help customers design, implement and validate secure solutions across cloud environments. In this role, you will act as a trusted security advisor, translating complex assurance requirements into practical technical architectures, controls and implementation plans. You will work with security, risk, compliance, engineering and business stakeholders to understand their objectives and guide them towards resilient, compliant and scalable outcomes. Key responsibilities include developing security assurance strategies; mapping regulatory, contractual and industry requirements to technical and organisational controls; reviewing architectures and identifying security gaps; and recommending pragmatic remediation approaches. You will support customer...

Learn more

Security Assurance Solutions Architect, AWS Security Assurance Services

Added 09/09/2026

We are seeking a Security Assurance Solutions Architect to help customers design, implement, and operate secure, resilient technology environments. In this role, you will serve as a trusted security advisor, translating complex regulatory, risk, and compliance requirements into practical technical solutions. You will work closely with security, engineering, architecture, risk, and compliance teams to develop assurance strategies that support business objectives while maintaining strong security controls. Your responsibilities will include assessing customer environments, identifying security and compliance gaps, and recommending improvements across governance, identity and access management, data protection, infrastructure security, monitoring, incident response, and resilience. You will create and...

Learn more

Senior Security Assurance Specialist , AWS Compliance and Security Assurance EMEA

Added 19/08/2026

We are seeking a Senior Security Assurance Specialist to join our team, focusing on compliance and security assurance across the EMEA region. In this role, you will be responsible for leading security assessments, audits, and compliance initiatives to ensure alignment with industry standards and regulatory requirements. You will collaborate with various stakeholders, including engineering, product management, and legal teams, to develop and implement security policies, procedures, and best practices. Your expertise will be crucial in identifying vulnerabilities and recommending effective mitigation strategies to enhance security posture. The ideal candidate will have a strong background in information security, risk management, and...

Learn more

Security Assurance Specialist , AWS Compliance and Security Assurance EMEA

Added 19/08/2026

We are seeking a detail-oriented Security Assurance Specialist to join our dynamic team focused on compliance and security assurance within the EMEA region. In this role, you will be responsible for evaluating and implementing security measures to protect sensitive information and ensure compliance with industry regulations. Your expertise will be crucial in assessing risks, conducting audits, and developing strategies to enhance the security posture of our cloud services. You will collaborate with cross-functional teams to identify vulnerabilities and recommend solutions that align with best practices and compliance requirements. The ideal candidate will possess a strong understanding of cloud security frameworks...

Learn more

Security Assurance Manager, Security Assurance

Added 19/08/2026

We are seeking a dedicated Security Assurance Manager to oversee and enhance our security assurance framework. In this pivotal role, you will be responsible for identifying, assessing, and mitigating security risks across all operations. You will lead a team of security professionals in conducting thorough security assessments, audits, and risk analyses to ensure compliance with industry standards and regulatory requirements. Your expertise will be instrumental in developing and maintaining security policies, procedures, and best practices that safeguard our assets and data integrity. As a Security Assurance Manager, you will collaborate with cross-functional teams to implement effective security controls and provide...

Learn more

Information Security and Assurance Analyst

Added 18/09/2026

We are seeking an Information Security and Assurance Analyst to support the protection, resilience and effective governance of information systems, data and technology services. This role will contribute to the development and maintenance of security controls, assurance processes and risk management activities, helping to ensure that information security requirements are understood and consistently applied across the organisation. You will work with colleagues across technology, business and operational teams to promote good security practices and provide practical, risk-based advice. Key responsibilities will include supporting security risk assessments, reviewing control effectiveness and maintaining accurate records of risks, issues, exceptions and remediation actions....

Learn more

Cyber Security and Information Assurance Lead

Added 18/09/2026

We are seeking a Cyber Security and Information Assurance Lead to provide strategic and operational leadership across cyber security, information assurance, risk management and data protection. The successful candidate will help safeguard critical systems, information assets and services by developing robust security frameworks, policies and controls aligned with recognised standards and regulatory requirements. You will work closely with technology, operational and business stakeholders to ensure that security is embedded throughout the organisation’s services, projects and change programmes. Key responsibilities will include leading the assessment and management of cyber and information risks; maintaining security policies, standards, procedures and assurance documentation; and...

Learn more

Information Security Assurance Administrator

Added 18/09/2026

An opportunity is available for an Information Security Assurance Administrator to support the effective management, monitoring and continuous improvement of information security controls. The role will assist with maintaining assurance activities across systems, processes and third-party services, helping to ensure that security requirements are understood, implemented and evidenced. You will work with colleagues across technology, risk, compliance and operational teams to coordinate security reviews and support a strong culture of information protection. Key responsibilities will include maintaining security assurance records, control frameworks, policies, procedures and risk documentation; coordinating evidence collection for internal and external audits; tracking remediation actions and escalating...

Learn more

Head of Operational Information Security, Risk and Assurance

Added 04/09/2026

We are seeking an experienced Head of Operational Information Security, Risk and Assurance to lead the development and delivery of a robust operational security, risk and assurance function. This is a senior leadership role with responsibility for protecting information assets, strengthening resilience and ensuring that security practices support organisational objectives. You will provide clear direction across information security operations, technology risk, governance, compliance and assurance, while promoting a culture of shared accountability for security. You will oversee the identification, assessment and treatment of information and technology risks, ensuring that effective controls are designed, implemented and continuously improved. Responsibilities will include...

Learn more
At least 8 characters, 1 uppercase, 1 lowercase and 1 special character or number
Your file must be a doc, docx or pdf. No larger than 5MB.