Third Party Cyber Risk Lead

Reference: iw94zfj71xqude0fym13

We are seeking an experienced Third Party Cyber Risk Lead to strengthen the management of cyber security risks across our external supplier and partner ecosystem. In this role, you will lead the development and delivery of a robust third-party cyber risk management programme, helping ensure that suppliers meet required security, resilience, privacy and regulatory standards. You will work closely with procurement, legal, technology, information security, risk and business teams to embed effective controls throughout the supplier lifecycle.

Your responsibilities will include defining and maintaining third-party cyber risk policies, standards, procedures and assessment methodologies; conducting risk assessments and due diligence for new and existing suppliers; reviewing security questionnaires, audit reports, certifications and remediation plans; and identifying control gaps requiring further action. You will monitor supplier risk profiles, oversee remediation activity and escalate material risks appropriately. You will also support contract negotiations by advising on security requirements, incident notification provisions, audit rights, data protection obligations and business continuity expectations.

The successful candidate will have proven experience in third-party risk management, supplier assurance, cyber security governance or a related discipline, ideally within a complex or highly regulated environment. You should have a strong understanding of recognised security and risk frameworks, such as ISO 27001, NIST, CIS Controls, SOC 2 or equivalent, together with knowledge of cloud security, data protection, operational resilience and cyber incident management. Strong analytical, communication and stakeholder management skills are essential, as is the ability to challenge constructively and influence at all levels. Relevant professional qualifications, such as CISA, CRISC, CISSP, CISM or equivalent experience, would be advantageous. This is an opportunity to play a key role in improving organisational resilience and reducing cyber risk across a diverse and critical third-party landscape.

COMPETITIVE SALARY
Added 25/08/2026
Reference: iw94zfj71xqude0fym13

Other similar jobs

Technical Specialist (cyber related), Operational Risk and Resilience, R&CGI Operational Risk and Resilience Team - Insurance Directorate

Added 24/07/2026

We are seeking a highly skilled Technical Specialist with a strong focus on cyber-related issues to join our Operational Risk and Resilience Team within the Insurance Directorate. In this role, you will be responsible for identifying, assessing, and mitigating cyber risks that could impact the organization's operational resilience. You will work closely with cross-functional teams to develop and implement strategies aimed at enhancing the cybersecurity posture and ensuring compliance with relevant regulations and industry standards. Your expertise will be critical in conducting risk assessments, analyzing potential threats, and recommending appropriate risk management solutions. The ideal candidate will have a solid...

Learn more

Lead Penetration Tester (Lead Cyber Analyst), Technical Vulnerability Management - Cyber Security Division

Added 17/08/2026

We are seeking a highly skilled Lead Penetration Tester (Lead Cyber Analyst) to join our Technical Vulnerability Management team within our Cyber Security Division. In this role, you will be responsible for leading and executing comprehensive penetration testing engagements, identifying and assessing vulnerabilities within various systems and applications. You will collaborate closely with cross-functional teams to develop and implement effective remediation strategies, ensuring the security posture of the organization is continually enhanced. Your expertise will also be critical in mentoring junior analysts and conducting training sessions to elevate the team's overall capabilities. The ideal candidate will have a strong background...

Learn more

Junior Cyber Risk and Assurance Analyst

Added 01/09/2026

We are seeking a motivated Junior Cyber Risk and Assurance Analyst to support the development, maintenance and continuous improvement of cyber security risk and assurance activities. This is an excellent opportunity for someone at the early stage of their cyber security career who is keen to build practical experience across governance, risk management, compliance and security assurance. You will work with colleagues across technology, risk and business functions to help identify, assess and manage cyber security risks in a structured and consistent way. Key responsibilities will include supporting cyber risk assessments, maintaining risk registers and action plans, and assisting with...

Learn more

Cyber Analyst in CYBER DEFENCE CENTRE

Added 01/09/2026

We are seeking a Cyber Analyst to support the monitoring, detection and investigation of cyber threats across a complex technology environment. Working as part of a collaborative security operations team, you will help protect critical systems, networks and information by identifying suspicious activity, assessing potential risks and coordinating appropriate responses. This role is suited to an analytical and proactive professional who can work effectively in a fast-paced environment and communicate clearly with both technical and non-technical stakeholders. Your responsibilities will include monitoring security alerts and event data from a range of tools, investigating suspected incidents and conducting initial triage to...

Learn more

Senior Cyber Engineer in IDENTITY & ACCESS MANAGEMENT

Added 10/08/2026

We are seeking a highly skilled Senior Cyber Engineer specializing in Identity & Access Management (IAM) to join our dynamic team. In this role, you will be responsible for designing, implementing, and managing IAM solutions that ensure secure access to critical systems and data. You will collaborate with cross-functional teams to develop strategies for identity governance, authentication, and authorization, while continuously assessing and improving security protocols. Your expertise will be crucial in identifying vulnerabilities and developing mitigation strategies to protect sensitive information. The ideal candidate will have extensive experience with IAM technologies and frameworks, including Single Sign-On (SSO), Multi-Factor Authentication...

Learn more

Third Party Cyber Risk Lead

Added 25/08/2026

We are seeking an experienced Third Party Cyber Risk Lead to strengthen the management of cyber security risks across a complex supplier and partner ecosystem. In this role, you will develop and oversee a proportionate third-party cyber risk management framework, helping ensure that suppliers meet security expectations throughout the procurement, onboarding, monitoring, renewal and offboarding lifecycle. You will work closely with procurement, legal, information security, technology, risk and business stakeholders to embed effective controls and provide clear, practical advice. Your responsibilities will include conducting and overseeing supplier cyber risk assessments, reviewing security questionnaires and independent assurance reports, identifying control gaps,...

Learn more

Third Party Security Due Diligence Lead

Added 09/09/2026

We are seeking a Third Party Security Due Diligence Lead to oversee the assessment and management of information security risks associated with suppliers, partners and other external service providers. In this role, you will lead the end-to-end due diligence process, ensuring that third parties meet defined security, privacy, resilience and compliance requirements before and throughout the relationship lifecycle. You will work closely with procurement, legal, privacy, technology, risk and business stakeholders to provide clear, practical and risk-based recommendations. Your responsibilities will include designing and maintaining third-party security assessment processes, reviewing security questionnaires and supporting evidence, and evaluating controls across areas...

Learn more

Director, IT Security Third Party Monitor & Compliance

Added 09/09/2026

We are seeking a Director, IT Security Third Party Monitor & Compliance to lead the governance, oversight, and continuous improvement of third-party information security and compliance activities. This senior role will establish and maintain a comprehensive framework for assessing suppliers, service providers, and strategic partners throughout the relationship lifecycle. You will ensure that third-party risks are identified, evaluated, documented, and managed in line with applicable regulatory obligations, internal policies, contractual requirements, and recognised industry standards. Key responsibilities include directing third-party security assessments, reviewing control evidence, monitoring remediation plans, and providing clear risk-based reporting to senior leadership and relevant governance committees....

Learn more

Information Security Third Party Assurance Analyst

Added 03/09/2026

We are seeking an Information Security Third Party Assurance Analyst to support the assessment and ongoing oversight of the organisation’s suppliers, partners and other external service providers. In this role, you will help ensure that third parties meet required information security, privacy, resilience and risk management standards before and throughout the relationship lifecycle. You will work closely with procurement, legal, technology, privacy, risk and business teams to provide clear, practical assurance and support informed risk-based decisions. Your responsibilities will include reviewing supplier security questionnaires, independent assurance reports, policies, certifications and other evidence; assessing controls against recognised frameworks and internal requirements;...

Learn more

Cyber Operations & 3rd Party Security Manager

Added 01/09/2026

We are seeking a Cyber Operations & 3rd Party Security Manager to lead the development, operation and continual improvement of cyber security capabilities across a complex technology and supplier landscape. This role will help protect critical systems, information and services by overseeing security operations, coordinating incident response and ensuring that third-party relationships meet appropriate security standards. You will work closely with technology, risk, compliance, procurement and business stakeholders to embed practical, proportionate and effective security controls. Key responsibilities will include managing day-to-day cyber operations, monitoring security events and vulnerabilities, coordinating responses to incidents and supporting investigations, remediation and lessons learned....

Learn more

Risk Manager - Tech & Cyber Risk

Added 22/07/2026

We are seeking a skilled Risk Manager specializing in Tech & Cyber Risk to join our dynamic team. In this role, you will be responsible for identifying, assessing, and mitigating risks associated with technology and cybersecurity within the organization. You will develop and implement risk management strategies to safeguard sensitive data and maintain compliance with industry regulations. Collaborating closely with IT, legal, and operational teams, you will conduct thorough risk assessments, create risk reports, and present findings to senior management while ensuring that risk policies are upheld and communicated effectively across the organization. To excel in this role, you will...

Learn more

Vice President, Enterprise Risk Management & Legal Entity Risk

Added 25/08/2026

We are seeking a Vice President, Enterprise Risk Management & Legal Entity Risk to provide strategic leadership across the enterprise risk framework and legal entity governance environment. This senior role will oversee the identification, assessment, monitoring and management of key risks, ensuring that risk practices support business objectives, regulatory expectations and sustainable growth. The successful candidate will serve as a trusted adviser to senior leaders and governance committees, providing clear, independent insight into the organisation’s risk profile and emerging exposures. Key responsibilities include leading the development and ongoing enhancement of the enterprise risk management framework, risk appetite statement, policies, standards...

Learn more

ServiceNow Risk, Cyber & Resilience Transformation Lead - Managing Consultant

Added 26/08/2026

We are seeking a ServiceNow Risk, Cyber & Resilience Transformation Lead – Managing Consultant to shape and deliver strategic transformation programmes across risk management, cybersecurity, business resilience and governance. This role will work closely with senior stakeholders to understand business priorities, define target operating models and translate complex requirements into practical, technology-enabled solutions using the ServiceNow platform. You will lead engagements from discovery through to implementation, developing transformation roadmaps, operating model designs, process architectures and business cases. Responsibilities will include facilitating workshops, assessing current capabilities, identifying opportunities for improvement and designing future-state processes across areas such as risk and compliance,...

Learn more

Cyber Security Risk Manager Lead

Added 21/08/2026

We are seeking a highly skilled Cyber Security Risk Manager Lead to drive our organization's cybersecurity strategy and risk management initiatives. The successful candidate will be responsible for identifying, assessing, and mitigating cybersecurity risks across all business units. This role requires a deep understanding of security frameworks, risk assessment methodologies, and the ability to communicate complex security concepts to stakeholders at all levels. The Cyber Security Risk Manager Lead will collaborate with various teams to develop robust security policies and procedures, ensuring compliance with relevant regulations and industry standards. The ideal candidate will oversee risk assessments, vulnerability management, and incident...

Learn more
At least 8 characters, 1 uppercase, 1 lowercase and 1 special character or number
Your file must be a doc, docx or pdf. No larger than 5MB.