Third Party Cyber Risk Lead
We are seeking an experienced Third Party Cyber Risk Lead to strengthen the management of cyber security risks across our external supplier and partner ecosystem. In this role, you will lead the development and delivery of a robust third-party cyber risk management programme, helping ensure that suppliers meet required security, resilience, privacy and regulatory standards. You will work closely with procurement, legal, technology, information security, risk and business teams to embed effective controls throughout the supplier lifecycle.
Your responsibilities will include defining and maintaining third-party cyber risk policies, standards, procedures and assessment methodologies; conducting risk assessments and due diligence for new and existing suppliers; reviewing security questionnaires, audit reports, certifications and remediation plans; and identifying control gaps requiring further action. You will monitor supplier risk profiles, oversee remediation activity and escalate material risks appropriately. You will also support contract negotiations by advising on security requirements, incident notification provisions, audit rights, data protection obligations and business continuity expectations.
The successful candidate will have proven experience in third-party risk management, supplier assurance, cyber security governance or a related discipline, ideally within a complex or highly regulated environment. You should have a strong understanding of recognised security and risk frameworks, such as ISO 27001, NIST, CIS Controls, SOC 2 or equivalent, together with knowledge of cloud security, data protection, operational resilience and cyber incident management. Strong analytical, communication and stakeholder management skills are essential, as is the ability to challenge constructively and influence at all levels. Relevant professional qualifications, such as CISA, CRISC, CISSP, CISM or equivalent experience, would be advantageous. This is an opportunity to play a key role in improving organisational resilience and reducing cyber risk across a diverse and critical third-party landscape.
Third Party Cyber Risk Lead
Other similar jobs
Popular job searches
Your next job
starts here.
JOB SPECIALISMS
LATEST JOBS
TOP SEARCHES
LOCATIONS
- Security Engineer
- Security Analyst
- Security Architect
- IT Security Manager
- Security Consultant
- SOC Analyst
- Identity Access Management IAM
- Cyber Security Consultant
- Cloud Security
- Application Security
- Incident Response
- Penetration Tester
LATEST JOBS
- Security Engineer (Contractor)
- Vice President, Field CISO Com...
- Microsoft 365 & Security Infra...
- Senior ICT Security Designer
- Data Protection Expert
- Data Protection Officer: Schoo...
- Data Protection Officer
- IT CONSULTANT (IT Management,...
- Technology and Cyber Employee...
- Cyber Security Consultant
- Cyber Security Consultant (Pen...
- Platform and Services Engineer...