Third Party Cyber Risk Lead
We are seeking an experienced Third Party Cyber Risk Lead to strengthen the management of cyber security risks across a complex supplier and partner ecosystem. In this role, you will develop and oversee a proportionate third-party cyber risk management framework, helping ensure that suppliers meet security expectations throughout the procurement, onboarding, monitoring, renewal and offboarding lifecycle. You will work closely with procurement, legal, information security, technology, risk and business stakeholders to embed effective controls and provide clear, practical advice.
Your responsibilities will include conducting and overseeing supplier cyber risk assessments, reviewing security questionnaires and independent assurance reports, identifying control gaps, and agreeing remediation plans with relevant stakeholders. You will maintain accurate risk and issue records, monitor remediation progress, support risk acceptance decisions, and produce meaningful management information for governance forums and senior leadership. You will also contribute to the development of policies, standards, procedures and guidance, while helping to improve third-party security requirements, due diligence processes and ongoing monitoring activities. Where required, you will support incident response and investigations involving suppliers, ensuring lessons learned are incorporated into risk management practices.
The successful candidate will have strong experience in third-party, supplier or technology risk, ideally within a regulated, highly controlled or complex environment. You will understand information security principles, common cyber threats, risk assessment methodologies and relevant control frameworks such as ISO 27001, NIST, CIS or equivalent. Experience interpreting SOC reports, penetration testing results, business continuity evidence and other assurance materials is desirable. Strong stakeholder management and communication skills are essential, as is the ability to explain technical and risk matters clearly to both specialist and non-specialist audiences. You should be organised, commercially aware, confident challenging decisions constructively, and capable of managing competing priorities while delivering high-quality outcomes.
Third Party Cyber Risk Lead
Other similar jobs
Popular job searches
Your next job
starts here.
JOB SPECIALISMS
LATEST JOBS
TOP SEARCHES
LOCATIONS
- Security Engineer
- Security Analyst
- Security Architect
- IT Security Manager
- Security Consultant
- SOC Analyst
- Identity Access Management IAM
- Cyber Security Consultant
- Cloud Security
- Application Security
- Incident Response
- Penetration Tester
LATEST JOBS
- Security Engineer (Contractor)
- Vice President, Field CISO Com...
- Microsoft 365 & Security Infra...
- Senior ICT Security Designer
- Data Protection Expert
- Data Protection Officer: Schoo...
- Data Protection Officer
- IT CONSULTANT (IT Management,...
- Technology and Cyber Employee...
- Cyber Security Consultant
- Cyber Security Consultant (Pen...
- Platform and Services Engineer...