Third Party Cyber Risk Lead

Reference: q8y90hvzhk42pqbt5xi7

We are seeking an experienced Third Party Cyber Risk Lead to strengthen the management of cyber security risks across a complex supplier and partner ecosystem. In this role, you will develop and oversee a proportionate third-party cyber risk management framework, helping ensure that suppliers meet security expectations throughout the procurement, onboarding, monitoring, renewal and offboarding lifecycle. You will work closely with procurement, legal, information security, technology, risk and business stakeholders to embed effective controls and provide clear, practical advice.

Your responsibilities will include conducting and overseeing supplier cyber risk assessments, reviewing security questionnaires and independent assurance reports, identifying control gaps, and agreeing remediation plans with relevant stakeholders. You will maintain accurate risk and issue records, monitor remediation progress, support risk acceptance decisions, and produce meaningful management information for governance forums and senior leadership. You will also contribute to the development of policies, standards, procedures and guidance, while helping to improve third-party security requirements, due diligence processes and ongoing monitoring activities. Where required, you will support incident response and investigations involving suppliers, ensuring lessons learned are incorporated into risk management practices.

The successful candidate will have strong experience in third-party, supplier or technology risk, ideally within a regulated, highly controlled or complex environment. You will understand information security principles, common cyber threats, risk assessment methodologies and relevant control frameworks such as ISO 27001, NIST, CIS or equivalent. Experience interpreting SOC reports, penetration testing results, business continuity evidence and other assurance materials is desirable. Strong stakeholder management and communication skills are essential, as is the ability to explain technical and risk matters clearly to both specialist and non-specialist audiences. You should be organised, commercially aware, confident challenging decisions constructively, and capable of managing competing priorities while delivering high-quality outcomes.

COMPETITIVE SALARY
Added 25/08/2026
Reference: q8y90hvzhk42pqbt5xi7

Other similar jobs

Third Party Cyber Risk Lead

Added 25/08/2026

We are seeking an experienced Third Party Cyber Risk Lead to strengthen the management of cyber security risks across our external supplier and partner ecosystem. In this role, you will lead the development and delivery of a robust third-party cyber risk management programme, helping ensure that suppliers meet required security, resilience, privacy and regulatory standards. You will work closely with procurement, legal, technology, information security, risk and business teams to embed effective controls throughout the supplier lifecycle. Your responsibilities will include defining and maintaining third-party cyber risk policies, standards, procedures and assessment methodologies; conducting risk assessments and due diligence for...

Learn more

Third Party Security Due Diligence Lead

Added 09/09/2026

We are seeking a Third Party Security Due Diligence Lead to oversee the assessment and management of information security risks associated with suppliers, partners and other external service providers. In this role, you will lead the end-to-end due diligence process, ensuring that third parties meet defined security, privacy, resilience and compliance requirements before and throughout the relationship lifecycle. You will work closely with procurement, legal, privacy, technology, risk and business stakeholders to provide clear, practical and risk-based recommendations. Your responsibilities will include designing and maintaining third-party security assessment processes, reviewing security questionnaires and supporting evidence, and evaluating controls across areas...

Learn more

Director, IT Security Third Party Monitor & Compliance

Added 09/09/2026

We are seeking a Director, IT Security Third Party Monitor & Compliance to lead the governance, oversight, and continuous improvement of third-party information security and compliance activities. This senior role will establish and maintain a comprehensive framework for assessing suppliers, service providers, and strategic partners throughout the relationship lifecycle. You will ensure that third-party risks are identified, evaluated, documented, and managed in line with applicable regulatory obligations, internal policies, contractual requirements, and recognised industry standards. Key responsibilities include directing third-party security assessments, reviewing control evidence, monitoring remediation plans, and providing clear risk-based reporting to senior leadership and relevant governance committees....

Learn more

Information Security Third Party Assurance Analyst

Added 03/09/2026

We are seeking an Information Security Third Party Assurance Analyst to support the assessment and ongoing oversight of the organisation’s suppliers, partners and other external service providers. In this role, you will help ensure that third parties meet required information security, privacy, resilience and risk management standards before and throughout the relationship lifecycle. You will work closely with procurement, legal, technology, privacy, risk and business teams to provide clear, practical assurance and support informed risk-based decisions. Your responsibilities will include reviewing supplier security questionnaires, independent assurance reports, policies, certifications and other evidence; assessing controls against recognised frameworks and internal requirements;...

Learn more

Cyber Operations & 3rd Party Security Manager

Added 01/09/2026

We are seeking a Cyber Operations & 3rd Party Security Manager to lead the development, operation and continual improvement of cyber security capabilities across a complex technology and supplier landscape. This role will help protect critical systems, information and services by overseeing security operations, coordinating incident response and ensuring that third-party relationships meet appropriate security standards. You will work closely with technology, risk, compliance, procurement and business stakeholders to embed practical, proportionate and effective security controls. Key responsibilities will include managing day-to-day cyber operations, monitoring security events and vulnerabilities, coordinating responses to incidents and supporting investigations, remediation and lessons learned....

Learn more

Technical Specialist (cyber related), Operational Risk and Resilience, R&CGI Operational Risk and Resilience Team - Insurance Directorate

Added 24/07/2026

We are seeking a highly skilled Technical Specialist with a strong focus on cyber-related issues to join our Operational Risk and Resilience Team within the Insurance Directorate. In this role, you will be responsible for identifying, assessing, and mitigating cyber risks that could impact the organization's operational resilience. You will work closely with cross-functional teams to develop and implement strategies aimed at enhancing the cybersecurity posture and ensuring compliance with relevant regulations and industry standards. Your expertise will be critical in conducting risk assessments, analyzing potential threats, and recommending appropriate risk management solutions. The ideal candidate will have a solid...

Learn more

Risk Manager - Tech & Cyber Risk

Added 22/07/2026

We are seeking a skilled Risk Manager specializing in Tech & Cyber Risk to join our dynamic team. In this role, you will be responsible for identifying, assessing, and mitigating risks associated with technology and cybersecurity within the organization. You will develop and implement risk management strategies to safeguard sensitive data and maintain compliance with industry regulations. Collaborating closely with IT, legal, and operational teams, you will conduct thorough risk assessments, create risk reports, and present findings to senior management while ensuring that risk policies are upheld and communicated effectively across the organization. To excel in this role, you will...

Learn more

Vice President, Enterprise Risk Management & Legal Entity Risk

Added 25/08/2026

We are seeking a Vice President, Enterprise Risk Management & Legal Entity Risk to provide strategic leadership across the enterprise risk framework and legal entity governance environment. This senior role will oversee the identification, assessment, monitoring and management of key risks, ensuring that risk practices support business objectives, regulatory expectations and sustainable growth. The successful candidate will serve as a trusted adviser to senior leaders and governance committees, providing clear, independent insight into the organisation’s risk profile and emerging exposures. Key responsibilities include leading the development and ongoing enhancement of the enterprise risk management framework, risk appetite statement, policies, standards...

Learn more

ServiceNow Risk, Cyber & Resilience Transformation Lead - Managing Consultant

Added 26/08/2026

We are seeking a ServiceNow Risk, Cyber & Resilience Transformation Lead – Managing Consultant to shape and deliver strategic transformation programmes across risk management, cybersecurity, business resilience and governance. This role will work closely with senior stakeholders to understand business priorities, define target operating models and translate complex requirements into practical, technology-enabled solutions using the ServiceNow platform. You will lead engagements from discovery through to implementation, developing transformation roadmaps, operating model designs, process architectures and business cases. Responsibilities will include facilitating workshops, assessing current capabilities, identifying opportunities for improvement and designing future-state processes across areas such as risk and compliance,...

Learn more

Technology and Cyber Security Risk Audit Lead

Added 21/08/2026

We are seeking an experienced Technology and Cyber Security Risk Audit Lead to oversee the assessment and management of technology and cybersecurity risks within our organization. In this role, you will be responsible for designing, implementing, and maintaining a robust audit framework that aligns with industry standards and regulatory requirements. You will lead audits focusing on IT systems, data protection, and information security, ensuring that vulnerabilities are identified and addressed proactively. Collaborating with cross-functional teams, you will provide expert guidance on risk management strategies and cultivate a culture of security awareness throughout the organization. Your responsibilities will include developing and...

Learn more

Cyber Security Risk Manager Lead

Added 21/08/2026

We are seeking a highly skilled Cyber Security Risk Manager Lead to drive our organization's cybersecurity strategy and risk management initiatives. The successful candidate will be responsible for identifying, assessing, and mitigating cybersecurity risks across all business units. This role requires a deep understanding of security frameworks, risk assessment methodologies, and the ability to communicate complex security concepts to stakeholders at all levels. The Cyber Security Risk Manager Lead will collaborate with various teams to develop robust security policies and procedures, ensuring compliance with relevant regulations and industry standards. The ideal candidate will oversee risk assessments, vulnerability management, and incident...

Learn more

Lead Cyber Security Risk Manager

Added 19/08/2026

Are you passionate about safeguarding critical information assets and leading the charge against cyber threats? We are seeking a skilled Lead Cyber Security Risk Manager to join our dynamic team. In this pivotal role, you will be responsible for developing, implementing, and maintaining comprehensive cyber security risk management frameworks. You will identify, assess, and prioritize risks to ensure the organization’s information systems remain resilient and compliant with relevant regulations and industry standards. Your key responsibilities will include overseeing risk assessments, conducting in-depth analyses of emerging threats, and collaborating with IT, compliance, and business stakeholders to design effective mitigation strategies. You...

Learn more

ServiceNow Risk, Cyber & Resilience Transformation Lead - Managing Consultant

Added 18/08/2026

We are seeking a highly skilled and experienced ServiceNow Risk, Cyber & Resilience Transformation Lead - Managing Consultant to join our team. In this pivotal role, you will be responsible for driving the development and implementation of comprehensive risk management strategies, ensuring robust cybersecurity measures, and enhancing organizational resilience. You will work closely with clients to assess their current risk environments, develop tailored solutions, and lead transformation initiatives that align with best practices in the industry. Your key responsibilities will include leading cross-functional teams in the design and deployment of ServiceNow solutions, facilitating workshops to gather client requirements, and conducting...

Learn more

Cyber Risk and Compliance Lead (GRC) - Up to £80k

Added 29/07/2026

Are you passionate about cyber risk management and governance? An exciting opportunity has arisen for an experienced Cyber Risk and Compliance Lead (GRC) to join a dynamic team, offering up to £80k for the right candidate. In this pivotal role, you will be responsible for overseeing the development and implementation of the organisation's governance, risk, and compliance framework. You will lead efforts to identify, assess, and mitigate cyber risks, ensuring alignment with regulatory requirements and industry best practices. Your expertise will be crucial in conducting risk assessments, managing compliance audits, and supporting the implementation of security controls across the business....

Learn more

ServiceNow Risk, Cyber & Resilience Transformation Lead - Managing Consultant

Added 29/07/2026

We are seeking an experienced ServiceNow Risk, Cyber & Resilience Transformation Lead - Managing Consultant to spearhead our initiatives in risk management, cybersecurity, and resilience transformation. The ideal candidate will be responsible for leading the development and implementation of strategic frameworks that enhance our clients' risk posture and cybersecurity capabilities. You will work closely with cross-functional teams to identify vulnerabilities, assess risks, and design tailored solutions that align with industry standards and regulations. In this role, you will manage client engagements, ensuring the delivery of high-quality consulting services. You will be expected to conduct comprehensive assessments, develop risk management strategies,...

Learn more
At least 8 characters, 1 uppercase, 1 lowercase and 1 special character or number
Your file must be a doc, docx or pdf. No larger than 5MB.