Third Party Security Due Diligence Lead

Reference: 0u4gryw10oh1ngs5gavv

We are seeking a Third Party Security Due Diligence Lead to oversee the assessment and management of information security risks associated with suppliers, partners and other external service providers. In this role, you will lead the end-to-end due diligence process, ensuring that third parties meet defined security, privacy, resilience and compliance requirements before and throughout the relationship lifecycle. You will work closely with procurement, legal, privacy, technology, risk and business stakeholders to provide clear, practical and risk-based recommendations.

Your responsibilities will include designing and maintaining third-party security assessment processes, reviewing security questionnaires and supporting evidence, and evaluating controls across areas such as access management, data protection, vulnerability management, incident response, business continuity and regulatory compliance. You will identify control gaps, assess their potential impact, agree appropriate remediation plans and track actions through to completion. Where risks cannot be fully mitigated, you will prepare concise risk summaries and escalation recommendations for relevant governance forums. You will also support the development of security requirements for contracts, contribute to supplier segmentation and risk-tiering, and ensure that ongoing monitoring is proportionate to the level of risk.

The successful candidate will have substantial experience in third-party risk management, information security assurance, supplier security assessments or a related discipline. You will be confident interpreting technical and compliance evidence, challenging responses constructively and explaining security risks to both technical and non-technical audiences. Knowledge of recognised frameworks and standards such as ISO 27001, SOC 2, NIST, CIS Controls, GDPR or equivalent regulatory requirements is desirable. Strong organisational, analytical and stakeholder-management skills are essential, along with the ability to manage multiple assessments and competing priorities. Relevant professional qualifications in information security, risk or audit would be advantageous. You will bring sound judgement, attention to detail and a collaborative approach to strengthening security across the external partner ecosystem.

COMPETITIVE SALARY
Added 09/09/2026
Reference: 0u4gryw10oh1ngs5gavv

Third Party Security Due Diligence Lead

London, England, United Kingdom Permanent Compliance

Other similar jobs

Third Party Cyber Risk Lead

Added 25/08/2026

We are seeking an experienced Third Party Cyber Risk Lead to strengthen the management of cyber security risks across a complex supplier and partner ecosystem. In this role, you will develop and oversee a proportionate third-party cyber risk management framework, helping ensure that suppliers meet security expectations throughout the procurement, onboarding, monitoring, renewal and offboarding lifecycle. You will work closely with procurement, legal, information security, technology, risk and business stakeholders to embed effective controls and provide clear, practical advice. Your responsibilities will include conducting and overseeing supplier cyber risk assessments, reviewing security questionnaires and independent assurance reports, identifying control gaps,...

Learn more

Third Party Cyber Risk Lead

Added 25/08/2026

We are seeking an experienced Third Party Cyber Risk Lead to strengthen the management of cyber security risks across our external supplier and partner ecosystem. In this role, you will lead the development and delivery of a robust third-party cyber risk management programme, helping ensure that suppliers meet required security, resilience, privacy and regulatory standards. You will work closely with procurement, legal, technology, information security, risk and business teams to embed effective controls throughout the supplier lifecycle. Your responsibilities will include defining and maintaining third-party cyber risk policies, standards, procedures and assessment methodologies; conducting risk assessments and due diligence for...

Learn more

Director, IT Security Third Party Monitor & Compliance

Added 09/09/2026

We are seeking a Director, IT Security Third Party Monitor & Compliance to lead the governance, oversight, and continuous improvement of third-party information security and compliance activities. This senior role will establish and maintain a comprehensive framework for assessing suppliers, service providers, and strategic partners throughout the relationship lifecycle. You will ensure that third-party risks are identified, evaluated, documented, and managed in line with applicable regulatory obligations, internal policies, contractual requirements, and recognised industry standards. Key responsibilities include directing third-party security assessments, reviewing control evidence, monitoring remediation plans, and providing clear risk-based reporting to senior leadership and relevant governance committees....

Learn more

Information Security Third Party Assurance Analyst

Added 03/09/2026

We are seeking an Information Security Third Party Assurance Analyst to support the assessment and ongoing oversight of the organisation’s suppliers, partners and other external service providers. In this role, you will help ensure that third parties meet required information security, privacy, resilience and risk management standards before and throughout the relationship lifecycle. You will work closely with procurement, legal, technology, privacy, risk and business teams to provide clear, practical assurance and support informed risk-based decisions. Your responsibilities will include reviewing supplier security questionnaires, independent assurance reports, policies, certifications and other evidence; assessing controls against recognised frameworks and internal requirements;...

Learn more

Cyber Operations & 3rd Party Security Manager

Added 01/09/2026

We are seeking a Cyber Operations & 3rd Party Security Manager to lead the development, operation and continual improvement of cyber security capabilities across a complex technology and supplier landscape. This role will help protect critical systems, information and services by overseeing security operations, coordinating incident response and ensuring that third-party relationships meet appropriate security standards. You will work closely with technology, risk, compliance, procurement and business stakeholders to embed practical, proportionate and effective security controls. Key responsibilities will include managing day-to-day cyber operations, monitoring security events and vulnerabilities, coordinating responses to incidents and supporting investigations, remediation and lessons learned....

Learn more

Lead Penetration Tester (Lead Cyber Analyst), Technical Vulnerability Management - Cyber Security Division

Added 17/08/2026

We are seeking a highly skilled Lead Penetration Tester (Lead Cyber Analyst) to join our Technical Vulnerability Management team within our Cyber Security Division. In this role, you will be responsible for leading and executing comprehensive penetration testing engagements, identifying and assessing vulnerabilities within various systems and applications. You will collaborate closely with cross-functional teams to develop and implement effective remediation strategies, ensuring the security posture of the organization is continually enhanced. Your expertise will also be critical in mentoring junior analysts and conducting training sessions to elevate the team's overall capabilities. The ideal candidate will have a strong background...

Learn more

Lead IT Security Engineer (Cybersecurity & Platform Security)

Added 02/09/2026

We are seeking a Lead IT Security Engineer (Cybersecurity & Platform Security) to design, implement and continuously improve security controls across enterprise technology platforms. This role will provide technical leadership in cybersecurity engineering, platform hardening, cloud security and infrastructure protection, helping to safeguard critical systems, applications and data against evolving threats. You will work closely with architecture, infrastructure, development, operations and risk teams to embed security throughout the technology lifecycle. Key responsibilities include defining and maintaining secure configuration standards; leading vulnerability management, remediation and security monitoring activities; and evaluating the resilience of networks, operating systems, endpoints, cloud services and identity...

Learn more

Cyber Security Architect / Cyber Security Tech Lead

Added 26/08/2026

We are seeking an experienced Cyber Security Architect / Cyber Security Tech Lead to define and deliver secure, resilient technology solutions across a complex and evolving environment. This role will provide technical leadership across cyber security architecture, engineering and assurance, helping to protect critical systems, applications, data and infrastructure. You will work closely with technology, risk, compliance and business stakeholders to translate security requirements into practical, scalable outcomes. Your responsibilities will include developing and maintaining security architecture principles, reference architectures, standards and patterns; assessing the security implications of new technologies, platforms and transformation initiatives; and providing expert guidance across cloud,...

Learn more

Delivery Team Security Lead (Security Assurance Coordinator)

Added 21/08/2026

We are seeking a dedicated Delivery Team Security Lead (Security Assurance Coordinator) to join our dynamic team. In this role, you will be responsible for overseeing the security assurance processes within our delivery teams. Your primary duties will include developing, implementing, and maintaining security policies and procedures to ensure compliance with industry standards and regulations. You will work closely with project managers and technical teams to assess security risks, conduct security assessments, and facilitate security training to enhance awareness across the organization. The ideal candidate will have a strong background in cybersecurity and information security management. You should possess excellent...

Learn more

Cyber Security Lead

Added 18/09/2026

We are seeking an experienced Cyber Security Lead to develop and strengthen security capabilities across a complex technology environment. This role will provide strategic direction and hands-on leadership across cyber security operations, governance, risk management, and resilience. You will work closely with technology, compliance, and business stakeholders to ensure security is embedded into systems, services, and day-to-day decision-making. Key responsibilities will include leading the development and implementation of the cyber security strategy, policies, standards, and control frameworks. You will oversee security risk assessments, vulnerability management, threat monitoring, incident response, and remediation activities, ensuring that issues are prioritised and resolved effectively....

Learn more

Cyber Security and Information Assurance Lead

Added 18/09/2026

We are seeking a Cyber Security and Information Assurance Lead to provide strategic and operational leadership across cyber security, information assurance, risk management and data protection. The successful candidate will help safeguard critical systems, information assets and services by developing robust security frameworks, policies and controls aligned with recognised standards and regulatory requirements. You will work closely with technology, operational and business stakeholders to ensure that security is embedded throughout the organisation’s services, projects and change programmes. Key responsibilities will include leading the assessment and management of cyber and information risks; maintaining security policies, standards, procedures and assurance documentation; and...

Learn more

Global Product Security Services Lead

Added 18/09/2026

We are seeking an experienced Global Product Security Services Lead to define and deliver a comprehensive security services strategy across the product lifecycle. In this influential role, you will lead the development of scalable security capabilities that support product teams, engineering functions, and business stakeholders across multiple regions. You will help embed security by design, strengthen resilience, and ensure that products meet relevant regulatory, industry, and customer expectations. Key responsibilities include owning the global product security services roadmap, establishing operating models, and setting standards, processes, and performance measures for secure product development. You will oversee services such as threat modelling,...

Learn more

Security, Culture, Education & Awareness Team Lead

Added 18/09/2026

We are seeking a Security, Culture, Education & Awareness Team Lead to develop and deliver a comprehensive security culture and awareness programme across a complex organisation. This role will help strengthen security behaviours, improve understanding of risk, and ensure that colleagues at all levels are equipped to protect information, systems, people and services. You will lead a small team and work closely with security, technology, people, communications, risk and business teams to embed security into everyday decision-making. Your responsibilities will include creating and maintaining a strategic security education and awareness plan, informed by organisational priorities, emerging threats, regulatory expectations and...

Learn more

Cyber Security Lead

Added 17/09/2026

We are seeking an experienced Cyber Security Lead to develop and strengthen security capabilities across a complex technology environment. This role will provide strategic direction and hands-on leadership across cyber security operations, governance, risk management, and assurance. You will work closely with technology, engineering, infrastructure, compliance, and business stakeholders to identify emerging threats, protect critical information assets, and ensure security is embedded throughout the organisation’s systems, processes, and change initiatives. Key responsibilities will include maintaining and improving the cyber security strategy, policies, standards, and control framework; leading security risk assessments and remediation planning; and overseeing the monitoring, investigation, and response...

Learn more

Lead Game Security Engineer

Added 17/09/2026

We are seeking a Lead Game Security Engineer to strengthen the security of online game services, platforms, and development environments. In this role, you will define and deliver security strategies across the game lifecycle, from early design and development through launch and live operations. You will work closely with engineering, infrastructure, anti-cheat, trust and safety, QA, and production teams to identify risks, prioritise improvements, and embed secure practices into everyday development. Your responsibilities will include leading threat modelling and security reviews for game clients, backend services, APIs, authentication systems, payment flows, and online infrastructure. You will design and oversee anti-cheat...

Learn more
At least 8 characters, 1 uppercase, 1 lowercase and 1 special character or number
Your file must be a doc, docx or pdf. No larger than 5MB.