Third Party Security Due Diligence Lead
We are seeking a Third Party Security Due Diligence Lead to oversee the assessment and management of information security risks associated with suppliers, partners and other external service providers. In this role, you will lead the end-to-end due diligence process, ensuring that third parties meet defined security, privacy, resilience and compliance requirements before and throughout the relationship lifecycle. You will work closely with procurement, legal, privacy, technology, risk and business stakeholders to provide clear, practical and risk-based recommendations.
Your responsibilities will include designing and maintaining third-party security assessment processes, reviewing security questionnaires and supporting evidence, and evaluating controls across areas such as access management, data protection, vulnerability management, incident response, business continuity and regulatory compliance. You will identify control gaps, assess their potential impact, agree appropriate remediation plans and track actions through to completion. Where risks cannot be fully mitigated, you will prepare concise risk summaries and escalation recommendations for relevant governance forums. You will also support the development of security requirements for contracts, contribute to supplier segmentation and risk-tiering, and ensure that ongoing monitoring is proportionate to the level of risk.
The successful candidate will have substantial experience in third-party risk management, information security assurance, supplier security assessments or a related discipline. You will be confident interpreting technical and compliance evidence, challenging responses constructively and explaining security risks to both technical and non-technical audiences. Knowledge of recognised frameworks and standards such as ISO 27001, SOC 2, NIST, CIS Controls, GDPR or equivalent regulatory requirements is desirable. Strong organisational, analytical and stakeholder-management skills are essential, along with the ability to manage multiple assessments and competing priorities. Relevant professional qualifications in information security, risk or audit would be advantageous. You will bring sound judgement, attention to detail and a collaborative approach to strengthening security across the external partner ecosystem.
Third Party Security Due Diligence Lead
Other similar jobs
Popular job searches
Your next job
starts here.
JOB SPECIALISMS
LATEST JOBS
TOP SEARCHES
LOCATIONS
- Security Engineer
- Security Analyst
- Security Architect
- IT Security Manager
- Security Consultant
- SOC Analyst
- Identity Access Management IAM
- Cyber Security Consultant
- Cloud Security
- Application Security
- Incident Response
- Penetration Tester
LATEST JOBS
- Security Engineer (Contractor)
- Vice President, Field CISO Com...
- Microsoft 365 & Security Infra...
- Senior ICT Security Designer
- Data Protection Expert
- Data Protection Officer: Schoo...
- Data Protection Officer
- IT CONSULTANT (IT Management,...
- Technology and Cyber Employee...
- Cyber Security Consultant
- Cyber Security Consultant (Pen...
- Platform and Services Engineer...