At a Glance
- Tasks: Lead a dynamic team to enhance third-party security monitoring and compliance.
- Company: Join CLS, a forward-thinking company that values inclusion and innovation.
- Benefits: Enjoy 25+ holiday days, flexible working, and comprehensive wellbeing support.
- Other info: Embrace a culture of continuous improvement and professional development.
- Why this job: Make a real impact on security while developing your leadership skills.
- Qualifications: 12-15 years in third-party security risk management with strong leadership experience.
The predicted salary is between 90000 - 120000 £ per year.
- Functional Title: IT Security Third Party Monitor & Compliance
- Department: IT Security
- Reports To: Executive Director, Head of IT Sec Transformation
- Location: London
What you will be doing
- Lead the set‑up, development and management of the new Third‑Party Security Monitoring team, including fostering a culture of technical excellence and continuous improvement, for example:
- Team building, mentorship, and development for high‑performing critical Third‑Party Security Monitoring specialists in support of the overall security strategy.
- Drive the operationalisation and continuous monitoring of critical Third‑Party supplier security obligations, ensuring compliance with CLS security requirements.
- Play a leading role in the set‑up of the operational monitoring regime in respect of the recently established “Security Delivery Obligations”
- Operate this monitoring regime, including ensuring appropriate design and operational effectiveness of these obligations, as outlined in the Customer Security Document (CSD).
- Ensure the third party has clear remediation plans for any areas of non‑compliance identified in this testing
- Review a critical Third‑Party supplier's security processes and documentation, ensuring these processes and documentation align with CLS standards, CSD requirements, and regulatory expectations
- Set up and operate governance processes, with supporting metrics and performance indicators, in respect of the new third party monitoring regime
- Liaise extensively with required internal stakeholders (e. g., IT Security Teams, Procurement, Legal, Risk etc) and the critical Third‑Party supplier stakeholders.
What we’re looking for
- Oversee the Critical Third‑Party Supplier Security Monitoring team, driving innovation and ensuring the team has a clear understanding of its roles and responsibilities, and how they contribute and align to CLS's overall IT Security Function.
- Lead Critical Third‑Party Supplier Security Monitoring transformation programs and implement robust security monitoring solutions that establish a strong foundation for CLS's IT Security Function.
- Identify Critical Third‑Party Supplier Security Monitoring priorities to establish and strengthen a robust security team, by focusing efforts on tailoring work and programs for CLS specific needs.
- Drive strategic influence and foster strong relationships with key internal and external stakeholders.
For example, engaging with Procurement, Legal, Risk, other IT Security departments, and critical third‑party suppliers themselves to ensure effective security oversight, compliance, and continuous improvement of supplier security posture.
- Experience in third‑party security risk management, vendor oversight, or security governance (12-15 years), including ~8-10 years in a leadership role managing third‑party security relationships.
• Experience in
- Leading team adherence to operational and compliance standards within highly regulated environments.
- Reporting on team performance and project progress to senior management, translating technical insights.
- Representing the team in governance forums or committees, providing expert input and driving outcomes.
- Understand, interpret and apply regulatory requirements, compliance and industry standards as pertains to critical Third‑Party supplier Security Monitoring and Compliance.
Our commitment to employees
At CLS, we celebrate inclusion and consider this to be one of our strongest assets.
We are committed to fostering an environment in which everyone feels comfortable to be who they are, and inclusion is valued.
All employees have access to our inclusive benefits, including
- Holiday - UK/Asia: 25 holiday days and 3 ‘life days’ (in addition to bank holidays). US: 23 holiday days.
- 2 paid volunteer days so that you can actively support causes within your community that are important to you.
- Generous parental leave policies to ensure you can enjoy valuable time with your family.
- Parental transition coaching programmes and support services.
- Wellbeing and mental health support resources to ensure you are looking after yourself, and able to support others.
- Employee Networks (including our Women’s Forum, Black Employee Network and Pride Network) in support of our organisational commitment to embrace and always be learning more about inclusivity.
- Hybrid working to promote a healthy work/life balance, enabling employees to work collaboratively in the office when needed and work from home when they don’t.
- Active support of flexible working for all employees where possible.
- Monthly ‘Heads Down Days’ with no meetings across the whole company.
- Generous non‑contributory pension provision for UK/Asia employees, and 401K match from CLS for US employees.
- Private medical insurance and dental coverage.
- Social events that give you opportunities to meet new people and broaden your network across the organisation.
- Discounts and savings and cashback across a wide range of categories including health and retail for UK employees.
- Discounted Gym membership – Complete Body Gym Discount/Sweat equity program for US employees.
- All employees have access to Discover – our comprehensive learning platform with 1000+ courses from Linked In Learning.
- Access to frequent development sessions on a number of topics to help you be successful and develop your career at CLS.
- #J-18808-Ljbffr
Director, IT Security Third Party Monitor & Compliance employer: CLS Group
CLS Group is an exceptional employer that values collaboration and employee well-being, offering a supportive work culture in the heart of London. With generous leave policies and hybrid working options, employees can achieve a healthy work-life balance while benefiting from extensive growth opportunities in HR shared services. Join us to be part of a dynamic team that prioritises accuracy and excellence in payroll processes across diverse regions.
StudySmarter Expert Advice🤫
We think this is how you could land Director, IT Security Third Party Monitor & Compliance
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including CLS Group, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through CLS Group
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at CLS Group. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Director, IT Security Third Party Monitor & Compliance
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at CLS Group insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to CLS Group that you’re committed to staying ahead in the game.
How to prepare for a job interview at CLS Group
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at CLS Group to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at CLS Group.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.