Cyber Security Supply Chain Risk Manager in London
Cyber Security Supply Chain Risk Manager

Cyber Security Supply Chain Risk Manager in London

London Full-Time 48000 - 72000 £ / year (est.) No home office possible
Go Premium
G

At a Glance

  • Tasks: Manage cybersecurity risks in the supply chain and ensure vendor compliance.
  • Company: Join the Government Digital Service, leading digital transformation in the UK.
  • Benefits: Competitive salary, flexible working, and opportunities for professional growth.
  • Why this job: Make a real impact on national security while working with top digital professionals.
  • Qualifications: Experience in cybersecurity and supply chain management is essential.
  • Other info: Dynamic role with excellent career advancement opportunities.

The predicted salary is between 48000 - 72000 £ per year.

The Government Digital Service (GDS) is the digital centre of the government. We are responsible for setting, leading and delivering the vision of a digital modern government. Our priorities are to drive a modern digital government, by:

  • joining up public sector services
  • harnessing the power of AI for the public good
  • strengthening and extending our digital and data public infrastructure
  • elevating leadership and investing in talent
  • funding for outcomes and procuring for growth and innovation
  • committing to transparency and driving accountability

We are home to the Incubator for Artificial Intelligence (I.AI), the world-leading GOV.UK and at the forefront of coordinating the UK’s geospatial strategy and activity. We lead the Government Digital and Data function and champion the work of digital teams across government. We’re part of the Department for Science, Innovation and Technology (DSIT) and employ more than 1,000 people all over the UK, with hubs in Manchester, London and Bristol.

The Cyber Security Supply Chain Risk Manager is responsible for ensuring the security, integrity, and resilience of the organisation's supply chain in relation to cybersecurity risks. This role involves identifying and assessing cybersecurity risks within the supply chain, identifying suitable tender/contract security requirements/obligations to mitigate these risks, managing third-party vendor compliance with GDS’ specified security terms, and ensuring compliance/alignment with regulatory requirements and industry standards respectively. The Cyber Security Supply Chain Risk Manager will work cross-functionally with procurement, commercial, IT, risk management, engineering operations and legal departments to ensure that cybersecurity risks in the supply chain are understood and effectively managed throughout the supply chain lifecycle.

What you’ll do:

  • Cybersecurity Risk Assessment: conduct and manage comprehensive risk assessments of suppliers, vendors, and partners to identify and mitigate cybersecurity threats in the supply chain.
  • Service Team Collaboration: support and assist Service Teams with the security aspects of their procurement needs, ensuring that appropriate information and cyber security requirements are included in tender documents, specifications and contracts. Liaise with Commercial and Legal functions to ensure the requirements are included in tender and contract documentation.
  • Vendor Due Diligence: collaborate with procurement and legal teams to assess vendor security practices during onboarding and throughout the vendor lifecycle; ensure third-party vendors comply with the organisation’s cybersecurity policies and standards.
  • Supply Chain Risk Management (SCRM): develop and maintain a robust cybersecurity supply chain risk management (SCRM) program, including standardised supply chain risk logging, continuous monitoring, auditing, and evaluating third-party risk exposure individually, by category and in aggregate.
  • Compliance and Standards: ensure supply chain activities comply with relevant cybersecurity frameworks and regulations (e.g., NCSC Cyber Assessment Framework, GovS007, ISO 27001, GDPR/DPA18). Implement best practices from industry standards to secure supply chain operations.
  • Third-Party Contract Management: work with the legal and commercial teams to ensure cybersecurity clauses are included in supplier contracts. Define key performance indicators (KPIs) and service level agreements (SLAs) around vendor cybersecurity responsibilities. Periodically audit contracts for security terms, in order to understand any gaps in live contracts.
  • Incident Response: support the development of processes and protocols for managing third-party cybersecurity incidents, including coordinating with vendors during a breach, ensuring timely communication, and mitigating the impact on the organisation.
  • Vendor Cybersecurity Audits: lead or co-ordinate periodic cybersecurity audits of vendors and third parties to ensure they maintain high security standards. Identify gaps and work with vendors to implement remediation plans.
  • Training and Awareness: provide training and support to internal stakeholders on supply chain cybersecurity risks and vendor management best practices. Increase awareness of supply chain threats and trends within the organisation.
  • Collaboration and Communication: work closely with IT, risk, and procurement teams to communicate findings and recommended mitigations. Ensure transparency and alignment between teams on cybersecurity risks and strategies.
  • ‘Intelligent customer’ supply chain management: contribute to the working relationship and management of inter-government supply chain, for example, internal services provided by another government department.
  • Supply Chain Resilience: develop strategies to ensure supply chain resilience in the face of cybersecurity threats, including supply chain mapping and diversification to mitigate risk.
  • Monitoring and Reporting: continuously monitor the security posture of the supply chain and provide regular reports to leadership on third-party risk exposure, incidents, and mitigation efforts.

Person specification

We’re interested in people who have:

  • significant demonstrable experience in cybersecurity, supply chain management, and vendor/third-party risk management, including supply chain risk assessments and audits.
  • experience working with cybersecurity frameworks, risk management methodologies, and compliance requirements (e.g., NCSC CAF, ISO 27001, SOC 2), with strong information and cyber security risk knowledge and experience.
  • experience in managing cybersecurity for complex supply chains in sectors such as technology, healthcare, finance, or critical infrastructure, with the ability to identify and assess potential cybersecurity risks across the supply chain.
  • in-depth knowledge of cybersecurity principles and how they apply to supply chain and third-party risk management, including familiarity with emerging threats such as cyber-physical risks, counterfeit hardware/software, and compromised components.
  • strong understanding of supply chain operations, global supply chain regulations, and their intersection with cybersecurity policies, including integration of cybersecurity practices into procurement processes and supplier lifecycle/third-party vendor risk management.
  • knowledge of cloud service providers, managed service providers (MSPs), and other third-party IT service ecosystems, and experience working with vendor management systems, supply chain management tools, and cybersecurity risk platforms.
  • excellent communication and negotiation skills, with the ability to manage complex relationships with suppliers and vendors, and strong analytical skills to translate complex cybersecurity issues into actionable business terms.
  • a degree in Information Security, Information Technology, Business, or a related discipline (or equivalent professional experience), complemented by preferred professional certifications such as CISSP, CISM, CTPRP, or CSCP, with ISO 27001 Lead Auditor or Implementer qualifications considered advantageous.

Cyber Security Supply Chain Risk Manager in London employer: Government Digital Service

The Government Digital Service (GDS) is an exceptional employer, offering a dynamic work environment where your contributions directly impact the digital landscape of the UK. With a strong commitment to employee growth, GDS provides opportunities for professional development and collaboration with some of the brightest minds in the digital sector. Located in vibrant hubs across the UK, including Manchester, London, and Bristol, GDS fosters a culture of innovation and transparency, making it an ideal place for those seeking meaningful and rewarding employment in cybersecurity.
G

Contact Detail:

Government Digital Service Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Cyber Security Supply Chain Risk Manager in London

✨Tip Number 1

Network like a pro! Get out there and connect with people in the cybersecurity field. Attend industry events, webinars, or local meetups. You never know who might have the inside scoop on job openings or can refer you to someone looking for a Cyber Security Supply Chain Risk Manager.

✨Tip Number 2

Show off your skills! Create a personal project or contribute to open-source initiatives related to supply chain cybersecurity. This not only boosts your portfolio but also demonstrates your passion and expertise to potential employers.

✨Tip Number 3

Prepare for interviews by brushing up on common cybersecurity scenarios and risk management strategies. Be ready to discuss how you've tackled challenges in previous roles. We want to see your problem-solving skills in action!

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, we love seeing candidates who are genuinely interested in joining our mission to drive a modern digital government.

We think you need these skills to ace Cyber Security Supply Chain Risk Manager in London

Cybersecurity Risk Assessment
Supply Chain Risk Management (SCRM)
Vendor Due Diligence
Compliance and Standards
Incident Response
Vendor Cybersecurity Audits
Training and Awareness
Collaboration and Communication
Supply Chain Resilience
Monitoring and Reporting
Knowledge of cybersecurity frameworks (e.g., NCSC CAF, ISO 27001)
Strong analytical skills
Excellent communication and negotiation skills
Understanding of supply chain operations
Experience with vendor management systems

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the Cyber Security Supply Chain Risk Manager role. Highlight your experience in cybersecurity and supply chain management, and don’t forget to mention any relevant frameworks you’ve worked with. We want to see how your skills align with what we’re looking for!

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you’re passionate about cybersecurity and how your background makes you a great fit for our team. Keep it concise but impactful – we love a good story that connects your experience to our mission.

Showcase Your Achievements: When detailing your experience, focus on your achievements rather than just responsibilities. Use metrics where possible to demonstrate your impact in previous roles. We’re keen to see how you’ve made a difference in past positions!

Apply Through Our Website: Don’t forget to apply through our website! It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it gives you a chance to explore more about our culture and values while you’re at it!

How to prepare for a job interview at Government Digital Service

✨Know Your Cybersecurity Frameworks

Familiarise yourself with key cybersecurity frameworks like NCSC CAF and ISO 27001. Be ready to discuss how these frameworks apply to supply chain risk management, as this will show your understanding of the role's requirements.

✨Demonstrate Cross-Functional Collaboration

Prepare examples of how you've worked with different teams, such as procurement, IT, and legal, to manage cybersecurity risks. Highlighting your ability to communicate effectively across departments will be crucial for this role.

✨Showcase Your Risk Assessment Skills

Be prepared to discuss your experience in conducting risk assessments for vendors and third parties. Share specific instances where you identified and mitigated cybersecurity threats, as this will demonstrate your hands-on expertise.

✨Stay Updated on Emerging Threats

Research current trends in cybersecurity threats, especially those affecting supply chains. Being able to discuss recent incidents or emerging risks will show that you're proactive and knowledgeable about the field.

Cyber Security Supply Chain Risk Manager in London
Government Digital Service
Location: London
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

G
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>