At a Glance
- Tasks: Lead and enhance third-party cyber risk assurance processes for a dynamic organisation.
- Company: Join a forward-thinking company focused on cybersecurity and vendor management.
- Benefits: Competitive salary, professional development, and opportunities for career growth.
- Why this job: Make a real impact in cybersecurity while working with cutting-edge technologies.
- Qualifications: Experience in cyber security and a relevant degree or certifications required.
- Other info: Collaborative environment with a focus on continuous improvement and innovation.
The predicted salary is between 36000 - 60000 £ per year.
Key Responsibilities
- Lead and continuously improve the organisation's third-party cyber risk assurance process, covering onboarding, risk assessment, due diligence, and ongoing monitoring.
- Develop and maintain a robust vendor criticality assessment model, ensuring assurance activities are aligned to supplier risk level.
- Define and own due diligence requirements for critical and high-risk third parties in alignment with DORA, NIS2, PRA, FCA, and other emerging regulatory obligations.
- Produce dashboards, scorecards, and MI reports that provide senior stakeholders with meaningful insight into the organisation's third-party cyber risk posture.
- Embed third-party security controls into vendor governance processes, working closely with Procurement, Legal, Technology, and Risk.
- Monitor compliance with industry frameworks such as CIS Controls, NIST, GDPR, and sector-specific guidance.
- Support contract reviews and provide expert input on security clauses, ensuring risk-based decisions are supported by strong security requirements.
- Maintain process documentation, templates, and training materials for all third-party security assurance activities.
- Track developments in vendor security, regulatory change, and emerging threats, ensuring the programme remains aligned to best practice.
- Provide data, commentary, and risk metrics for divisional or organisational IT risk reporting.
- Escalate material risks or emerging issues to the Cyber Governance Manager and BISO leadership when required.
Performance Objectives
- Build a comprehensive understanding of the organisation's supplier landscape and existing vendor governance controls, taking full ownership of third-party cyber risk management.
- Identify gaps within current third-party cyber risk processes and deliver a clear roadmap to mature security controls and oversight.
- Demonstrate measurable improvements in third-party cyber assurance, including reduced risk exposure and increased visibility across leadership teams.
Skills and Experience Specification
Essential
- Experience in cyber security, information security, or technology risk roles with a focus on third-party/vendor risk management.
- Bachelor's degree in Information Security, Technology Risk Management, or a related discipline.
- Professional certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Lead Auditor, or equivalent.
- Experience working in regulated industries and applying regulatory expectations to third-party assurance programmes.
- Proven experience designing, executing, and improving structured vendor due diligence processes.
- Strong understanding of vendor-held assurance artefacts such as ISO 27001, SOC 2, CSA STAR/CAIQ, and security questionnaires.
- Ability to communicate complex vendor-related cyber risks clearly to both business and technical audiences.
- Skilled in facilitating cross-functional meetings, workshops, and risk discussions with diverse stakeholders.
- Confident presenting information, acting as an SME, and influencing decision-making at all levels.
- Strong analytical, conceptual thinking, and structured execution skills.
- Ability to drive initiatives, coordinate effectively across teams, and manage outcomes to agreed targets.
- Results-driven mindset with a commitment to continuous improvement.
- Strong communication skills with the ability to translate technical issues into actionable business insight.
- Passion for championing good cyber behaviours and staying informed about emerging cyber and vendor-related threats.
Desirable
- Experience with third-party risk management or GRC platforms.
- Ability to develop meaningful MI and dashboards (e.g., using Power BI) and convert data into clear insights and decisions.
- Experience within the specialty insurance, financial services, or wider regulated industries.
Third Party Risk Lead Cyber in City of London employer: Hays Technology
Contact Detail:
Hays Technology Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Third Party Risk Lead Cyber in City of London
✨Tip Number 1
Network like a pro! Reach out to your connections in the cyber security field and let them know you're on the hunt for a role. You never know who might have the inside scoop on opportunities that aren't advertised.
✨Tip Number 2
Get your LinkedIn game on point! Make sure your profile is up-to-date and showcases your skills in third-party risk management. Engage with relevant content and connect with industry leaders to increase your visibility.
✨Tip Number 3
Prepare for interviews by brushing up on your knowledge of regulatory frameworks like DORA and NIS2. Be ready to discuss how you've tackled vendor risk in the past and how you can bring that expertise to the table.
✨Tip Number 4
Don't forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you're serious about joining our team and making an impact in third-party cyber risk management.
We think you need these skills to ace Third Party Risk Lead Cyber in City of London
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the role of Third Party Risk Lead Cyber. Highlight your experience in cyber security and vendor risk management, and don’t forget to mention any relevant certifications you have!
Showcase Your Skills: In your application, clearly showcase your skills in communication and analytical thinking. We want to see how you can translate complex cyber risks into actionable insights for both technical and business audiences.
Be Specific About Your Experience: When detailing your past roles, be specific about your experience with third-party assurance programmes and regulatory compliance. Use examples that demonstrate your ability to improve processes and manage risks effectively.
Apply Through Our Website: We encourage you to apply through our website for a smoother application process. It’s the best way for us to receive your application and get you on our radar quickly!
How to prepare for a job interview at Hays Technology
✨Know Your Cyber Risk Stuff
Make sure you brush up on your knowledge of third-party cyber risk management. Familiarise yourself with key regulations like DORA, NIS2, and FCA. Being able to discuss how these apply to the role will show you're serious about the position.
✨Showcase Your Analytical Skills
Prepare to demonstrate your analytical and conceptual thinking skills. Think of examples where you've successfully identified gaps in processes or improved vendor due diligence. This will highlight your ability to drive initiatives and manage outcomes effectively.
✨Communicate Clearly
Practice explaining complex cyber risks in simple terms. You’ll likely need to communicate with both technical and non-technical stakeholders, so being able to translate jargon into actionable insights is crucial.
✨Bring Your Data Game
If you have experience with MI reports or dashboards, be ready to discuss it. Mention any tools you’ve used, like Power BI, and how you’ve turned data into clear insights. This will show your capability in providing meaningful information to senior stakeholders.