b Overview /b p In this role you take a lead in identifying and managing cyber security risks across a complex supplier ecosystem. You will work with procurement, commercial and security teams to embed risk-based decisions throughout the supplier lifecycle. Your work supports stronger third-party risk management and cyber resilience within a regulated, security-conscious environment. This position offers high-impact ownership and collaboration with cross-functional stakeholders to shape supplier security requirements and governance. /p b Responsibilities /b ul li Lead cyber security assessments of prospective and existing suppliers using available information, supplier evidence, and assurance tooling /li li Evaluate supplier security documents including penetration tests, certifications, audits, and SOC reports /li li Own the supplier assurance process: tracking, reporting, governance, and metrics /li li Provide risk-based advice on onboarding, contract renewals, and ongoing supplier engagements /li li Ensure compliance with relevant regulatory and legislative requirements in supplier activities /li li Maintain and mature supplier assurance processes in line with best practices and evolving threats /li li Collaborate with procurement, legal, and operations to align supplier risk management /li li Define cyber security requirements within supplier contracts and security docs /li li Coordinate assessments involving both information and physical security controls where needed /li li Advise on governance for handling sensitive or regulated information by suppliers /li li Identify improvements to assurance processes, tooling, and reporting for third-party risk /li li Review customer security requirements where the organisation acts as a supplier /li li Act as the Cyber Security SME for supplier assurance and participate in stakeholder discussions /li li Contribute to the ongoing development of third-party risk management frameworks and controls /li /ul b Key requirements /b ul li Significant experience in Information Security, Cyber Security GRC, Third-Party Risk Management or Supplier Assurance /li li Proven track record in supplier assurance reviews and third-party cyber security assessments /li li Experience reviewing supplier security evidence (penetration tests, certifications, audit findings, assurance docs) /li li Strong understanding of supplier risk management and third-party cyber security risk /li li Ability to assess technical security controls and communicate risks to technical and non-technical audiences /li li Strong analytical and problem-solving abilities for complex technical information and business impact /li li Experience with risk management frameworks, governance processes and assurance methodologies /li li Excellent stakeholder management and relationship-building skills /li li Strong written and verbal communication, with experience presenting risks to senior stakeholders /li li Eligible for UK SC Security Clearance (active clearance preferred) /li /ul ul li Stakeholder management /li li Clear communication /li li Analytical thinking /li li Information Security /li li Cyber Security GRC /li li Third-Party Risk Management /li /ul
Supplier Assurance Lead employer: Morson Group
Morson Group is an exceptional employer, recognised as one of the UK's Best Big Companies to work for, offering a supportive family-run culture that prioritises employee well-being and development. With 26 days of holiday, bespoke training programmes, and comprehensive mental health support, employees are empowered to grow and thrive in their roles, particularly within the dynamic Payroll team at our Salford office.