At a Glance
- Tasks: Conduct vendor risk assessments and present actionable insights to stakeholders.
- Company: Dynamic company focused on cybersecurity and risk management.
- Benefits: Competitive pay, flexible work arrangements, and a collaborative environment.
- Other info: Join a diverse team committed to equality and professional growth.
- Why this job: Make a real impact by managing third-party cyber risks in a growing field.
- Qualifications: Experience in third-party risk management and strong communication skills.
We are looking for an experienced Information Security Analyst with a strong focus on third-party cyber risk management. This role centres on conducting detailed vendor risk assessments, analysing findings and presenting clear, actionable insights to stakeholders. You'll play a key role in translating complex infosec concepts into business-friendly language, enabling informed decision-making across the organisation.
Key Responsibilities:
- Conduct in-depth third-party cyber risk assessments across vendors and partners
- Analyse security controls, identify vulnerabilities and assess overall risk exposure
- Proactively identify and flag emerging risks before they impact the business
- Produce high quality assessment reports with clear findings and recommendations
- Present risk insights to both technical and non-technical stakeholders
- Translate infosec 'technical speak' into clear business risk language to support decision-making
- Track remediation activities and ensure timely resolution of identified risks
- Work closely with procurement, legal and business teams to embed security into third-party processes
- Act as a key contact for vendors regarding security assessments and risk queries
Key Skills & Experience:
- Proven experience in third-party risk management / vendor security assessments
- Strong risk analysis and proactive risk identification capability
- Ability to communicate complex security concepts to business stakeholders
- Experience producing detailed reports and presenting findings confidently
- Solid understanding of cybersecurity frameworks and risk methodologies
Key Competencies:
- Analytical & detail oriented
- Strong communicator (Tech to Business translation)
- Proactive & risk focused
- Collaborative & stakeholder facing
Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients. If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.
Infosec Analyst - TPRM in Oxford employer: Sanderson Recruitment
Contact Detail:
Sanderson Recruitment Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Infosec Analyst - TPRM in Oxford
✨Tip Number 1
Network like a pro! Reach out to your connections in the InfoSec field, especially those who work with third-party risk management. A friendly chat can lead to insider info about job openings or even referrals.
✨Tip Number 2
Prepare for interviews by brushing up on your ability to translate complex security concepts into business-friendly language. Practice explaining your past experiences in vendor assessments and risk analysis in a way that resonates with non-technical stakeholders.
✨Tip Number 3
Showcase your analytical skills! Bring examples of your previous risk assessments and reports to interviews. Being able to discuss your findings and how you presented them will demonstrate your expertise and confidence.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, we love seeing candidates who are proactive about their job search!
We think you need these skills to ace Infosec Analyst - TPRM in Oxford
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights your experience in third-party risk management and vendor security assessments. We want to see how your skills align with the job description, so don’t be shy about showcasing relevant projects or achievements!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you’re passionate about InfoSec and how your background makes you a perfect fit for this role. Remember, we love seeing how you can translate complex concepts into business-friendly language.
Showcase Your Communication Skills: Since this role involves presenting findings to both technical and non-technical stakeholders, make sure to highlight your communication skills in your application. We want to know how you can bridge the gap between tech speak and business language!
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you don’t miss out on any important updates during the recruitment process. Plus, we love seeing applications come through our platform!
How to prepare for a job interview at Sanderson Recruitment
✨Know Your Stuff
Make sure you brush up on your knowledge of third-party cyber risk management. Familiarise yourself with common frameworks and methodologies, as well as recent trends in cybersecurity. This will help you answer questions confidently and demonstrate your expertise.
✨Speak Their Language
Practice translating complex infosec concepts into business-friendly language. During the interview, focus on how you can communicate technical findings to non-technical stakeholders. This skill is crucial for the role, so be ready to showcase it with examples.
✨Prepare for Scenario Questions
Expect scenario-based questions that assess your analytical skills and risk identification capabilities. Think of past experiences where you successfully identified risks or improved processes, and be prepared to discuss these in detail.
✨Engage with Stakeholders
Show your collaborative side by discussing how you've worked with different teams in the past. Highlight your experience in engaging with procurement, legal, and business teams to embed security into processes. This will demonstrate your ability to work cross-functionally.