At a Glance
- Tasks: Conduct cyber risk assessments and manage third-party vendor security.
- Company: Join the world's leading sports technology company, connecting sports, media, and betting.
- Benefits: Enjoy a full-time role with opportunities for growth and development in a dynamic environment.
- Why this job: Be part of a team that safeguards operations and drives secure business growth.
- Qualifications: 3-5 years in vendor risk management; knowledge of security standards like ISO/IEC 27001.
- Other info: Ideal for those passionate about information security and compliance.
The predicted salary is between 36000 - 60000 £ per year.
We’re the world’s leading sports technology company, at the intersection between sports, media, and betting. More than 1,700 sports federations, media outlets, betting operators, and consumer platforms across 120 countries rely on our know-how and technology to boost their business.
Sport connects us—across borders, time zones, and cultures. At Sportradar, we use that connection to drive technology forward. Our Information Security Governance, Risk, and Compliance (GRC) team is foundational in safeguarding the integrity and resilience of our operations. We are looking for an InfoSec Third Party Assurance Specialist to assist in conducting cyber risk assessments of third-party technology suppliers, ensure adherence to security policies, and support the identification and record risks. If you’re passionate about ensuring the security posture of vendors and enabling secure business growth at scale, this role is for you.
THE CHALLENGE:
- Conduct security risk assessments on third-party vendors, review SOC reports, and evaluate technical and non-technical controls.
- Maintain and enhance TPRM documentation, including policies, workflows, and assessment templates aligned with ISO/IEC 27001, NIST, and other relevant standards.
- Track and manage third-party risks through to remediation, working directly with vendors and internal stakeholders.
- Contribute to the broader ISMS (Information Security Management System) and support internal risk, compliance, and audit activities.
- Participate in governance initiatives, including regulatory compliance efforts, awareness campaigns, and cross-functional risk assessments.
- Support the wider GRC team with reporting, metrics, and stakeholder communications.
YOUR PROFILE:
- 3–5 years of experience in third-party/vendor risk management, preferably within an information security, risk, or compliance team.
- Strong working knowledge of information security standards and frameworks such as ISO/IEC 27001, SOC 2, NIST CSF, or SIG.
- Familiarity with technology systems, infrastructure, and related security controls.
- Experience conducting vendor risk assessments, including reviewing SOC 2 reports and security questionnaires.
- Familiarity with GRC platforms and tools used for third-party or enterprise risk management.
- Understanding of contractual and regulatory requirements around third-party risk (e.g., GDPR, DORA, or other industry-specific regulations).
- Bonus: Hands-on involvement in broader GRC functions like ISMS maintenance or Business Continuity Management (BCM).
- Preferred certifications: CISA, CRISC, CISSP, or similar.
InfoSec Third Party Assurance Specialist employer: Sportradar AG
Contact Detail:
Sportradar AG Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land InfoSec Third Party Assurance Specialist
✨Tip Number 1
Familiarise yourself with the key information security standards mentioned in the job description, such as ISO/IEC 27001 and NIST. Understanding these frameworks will not only help you in interviews but also demonstrate your commitment to the role.
✨Tip Number 2
Network with professionals in the information security field, especially those who work in vendor risk management. Engaging with industry peers can provide insights into best practices and may even lead to referrals for the position.
✨Tip Number 3
Stay updated on the latest trends and challenges in third-party risk management. Being knowledgeable about current events and emerging threats will show your passion for the field and readiness to tackle real-world issues.
✨Tip Number 4
Prepare to discuss specific examples from your past experience where you've successfully conducted vendor risk assessments or managed third-party risks. Concrete examples will help you stand out during the interview process.
We think you need these skills to ace InfoSec Third Party Assurance Specialist
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in third-party/vendor risk management and information security. Use keywords from the job description, such as 'ISO/IEC 27001' and 'vendor risk assessments', to demonstrate your fit for the role.
Craft a Compelling Cover Letter: In your cover letter, express your passion for information security and how your background aligns with Sportradar's mission. Mention specific experiences that showcase your ability to conduct risk assessments and manage third-party risks.
Showcase Relevant Certifications: If you have certifications like CISA, CRISC, or CISSP, make sure to mention them prominently in your application. These credentials can set you apart and demonstrate your commitment to the field of information security.
Highlight Soft Skills: In addition to technical skills, emphasise your communication and collaboration abilities. The role involves working with vendors and internal stakeholders, so showcasing your interpersonal skills can strengthen your application.
How to prepare for a job interview at Sportradar AG
✨Know Your Standards
Familiarise yourself with key information security standards such as ISO/IEC 27001 and NIST. Be prepared to discuss how these frameworks apply to third-party risk management and how you have used them in your previous roles.
✨Showcase Your Experience
Highlight your experience in conducting vendor risk assessments and reviewing SOC reports. Provide specific examples of how you've identified risks and worked with vendors to mitigate them, demonstrating your hands-on approach.
✨Understand the Regulatory Landscape
Brush up on relevant regulations like GDPR and DORA. Be ready to explain how these regulations impact third-party risk management and how you ensure compliance within your work.
✨Prepare for Scenario Questions
Expect scenario-based questions that assess your problem-solving skills in real-world situations. Think about past challenges you've faced in vendor risk management and how you successfully navigated them.