Third Party Cyber Risk Lead

Third Party Cyber Risk Lead

Full-Time 60000 - 80000 £ / year (est.) No home office possible
Tokio Marine HCC International

At a Glance

  • Tasks: Lead third-party cyber risk management and streamline vendor security processes.
  • Company: Join Tokio Marine HCC, a top global specialty insurer with a dynamic culture.
  • Benefits: Competitive salary, great benefits, and opportunities for professional growth.
  • Why this job: Make a real impact in cybersecurity while working with innovative teams.
  • Qualifications: Experience in cyber risk management and relevant certifications required.
  • Other info: Be part of a rapidly growing organisation with a focus on collaboration and empowerment.

The predicted salary is between 60000 - 80000 £ per year.

Tokio Marine HCC is one of the world’s leading Specialty Insurers. With deep expertise in our chosen lines of business, our unparalleled track record and a solid balance sheet, TMHCC evaluates and manages risk like no one else in the industry. Looking beyond profit, empowering our people and delivering on our commitments are at the core of our customer values, along with a desire to grow and provide creative and innovative solutions to our clients.

About Operations: Operations sits at the heart of TMHCC, ensuring the smooth running of all business processes — from policy administration and claims handling to data, technology, and delivery. We focus on driving efficiency which enables our teams across the business to deliver exceptional results every day. Our value statement: Ops makes it happen. Operations is made up of 7 functions; this role sits within IT. We are the foundation for TMHCC’s success - enabling the business to grow, compete, and innovate through technology, security, and solution design.

Job Purpose: Reporting to the Cyber Governance Manager in the Business Information Security Office, you will own and mature TMHCC International’s third-party cyber risk management processes, streamlining processes as the vendor landscape grows. You will partner with internal teams such as Procurement and Legal to prioritise risk, remediate issues and deliver clear management information on cyber risk across the third-party portfolio.

Key Responsibilities:

  • Own, manage, and evolve the third-party security due diligence process for TMHCC International vendors, including onboarding and continuous monitoring.
  • Establish and maintain a vendor criticality assessment process; ensure the appropriate vendor due diligence and monitoring activities take place in accordance with vendor criticality.
  • Own and maintain ongoing due diligence requirements for critical and high-risk suppliers in line with regulatory expectations, including DORA, NIS2, PRA and FCA requirements.
  • Build MI and dashboards to showcase security due diligence and third-party risk management efforts for senior IT stakeholders and executives.
  • Collaborate with IT, Procurement, and Legal teams to embed third party security risk management controls into the overall vendor risk management process.
  • Ensure compliance with relevant industry regulations and standards (e.g., DORA, NIS2, CIS Controls, NIST, GDPR).
  • Provide security guidance on third party due diligence, contract reviews, and other ad-hoc vendor security risk management queries.
  • Create and maintain vendor security risk management documentation (including process documentation) and training materials.
  • Stay current on emerging vendor security trends, tools, and technologies.
  • Support the Cyber Governance Manager by providing metrics to the Divisional IT Risk Reporting and Dashboards.
  • Escalate significant cyber risks and issues as they emerge to the Cyber Governance Manager and BISO for action or information.

Performance Objectives:

  • Develop a strong understanding of TMHCC’s third party landscape and current organisational controls used within the vendor risk management process and take on responsibility for cyber third-party risk management.
  • Identify gaps and improvement areas within the cyber third-party risk processes, develop plans to further mature cyber security controls within this area, and own the implementation of these plans going forward.

Essential Skills and Experience Specification:

  • Experience in cyber/information security risk roles with a focus on third-party/vendor risk management.
  • Bachelor’s degree in information security, Technology Risk Management or a related field.
  • Relevant professional certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Lead Auditor.
  • Experience in regulated industries, implementing relevant regulations and expectations for third-party security risk management.
  • Proven experience designing, running, and improving vendor security due diligence processes.
  • Strong knowledge of security assurance certifications and assessments maintained by vendors (e.g., ISO 27001, SOC 2, CSA STAR/CAIQ, vendor security questionnaires).
  • Deep understanding of and ability to articulate the risk associated with vendor risk posture to both technical and non-technical stakeholders.
  • Ability to coordinate and chair regular meetings and workshops with multiple stakeholders to provide guidance, collaboration and oversight of third-party security risk management initiatives.
  • Confidence in presenting information and acting as a source of SME knowledge and guidance.
  • Analytical, conceptual thinking, planning and execution skills.
  • Ability to drive improvements and take charge of initiatives, backed with excellent coordination strength as well as assertiveness.
  • Results-orientated and able to manage to measurable targets and desired outcomes.
  • A passion to champion a cyber security culture and continuous learning of latest cyber threat trends.
  • Strong communication skills with the ability to explain complex security issues to non-technical stakeholders.

Desirable:

  • Experience with third party risk management platforms or GRC tooling.
  • Capability and experience in building actionable MI and dashboards (e.g. using Power BI) and turning data into clear decisions and narratives.
  • Experience of the Specialty and Lloyd’s/Companies market insurance industry.

What We Offer: The Tokio Marine HCC Group of Companies offers a competitive salary and employee benefit package. We are a successful, dynamic organization experiencing rapid growth and are seeking energetic and confident individuals to join our team of professionals. The Tokio Marine HCC Group of companies is an equal opportunity employer.

Third Party Cyber Risk Lead employer: Tokio Marine HCC International

At Tokio Marine HCC, we pride ourselves on being a leading Specialty Insurer that values empowerment, innovation, and collaboration. Our inclusive work culture fosters personal and professional growth, providing employees with the opportunity to tackle meaningful challenges in the dynamic field of cyber risk management. With a competitive salary and comprehensive benefits package, we are committed to supporting our team members as they build fulfilling careers that make a real impact.
Tokio Marine HCC International

Contact Detail:

Tokio Marine HCC International Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Third Party Cyber Risk Lead

✨Tip Number 1

Network like a pro! Reach out to folks in the industry, especially those at Tokio Marine HCC. A friendly chat can open doors that a CV just can't.

✨Tip Number 2

Prepare for interviews by researching TMHCC's values and recent projects. Show them you’re not just another candidate; you’re genuinely interested in their mission and how you can contribute.

✨Tip Number 3

Practice your pitch! Be ready to explain how your experience aligns with the role of Third Party Cyber Risk Lead. Keep it concise but impactful—make them remember you!

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re serious about joining the team.

We think you need these skills to ace Third Party Cyber Risk Lead

Cyber Risk Management
Vendor Risk Management
Information Security
Regulatory Compliance
Risk Assessment
Data Analysis
Communication Skills
Stakeholder Engagement
Process Improvement
Project Management
Technical Knowledge of Cyber Security
Dashboard Creation
Analytical Thinking
Problem-Solving Skills
Collaboration

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter for the Third Party Cyber Risk Lead role. Highlight your experience in cyber risk management and how it aligns with TMHCC's values. We want to see how you can contribute to our mission!

Showcase Your Skills: Don’t just list your qualifications; demonstrate them! Use specific examples from your past roles that showcase your expertise in vendor risk management and compliance with regulations like DORA and NIS2. This helps us see your potential impact.

Be Clear and Concise: When writing your application, keep it straightforward. Use clear language and avoid jargon where possible. We appreciate a well-structured application that makes it easy for us to understand your experience and skills.

Apply Through Our Website: We encourage you to submit your application through our website. It’s the best way for us to receive your details directly and ensures you’re considered for the role. Plus, it’s super easy to do!

How to prepare for a job interview at Tokio Marine HCC International

✨Know Your Cyber Risk Stuff

Make sure you brush up on the latest trends in cyber risk management, especially around third-party vendors. Familiarise yourself with regulations like DORA and NIS2, as well as industry standards such as ISO 27001. Being able to discuss these confidently will show that you're serious about the role.

✨Showcase Your Experience

Prepare specific examples from your past roles where you've successfully managed vendor security due diligence processes. Highlight any improvements you made and how they benefited the organisation. This will demonstrate your hands-on experience and problem-solving skills.

✨Collaborate Like a Pro

Since this role involves working closely with teams like Procurement and Legal, think of ways to illustrate your collaborative skills. Be ready to discuss how you've worked with different stakeholders in the past to achieve common goals, especially in a regulated environment.

✨Prepare Questions

Have a few thoughtful questions ready for your interviewers. Ask about TMHCC's approach to evolving their third-party risk management processes or how they stay ahead of emerging cyber threats. This shows your genuine interest in the company and the role.

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>