At a Glance
- Tasks: Lead third-party cyber risk management and enhance security processes for vendors.
- Company: Join a leading global specialty insurer with a focus on innovation and collaboration.
- Benefits: Competitive salary, dynamic work environment, and opportunities for professional growth.
- Why this job: Make a real impact in cybersecurity while working with cutting-edge technology.
- Qualifications: Experience in cyber risk management and relevant certifications required.
- Other info: Be part of a rapidly growing team that values creativity and inclusivity.
The predicted salary is between 36000 - 60000 £ per year.
Why
Standing still is not an option in the current world of Insurance. TMHCC is one of the world’s leading Specialty Insurers. With deep expertise in our chosen lines of business, our unparalleled track record and a solid balance sheet, TMHCC evaluates and manages risk like no one else in the industry. Looking beyond profit, empowering our people and delivering on our commitments are at the core of our customer values, along with a desire to grow and provide creative and innovative solutions to our clients.
About Operations
Operations sits at the heart of TMHCC, we ensure the smooth running of all business processes — from policy administration and claims handling to data, technology, and delivery. We focus on driving efficiency which enables our teams across the business to deliver exceptional results every day. Our value statement: Ops makes it happen.
Job Purpose:
Reporting to the Cyber Governance Manager in the Business Information Security Office you will own and mature TMHCC International’s third-party cyber risk management processes, streamlining processes as the vendor landscape grows. You will partner with internal teams such as Procurement and Legal to prioritise risk, remediate issues and deliver clear management information on cyber risk across the third-party portfolio.
Key Responsibilities:
- Own, manage, and evolve the third-party security due diligence process for TMHCC International vendors, including onboarding and continuous monitoring.
- Establish and maintain a vendor criticality assessment process; Ensure the appropriate vendor due diligence and monitoring activities take place in accordance with vendor criticality.
- Own and maintain ongoing due diligence requirements for critical and high-risk suppliers in line with regulatory expectations, including DORA, NIS2, PRA and FCA requirements etc.
- Build MI and dashboards to showcase security due diligence and third-party risk management efforts for senior IT stakeholders and executives.
- Collaborate with IT, Procurement, and Legal teams to embed third party security risk management controls into the overall vendor risk management process.
- Ensure compliance with relevant industry regulations and standards (e.g., DORA, NIS2, CIS Controls, NIST, GDPR).
- Provide security guidance on third party due diligence, contract reviews, and other ad-hoc vendor security risk management queries.
- Create and maintain vendor security risk management documentation (including process documentation) and training materials.
- Stay current on emerging vendor security trends, tools, and technologies.
- Support the Cyber Governance Manager by providing metrics to the Divisional IT Risk Reporting and Dashboards.
- Escalate significant cyber risks and issues as they emerge to the Cyber Governance Manager and BISO for action or information.
Performance Objectives:
- Develop a strong understanding on TMHCC’s third party landscape and current organisational controls used within the vendor risk management process and take on responsibility for cyber third-party risk management.
- Identify gaps and improvement areas within the cyber third-party risk processes, develop plans to further mature cyber security controls within this area, and own the implementation of these plans going forward.
Skills and Experience Specification:
Essential:
- Experience in cyber/information security risk roles with a focus on third-party/vendor risk management.
- Bachelor’s degree in information security, Technology Risk Management or a related field.
- Relevant professional certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Lead Auditor.
- Experience in regulated industries, implementing relevant regulations and expectations for third-party security risk management.
- Proven experience designing, running, and improving vendor security due diligence processes.
- Strong knowledge of security assurance certifications and assessments maintained by vendors (e.g., ISO 27001, SOC 2, CSA STAR/CAIQ, vendor security questionnaires).
- Deep understanding of and ability to articulate the risk associated with vendor risk posture to both technical and non-technical stakeholders.
- Ability to coordinate and chair regular meetings and workshops with multiple stakeholders to provide guidance, collaboration and oversight of third-party security risk management initiatives.
- Confidence in presenting information and acting as a source of SME knowledge and guidance.
- Analytical, conceptual thinking, planning and execution skills.
- Ability to drive improvements and take charge of initiatives, backed with excellent coordination strength as well as assertiveness.
- Results-orientated and able to manage to measurable targets and desired outcomes.
- A passion to champion a cyber security culture and continuous learning of latest cyber threat trends.
- Strong communication skills with the ability to explain complex security issues to non-technical stakeholders.
Desirable:
- Experience with third party risk management platforms or GRC tooling.
- Capability and experience in building actionable MI and dashboards (e.g. using Power BI) and turning data into clear decisions and narratives.
- Experience of the Specialty and Lloyd’s/Companies market insurance industry.
What We Offer
The Tokio Marine HCC Group of Companies offers a competitive salary and employee benefit package. We are a successful, dynamic organization experiencing rapid growth and are seeking energetic and confident individuals to join our team of professionals. The Tokio Marine HCC Group of companies is an equal opportunity employer.
Third Party Cyber Risk Lead employer: Tokio Marine HCC
Contact Detail:
Tokio Marine HCC Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Third Party Cyber Risk Lead
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend events, and connect on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by researching TMHCC and understanding their values and operations. Tailor your responses to show how your skills align with their mission of delivering exceptional results and driving efficiency.
✨Tip Number 3
Practice makes perfect! Conduct mock interviews with friends or use online platforms to refine your answers. Focus on articulating your experience in cyber risk management and how you can contribute to their team.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, it shows you’re genuinely interested in being part of the TMHCC family.
We think you need these skills to ace Third Party Cyber Risk Lead
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Third Party Cyber Risk Lead role. Highlight your experience in cyber/information security risk and any relevant certifications. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about cyber risk management and how you can contribute to our team. Keep it concise but impactful – we love a good story!
Showcase Your Achievements: When detailing your experience, focus on specific achievements rather than just duties. Did you improve a process or reduce risks? Quantify your successes to grab our attention – numbers speak volumes!
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, it shows us you’re serious about joining our team at TMHCC!
How to prepare for a job interview at Tokio Marine HCC
✨Know Your Cyber Risk Stuff
Make sure you brush up on your knowledge of third-party cyber risk management. Familiarise yourself with relevant regulations like DORA and NIS2, and be ready to discuss how you've implemented these in past roles. This shows you're not just a fit for the role but also genuinely interested in the field.
✨Showcase Your Collaboration Skills
Since this role involves working closely with teams like Procurement and Legal, prepare examples of how you've successfully collaborated with different departments in the past. Highlight any specific projects where you’ve led cross-functional teams to achieve a common goal.
✨Prepare for Technical Questions
Expect some technical questions about vendor security due diligence processes and risk assessments. Brush up on your knowledge of security assurance certifications like ISO 27001 and SOC 2, and be ready to explain how you would assess a vendor's security posture.
✨Bring Data to Life
Since building MI and dashboards is part of the job, think of ways you've used data to drive decisions in previous roles. Be prepared to discuss how you can turn complex data into actionable insights, perhaps even mentioning tools like Power BI if you have experience with them.