Salary – Between £72,200 - £86,640 + annual bonus & benefits
Work Level – WL2
Location – Edinburgh, Reigate, Glasgow, Newcastle. Permanent.
Office Attendance - Our roles are hybrid; however, you should be able to travel to our office, 1-3 days per week for this position.
Closing Date - Applications close 6th August at 5pm
We’re looking for two Third Party Risk Manager – Cyber to join our Insurance, Money & Services team.
Reporting to the Lead GRC Manager, you’ll lead the design, operation and continuous improvement of our third-party cyber risk management capability. You’ll ensure that cyber risks introduced through suppliers, partners and third parties are identified, assessed, treated and monitored in line with enterprise risk appetite, regulatory expectations and industry best practice.
You’ll play a critical role as a subject matter expert for cyber third-party risk, providing clear direction, pragmatic risk decisions and senior-level assurance that supplier cyber risks are being effectively managed.
What you’ll be doing
• Own and evolve the cyber third-party risk management framework, processes and standards, ensuring alignment with the wider enterprise GRC framework, procurement processes and supplier lifecycle.
• Lead cyber risk assessments of suppliers, partners and third parties, including high-risk and critical suppliers.
• Oversee supplier assurance activity, including questionnaires, evidence reviews, attestations and onsite or remote assessments.
• Ensure cyber risks are clearly articulated, scored and recorded consistently, with appropriate treatment plans in place.
• Validate supplier remediation plans and track progress through to closure.
• Act as the primary point of contact for cyber third-party risk during internal audit, external audit and regulatory reviews.
• Apply enterprise risk appetite when reviewing and approving supplier cyber risks, escalating unmanaged or unacceptable risks through the appropriate governance forums.
• Partner closely with Procurement, Legal, Technology, Data Protection and Business teams to drive proportionate and pragmatic risk treatment decisions.
• Produce clear reporting on supplier cyber risk posture, trends and systemic issues, contributing to enterprise-level cyber and GRC reporting.
• Provide specialist guidance and coaching to GRC Managers, Analysts and wider teams, helping to build capability across the function.
We need you to have (minimum experience)
• Third-party cyber risk expertise
o Significant experience in cyber security, third-party risk management, supplier assurance or GRC.
o Demonstrate ownership of third-party cyber risk processes and outcomes.
o Deep knowledge of supplier cyber risk and assurance models, including proportionate, risk-based assessment approaches.
• Cyber risk assessment and assurance
o Strong understanding of cyber threats, controls and assurance evidence.
o Experience leading supplier assessments and reviewing assurance evidence for high-risk or critical suppliers.
o Ability to articulate, score and manage supplier cyber risks in line with agreed risk appetite.
• Stakeholder Management and influence
o Experience working closely with Procurement, Legal, Technology, Data Protection and Business teams.
o Ability to influence senior stakeholders and suppliers without direct authority.
o Confidence to constructively challenge suppliers and internal teams where cyber risks are not being managed effectively.
• Regulatory & assurance knowledge
o Experience supporting internal audit, external audit and regulatory reviews.
o Strong understanding of supplier assurance in a large, complex or regulated environment.
o Ability to provide defensible assurance that supplier cyber risks are understood and managed within risk appetite.
• Certifications
o CISSP, CISM, CRISC, CISA
o ISO 27001 Lead Implementer or Lead Auditor
o Third-party risk or supplier assurance certifications would also be beneficial
We don’t expect you to tick every box, and if you feel you hit most of the brief, it’s worth exploring to further develop your career here with us.
What’s in it for you
• Prepare for your retirement with our colleague pension scheme.
• Virtual GP Service for you and your family 365 days a year.
• Performance related annual bonus.
• Indulge in a generous holiday allowance with a minimum of 7.2 weeks, with the opportunity to buy more.
• Embrace the benefits of our Colleague Clubcard, enjoy a 10% discount that increase to 15% every payday. As an added perk, we’ll give you a second card to share with someone else.
• Benefit from our family-oriented initiatives, encompassing enhanced maternity leave pay, a shared parental leave policy, and a generous 8-week paid paternity leave.
• A place to get on - take advantage of our ongoing learning opportunities and award-winning training, to help you achieve the job and career you want.
• Take part in our Buy as you Earn and Save as your Earn share schemes.
Everyone’s welcome
We want all our colleagues to always feel welcome and be themselves. We’re committed to building a more inclusive workplace and celebrating everything that makes colleagues unique, and value the richness and diversity this brings to our business. A more diverse business helps us deliver on our purpose to serve our customers, communities, and planet a little better every day.
Interviews
We also know the importance of balancing work with life’s other commitments. Please talk to us at interview about the flexibility you need, as we’re committed to exploring part time and flexible working opportunities, at every level of the organisation.
Interviews are expected to be held shortly after closing date.