Назад
Company hidden
5 дней назад

Third Party Risk Manager (Cyber)

72 200 - 86 640GBP
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Third Party Risk Manager (Cyber) (Cybersecurity/GRC): Leading the design, operation and continuous improvement of third-party cyber risk management for suppliers, partners and critical third parties with an accent on risk-based assessments, supplier assurance and regulatory alignment. Focus on evaluating assurance evidence, managing remediation, challenging senior stakeholders and reporting supplier cyber risk across a regulated insurance and financial services environment.

Location: Hybrid, with attendance at an office 1–3 days per week in Edinburgh, Reigate, Glasgow or Newcastle, United Kingdom.

Salary: £72,200–£86,640 per year, plus annual bonus and benefits.

Company

Tesco Insurance and Money Services provides insurance, travel money and related financial services to more than 2 million customers.

What you will do

  • Own and continuously improve the third-party cyber risk management framework, processes and standards.
  • Lead cyber risk assessments for suppliers, partners and high-risk or critical third parties.
  • Oversee supplier assurance activities, including questionnaires, evidence reviews, attestations and onsite or remote assessments.
  • Score supplier cyber risks, define treatment plans, validate remediation and track issues through closure.
  • Support internal audits, external audits and regulatory reviews as the subject matter expert for third-party cyber risk.
  • Partner with Procurement, Legal, Technology, Data Protection and business teams while producing enterprise-level risk reporting and coaching GRC colleagues.

Requirements

  • Significant experience in cybersecurity, third-party risk management, supplier assurance or GRC, including ownership of third-party cyber risk processes.
  • Strong knowledge of supplier cyber risk, assurance models, cyber threats, controls and assurance evidence.
  • Experience leading assessments of high-risk or critical suppliers and managing risks within agreed risk appetite.
  • Ability to influence senior stakeholders and suppliers, constructively challenge ineffective risk management and work across Procurement, Legal, Technology and Data Protection.
  • Experience supporting internal audit, external audit and regulatory reviews in a large, complex or regulated environment.
  • Relevant certifications such as CISSP, CISM, CRISC, CISA, ISO 27001 Lead Implementer or Lead Auditor.

Nice to have

  • Third-party risk or supplier assurance certifications.

Culture & Benefits

  • Hybrid working with regular office collaboration and flexibility discussions during the interview process.
  • Company pension scheme and performance-related annual bonus.
  • Minimum 7.2 weeks of holiday, with the option to buy additional leave.
  • Virtual GP service, family leave support and enhanced maternity, shared parental and paternity leave.
  • Learning opportunities, award-winning training, colleague discounts and share schemes.

Hiring process

  • Applications close on 5 October 2026 at 5pm.
  • Interviews are expected to take place shortly after the closing date.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →