5 дней назад
Third Party Risk Manager (Cyber)
72 200 - 86 640GBP
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Third Party Risk Manager (Cyber) (Cybersecurity/GRC): Leading the design, operation and continuous improvement of third-party cyber risk management for suppliers, partners and critical third parties with an accent on risk-based assessments, supplier assurance and regulatory alignment. Focus on evaluating assurance evidence, managing remediation, challenging senior stakeholders and reporting supplier cyber risk across a regulated insurance and financial services environment.
Location: Hybrid, with attendance at an office 1–3 days per week in Edinburgh, Reigate, Glasgow or Newcastle, United Kingdom.
Salary: £72,200–£86,640 per year, plus annual bonus and benefits.
Company
Tesco Insurance and Money Services provides insurance, travel money and related financial services to more than 2 million customers.
What you will do
- Own and continuously improve the third-party cyber risk management framework, processes and standards.
- Lead cyber risk assessments for suppliers, partners and high-risk or critical third parties.
- Oversee supplier assurance activities, including questionnaires, evidence reviews, attestations and onsite or remote assessments.
- Score supplier cyber risks, define treatment plans, validate remediation and track issues through closure.
- Support internal audits, external audits and regulatory reviews as the subject matter expert for third-party cyber risk.
- Partner with Procurement, Legal, Technology, Data Protection and business teams while producing enterprise-level risk reporting and coaching GRC colleagues.
Requirements
- Significant experience in cybersecurity, third-party risk management, supplier assurance or GRC, including ownership of third-party cyber risk processes.
- Strong knowledge of supplier cyber risk, assurance models, cyber threats, controls and assurance evidence.
- Experience leading assessments of high-risk or critical suppliers and managing risks within agreed risk appetite.
- Ability to influence senior stakeholders and suppliers, constructively challenge ineffective risk management and work across Procurement, Legal, Technology and Data Protection.
- Experience supporting internal audit, external audit and regulatory reviews in a large, complex or regulated environment.
- Relevant certifications such as CISSP, CISM, CRISC, CISA, ISO 27001 Lead Implementer or Lead Auditor.
Nice to have
- Third-party risk or supplier assurance certifications.
Culture & Benefits
- Hybrid working with regular office collaboration and flexibility discussions during the interview process.
- Company pension scheme and performance-related annual bonus.
- Minimum 7.2 weeks of holiday, with the option to buy additional leave.
- Virtual GP service, family leave support and enhanced maternity, shared parental and paternity leave.
- Learning opportunities, award-winning training, colleague discounts and share schemes.
Hiring process
- Applications close on 5 October 2026 at 5pm.
- Interviews are expected to take place shortly after the closing date.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
11 дней назад
IT Risks & Control Manager (Insurance)
59 200 - 88 800GBP
10 дней назад
Global Risk Manager (Cybersecurity, Data & AI)
10 дней назад
Technology GRC Analyst
10 дней назад
Security Assurance Manager
12 дней назад
Senior Digital Security Manager (Cybersecurity)
6 дней назад