Third Party Cyber Risk Lead - Specialty Insurance - London (Hybrid)
£80,000 - £90,000 + Benefits
A leading insurance organisation is seeking an experienced Third Party Cyber Risk Lead to join its growing Cyber Governance function.
This is an excellent opportunity for a cyber risk professional who enjoys owning & developing risk frameworks, working closely with senior stakeholders, & driving meaningful improvements across a complex supplier landscape.
You'll play a pivotal role in strengthening & maturing an established Third Party Risk Management (TPRM) programme, helping ensure that cyber risks across a large & diverse vendor estate are identified, assessed & managed effectively.
*Please note previous Insurance industry experience is highly preferred*
Role:
- Own & lead Third Party Cyber Risk Management activities across a large supplier ecosystem.
- Conduct cyber due diligence assessments for new & existing suppliers.
- Perform supplier criticality & risk assessments to support informed business decision-making.
- Review & evaluate third-party security controls, evidence & risk information.
- Develop, refine & enhance cyber risk assessment methodologies & governance processes.
- Work closely with technology, procurement, compliance, legal & business stakeholders.
- Drive continuous improvement across third-party risk processes, reporting & controls.
- Explore opportunities to introduce automation, tooling & AI-driven efficiencies into assessment activities.
- Contribute to the ongoing maturity of the overall Cyber Governance function.
Experience
Proven experience within Third Party Risk Management (TPRM), Vendor Risk Management (VRM) or Supplier Cyber Risk.
- Strong understanding of cyber security governance, risk & compliance principles.
- Experience conducting vendor security assessments & cyber due diligence reviews.
- Ability to develop & improve risk management processes & assessment frameworks.
- Strong stakeholder engagement skills with the ability to influence at all levels of the business.
- Experience presenting findings, recommendations & risk positions to senior leadership.
- Ability to work autonomously & take ownership of initiatives from concept through to delivery.
- Excellent communication & relationship-building skills.
- Knowledge of industry frameworks & standards such as ISO27001, NIST, CIS Controls or SOC reporting.
- Exposure to cyber governance, supplier assurance, regulatory compliance or operational resilience programmes.
- Experience leveraging automation, AI or workflow tooling to improve risk assessment processes.
If you have the relevant experience & skills, please forward your profile for an immediate review.
pratap@pioneer-search.com
Data & Application Notice
We process personal data submitted as part of your application for recruitment purposes in line with UK GDPR. All applications are reviewed by a member of our team, we do not use automated decision-making in our selection process.
Your application will be assessed against the requirements of this role.
By applying to this advert, you consent to receiving future relevant roles & industry news & insights from us. To opt out of this, please contact: compliance@pioneer-search.com.
For more information on how we use your data, including how long we retain it & your rights, please refer to our Privacy Policy: www.pioneer-search.com/privacy-policy.