Third Party Cyber Risk Lead

Location: London Salary: £80000.00 - £90000.00 per annum Type: Permanent

Third Party Cyber Risk Lead - Specialty Insurance - London (Hybrid)
£80,000 - £90,000 + Benefits

A leading insurance organisation is seeking an experienced Third Party Cyber Risk Lead to join its growing Cyber Governance function.

This is an excellent opportunity for a cyber risk professional who enjoys owning & developing risk frameworks, working closely with senior stakeholders, & driving meaningful improvements across a complex supplier landscape.

You'll play a pivotal role in strengthening & maturing an established Third Party Risk Management (TPRM) programme, helping ensure that cyber risks across a large & diverse vendor estate are identified, assessed & managed effectively.

*Please note previous Insurance industry experience is highly preferred*

Role:

  • Own & lead Third Party Cyber Risk Management activities across a large supplier ecosystem.
  • Conduct cyber due diligence assessments for new & existing suppliers.
  • Perform supplier criticality & risk assessments to support informed business decision-making.
  • Review & evaluate third-party security controls, evidence & risk information.
  • Develop, refine & enhance cyber risk assessment methodologies & governance processes.
  • Work closely with technology, procurement, compliance, legal & business stakeholders.
  • Drive continuous improvement across third-party risk processes, reporting & controls.
  • Explore opportunities to introduce automation, tooling & AI-driven efficiencies into assessment activities.
  • Contribute to the ongoing maturity of the overall Cyber Governance function.


Experience
Proven experience within Third Party Risk Management (TPRM), Vendor Risk Management (VRM) or Supplier Cyber Risk.

  • Strong understanding of cyber security governance, risk & compliance principles.
  • Experience conducting vendor security assessments & cyber due diligence reviews.
  • Ability to develop & improve risk management processes & assessment frameworks.
  • Strong stakeholder engagement skills with the ability to influence at all levels of the business.
  • Experience presenting findings, recommendations & risk positions to senior leadership.
  • Ability to work autonomously & take ownership of initiatives from concept through to delivery.
  • Excellent communication & relationship-building skills.
  • Knowledge of industry frameworks & standards such as ISO27001, NIST, CIS Controls or SOC reporting.
  • Exposure to cyber governance, supplier assurance, regulatory compliance or operational resilience programmes.
  • Experience leveraging automation, AI or workflow tooling to improve risk assessment processes.


If you have the relevant experience & skills, please forward your profile for an immediate review.
pratap@pioneer-search.com

Data & Application Notice

We process personal data submitted as part of your application for recruitment purposes in line with UK GDPR. All applications are reviewed by a member of our team, we do not use automated decision-making in our selection process.
Your application will be assessed against the requirements of this role.

By applying to this advert, you consent to receiving future relevant roles & industry news & insights from us. To opt out of this, please contact: compliance@pioneer-search.com.

For more information on how we use your data, including how long we retain it & your rights, please refer to our Privacy Policy: www.pioneer-search.com/privacy-policy.