Job Description
Cyber Risk Lead
Up to £90,000 p/annum
Hybrid Working - 3 days onsite
CPS Group are supporting a global financial services organisation with the recruitment of a Cyber Risk Lead to own and develop their third-party cyber risk management framework.
This is a great opportunity for an experienced Cyber Security / Third-Party Risk professional to take ownership of a growing vendor risk function and work closely with IT, Procurement, Legal and senior stakeholders.
The Role:
- Own and continuously improve the third-party cyber risk and security due diligence process.
- Lead vendor criticality assessments and ensure appropriate due diligence and ongoing monitoring.
- Manage cyber risk requirements for critical and high-risk suppliers.
- Ensure compliance with regulations including DORA, NIS2, PRA, FCA and GDPR.
- Develop MI, dashboards and reporting for senior IT stakeholders and executives.
- Provide cyber security guidance across vendor assessments, contracts and risk management.
- Identify gaps and drive improvements across third-party cyber risk processes.
Required Experience:
- Proven experience in Cyber Security / Information Security Risk, with a focus on third-party or vendor risk.
- Strong experience designing, managing and improving vendor security due diligence processes.
- Knowledge of vendor security assessments (ideally CSA STAR/CAIQ, SOC 2, and ISO 27001)
- Experience working within a regulated industry and understanding relevant regulatory requirements.
- Strong understanding of third-party cyber risk and the ability to communicate risks to both technical and non-technical stakeholders.
- Experience with GRC / third-party risk management platforms is desirable.
- Experience producing MI and dashboards, ideally using Power BI, is desirable.
- Relevant certifications such as CISSP, CISM, CRISC or ISO 27001 are advantageous.
If interested, please contact apply and contact Sam John.