Please note this is an OD vacancy and only impacted colleagues who are at risk or placed in a pool will be considered for this role. If you are at risk or in a pool, you will be asked to confirm this in the application process. Applications from candidates who are not at risk or in a pool will be declined at this stage. The role may be re-advertised in future as a standard vacancy open to all internal candidates. Role title: Security Analyst - Third Parties Function: Digital Technology & Data Reports to: Head of Compliance Number of reports:0 Work level:WL6a Role Summary The purpose is to provide operational support to the Information Security team and wider DT&D function by supporting with third party information security risk assessments, supplier assurance activities and supply chain risk management in order to align with the NIST framework and Third-Party Assurance framework so that supply chain cyber security risk is mitigated. Key Responsibilities Responsible for developing andmaintainingan accurateand up to date third party risk management process for suppliers and partners, to enable prioritisation of supply chain cyber gaps and risks. Support the Information Security Leadership team and BISOs with the delivery of third-party security assessments through supplier lifecycle, including onboarding, periodicreviewand offboarding. Work with Procurement, Legal, Data Protection,Riskand business stakeholders to obtain informationrequiredto complete supplier assurance reviews. Maintainaccuratesupplier risk records and track remediation actions,monitoringprogress,reportingandescalatingas necessary. Support continuous monitoring activities by reviewing supplier security ratings,alertsand intelligence from assurance tooling. Review third party independent assessments and assurance documentation (e.g. ISO27001, SOC2, Cyber Essentials Plus). Support the Information Security Incident Manager to ensure supply chain incidents are reported,investigatedand mitigated asappropriate. Production of third-party assurance risk reports,dashboardsand management information Knowledge, Skills, Experience Experience of maintaining third party assurance records and security documentation, within security tooling or M365 tooling to performing supplier security analysis against defined control requirements and articulating this into meaningful risk-based reporting.
27/07/2026
Full time
Please note this is an OD vacancy and only impacted colleagues who are at risk or placed in a pool will be considered for this role. If you are at risk or in a pool, you will be asked to confirm this in the application process. Applications from candidates who are not at risk or in a pool will be declined at this stage. The role may be re-advertised in future as a standard vacancy open to all internal candidates. Role title: Security Analyst - Third Parties Function: Digital Technology & Data Reports to: Head of Compliance Number of reports:0 Work level:WL6a Role Summary The purpose is to provide operational support to the Information Security team and wider DT&D function by supporting with third party information security risk assessments, supplier assurance activities and supply chain risk management in order to align with the NIST framework and Third-Party Assurance framework so that supply chain cyber security risk is mitigated. Key Responsibilities Responsible for developing andmaintainingan accurateand up to date third party risk management process for suppliers and partners, to enable prioritisation of supply chain cyber gaps and risks. Support the Information Security Leadership team and BISOs with the delivery of third-party security assessments through supplier lifecycle, including onboarding, periodicreviewand offboarding. Work with Procurement, Legal, Data Protection,Riskand business stakeholders to obtain informationrequiredto complete supplier assurance reviews. Maintainaccuratesupplier risk records and track remediation actions,monitoringprogress,reportingandescalatingas necessary. Support continuous monitoring activities by reviewing supplier security ratings,alertsand intelligence from assurance tooling. Review third party independent assessments and assurance documentation (e.g. ISO27001, SOC2, Cyber Essentials Plus). Support the Information Security Incident Manager to ensure supply chain incidents are reported,investigatedand mitigated asappropriate. Production of third-party assurance risk reports,dashboardsand management information Knowledge, Skills, Experience Experience of maintaining third party assurance records and security documentation, within security tooling or M365 tooling to performing supplier security analysis against defined control requirements and articulating this into meaningful risk-based reporting.
The Co-operative Group is seeking a Security Analyst - Third Parties to support the Information Security team within the Digital Technology & Data function. The role focuses on third party information security risk assessments and supplier assurance to align with NIST and Third-Party Assurance frameworks for mitigating supply chain cyber risks. You will help develop and maintain risk processes, collaborate with stakeholders, and provide regular risk reporting to strengthen our supplier security
27/07/2026
Full time
The Co-operative Group is seeking a Security Analyst - Third Parties to support the Information Security team within the Digital Technology & Data function. The role focuses on third party information security risk assessments and supplier assurance to align with NIST and Third-Party Assurance frameworks for mitigating supply chain cyber risks. You will help develop and maintain risk processes, collaborate with stakeholders, and provide regular risk reporting to strengthen our supplier security