Please note this is an OD vacancy and only impacted colleagues who are at risk or placed in a pool will be considered for this role. If you are at risk or in a pool, you will be asked to confirm this in the application process.
Applications from candidates who are not at risk or in a pool will be declined at this stage. The role may be re-advertised in future as a standard vacancy open to all internal candidates.
Role title: Security Analyst - Third Parties
Function: Digital Technology & Data
Reports to: Head of Compliance
Number of reports:0
Work level:WL6a
Role Summary
The purpose is to provide operational support to the Information Security team and wider DT&D function by supporting with third party information security risk assessments, supplier assurance activities and supply chain risk management in order to align with the NIST framework and Third-Party Assurance framework so that supply chain cyber security risk is mitigated.
Key Responsibilities
- Responsible for developing andmaintainingan accurateand up to date third party risk management process for suppliers and partners, to enable prioritisation of supply chain cyber gaps and risks.
- Support the Information Security Leadership team and BISOs with the delivery of third-party security assessments through supplier lifecycle, including onboarding, periodicreviewand offboarding.
- Work with Procurement, Legal, Data Protection,Riskand business stakeholders to obtain informationrequiredto complete supplier assurance reviews.
- Maintainaccuratesupplier risk records and track remediation actions,monitoringprogress,reportingandescalatingas necessary.
- Support continuous monitoring activities by reviewing supplier security ratings,alertsand intelligence from assurance tooling.
- Review third party independent assessments and assurance documentation (e.g. ISO27001, SOC2, Cyber Essentials Plus).
- Support the Information Security Incident Manager to ensure supply chain incidents are reported,investigatedand mitigated asappropriate.
- Production of third-party assurance risk reports,dashboardsand management information
Knowledge, Skills, Experience
- Experience of maintaining third party assurance records and security documentation, within security tooling or M365 tooling to performing supplier security analysis against defined control requirements and articulating this into meaningful risk-based reporting.