third-party security programme, and be the person who turns evidence into something a due diligence team or a certification auditor can be satisfied by. You will be responsible for building controls, gathering evidence, and challenging suppliers. What you will own: 1. Third-party security assurance Run security … security and data protection schedules. Maintain a supplier tiering model based on criticality and run the periodic re-assessment cycle for tiered suppliers: certification expiry, subprocessor changes, breach notifications, SLA performance. Maintain the supplier and outsourcing registers, including preparation for the FCA's material third party register under PS26 ...