Security Analyst
The team you'll be working with: Position Title: Senior Security Analyst - Third-Party Security Assurance (TPSA) – P2/3 Location: United Kingdom/Remote Employment Type: Full-Time, Permanent Reporting To: Head of Information Security We are seeking an experienced security and risk professional to join the Third-Party Security Assurance team. The successful candidate will be responsible for evaluating, monitoring, and managing security, privacy, operational, and compliance risks associated with third parties, suppliers, strategic partners, and acquired entities. The role operates within a complex, multi-entity environment comprising Business Units, third-party suppliers, and M&A integrations, with responsibility for conducting security due diligence, reviewing assessments, evaluating supplier controls, and ensuring effective risk management across the third-party lifecycle. It also serves as a key liaison across TPSA, Legal, Privacy, Compliance, Enterprise Risk, Internal Audit, and business stakeholders, driving consistent risk governance and regulatory compliance. What you'll be doing:
- Collaborate with cross-functional teams including Legal, Procurement, Privacy, and Compliance
- Provide clear, risk-based insights to stakeholders and support decision-making
- Support audit, regulatory, and customer assurance requirements
- Leverage GRC platforms (e.g., OneTrust, BitSight, and internal SaaS solutions) to manage TPSA activities
- Support month-end SLA reporting and develop dashboards using Power BI and SharePoint
- Contribute to governance forums and risk review meetings
- Ensure adherence to TPSA tiering models, standards, and processes
- Maintain oversight of third-party risks throughout the vendor lifecycle.
- Perform periodic reassessments and continuous monitoring activities.
- Track remediation activities and risk treatment plans through closure.
- Maintain third-party risk registers, dashboards, and management reporting.
- Escalate material risks and control deficiencies to appropriate governance forums.
- Partner with Procurement, Legal, Compliance, Privacy, Enterprise Risk, Internal Audit, and Technology teams.
- Provide risk-based recommendations to business stakeholders and decision-makers.
- Support customer assurance requests and regulatory inquiries where required.
- Participate in governance committees and risk review meetings.
- Use Governance, Risk & Compliance (GRC) platforms and applications (for example OneTrust, Drata and Swiss GRC
- Support development of assessment methodologies, risk scoring models, and reporting frameworks.
- Minimum 3 years' experience in Information Security, Cyber Risk Management, Third-Party Risk Management, Supplier Assurance, or GRC functions.
- Demonstrable experience working on third-party security risk programmes within medium to large enterprises.
- Experience supporting organisations operating across multiple jurisdictions, including the UK and European Union.
- Experience reviewing supplier security assessments, due diligence questionnaires, audit reports, and compliance evidence.
- Experience supporting security and risk activities related to mergers and acquisitions.
- Solid hands-on experience in TPRM, security risk, or GRC
- Proven ability to independently deliver third-party assessments end-to-end
- Strong understanding of regulatory frameworks (GDPR, ISO 27001, IS0 42001 etc.)
- Regular interaction with stakeholders (but limited strategiec ownership)