Security Supply Chain Assurance Lead
Security Supply Chain Assurance
Length: 1st November - March 2027, extensions to follow
Inside IR35: £450 (more junior) - £560 per day
Active SC Required
Fully remote, ad hoc travel to London
A critical government department is strengthening how it assures the security of its third-party suppliers. This senior role leads Second Line of Defence (2LoD) governance for supply chain security. You'll oversee, assure and analyse supplier security so that policies, controls and risk management processes work as intended and support organisational, regulatory and industry requirements.
The immediate focus is building out the organisation's use of a third-party risk management (TPRM) platform (RiskLedger) and moving the supply chain assurance programme forward. You'll work in a small team of one or two, so you'll need to shape and drive the work yourself with limited handover.
Key responsibilities
- Lead 2LoD governance, oversight and assurance of supply chain security activity.
- Develop and expand the use of the TPRM platform for supplier onboarding, assessment and ongoing monitoring.
- Assess third-party suppliers against the NCSC Cyber Assessment Framework (CAF), the client's internal Security Controls Framework, physical security requirements and internal risk standards.
- Evaluate supplier risk, identify gaps and agree proportionate remediation with suppliers and internal owners.
- Turn assurance data into insight and reporting that improves security posture and resilience.
- Advise stakeholders across security, procurement, commercial and risk on supplier security matters.
- Help define and mature the supply chain assurance approach, processes and governance.
Essential skills and experience
- Proven experience in supply chain or third-party security assurance, ideally in the public sector, CNI or another regulated environment.
- A strong grounding in information and cyber security risk management.
- Working knowledge of the NCSC CAF and of security controls frameworks such as ISO 27001, NIST or Cyber Essentials.
- Experience in a 2LoD or assurance function, including governance, oversight and challenge.
- The confidence to operate autonomously, set direction and build a function from an early stage.
- Strong stakeholder management and reporting skills, including at senior level.
- Active SC clearance.
Desirable
- Hands-on experience with RiskLedger or similar TPRM platforms such as SecurityScorecard, BitSight or Prevalent.
- An understanding of physical security assurance in supplier settings.
- Experience in critical national infrastructure or other regulated sectors.
- A relevant certification such as CISSP, CISM, CISA or CRISC.