SonicJobs Logo
Left arrow iconBack to search

Director Third Party Risk Management, 3rd Party Risk Management, TPRM Leader,

ARCUS SEARCH LIMITED
Posted 6 hours ago, valid for 2 days
Location

London, Greater London EC1R 0WX

Salary

£80,000 - £96,000 per annum

info
Contract type

Full Time

In order to submit this application, a Reed account will be created for you. As such, in addition to applying for this job, you will be signed up to all Reed’s services as part of the process. By submitting this application, you agree to Reed’s Terms and Conditions and acknowledge that your personal data will be transferred to Reed and processed by them in accordance with their Privacy Policy.

Sonic Summary

info
  • The Information Security Third Party Supplier Relationship Director position is based in London and is a full-time freelance role.
  • The ideal candidate should have a minimum of 10 years of experience in information security, risk management, or compliance, particularly in third-party supplier management.
  • The role requires a bachelor's degree in Information Security, Computer Science, Business Administration, or a related field, with a master's degree being a plus.
  • Key responsibilities include developing a supplier risk management framework, evaluating and selecting vendors, and ensuring compliance with information security standards.
  • The salary for this position is competitive and commensurate with experience.

Job Title: Information Security Third Party Supplier Relationship Director

Location: London

Job Type: Full-Time Freelancer

Job Summary:

We are seeking a highly skilled and experienced Information Security Third Party Supplier Relationship Director to oversee and manage our organisation's relationships with third-party suppliers in the insurance industry. The ideal candidate will ensure that all third-party vendors meet our stringent information security standards and comply with applicable regulations. This position requires strong leadership, strategic thinking, and the ability to effectively communicate with internal stakeholders and external partners.

Key Responsibilities:

  • Supplier Risk Management: Develop and implement a comprehensive supplier risk management framework that assesses the information security posture of third-party vendors. Conduct regular risk assessments and due diligence reviews of potential and existing suppliers.
  • Policy Development: Create and enforce information security policies and procedures related to third-party engagements, ensuring alignment with industry standards and regulatory requirements.
  • Vendor Evaluation and Selection: Collaborate with procurement and business units to evaluate and select suppliers based on information security criteria. Lead the information security assessment process for new vendors.
  • Contract Management: Review and negotiate contracts with third-party suppliers to ensure that security-related clauses and requirements are included. Work with legal teams to mitigate legal risks associated with third-party relationships.
  • Monitoring and Reporting: Establish metrics for assessing vendor performance and compliance with information security requirements. Monitor and report on third-party supplier security incidents and breaches.
  • Stakeholder Engagement: Serve as the primary point of contact for internal stakeholders regarding third-party information security issues. Communicate effectively with business units to ensure alignment on security objectives and requirements.
  • Training and Awareness: Develop and deliver training programs for employees regarding third-party risk management and information security best practices.
  • Incident Response: Coordinate incident response activities related to third-party suppliers, ensuring timely communication and remediation efforts.
  • Continuous Improvement: Stay updated on industry trends, threats, and regulatory changes that impact third-party risk management and information security. Continuously improve processes to enhance security posture.

Qualifications:

  • Bachelor's degree in Information Security, Computer Science, Business Administration, or a related field; master's degree is a plus.
  • Minimum of 10 years of experience in information security, risk management, or compliance, with a focus on third-party supplier management.
  • In-depth knowledge of information security frameworks (e.g., NIST, ISO 27001) and regulatory requirements specific to the insurance industry (e.g., GLBA, HIPAA).
  • Strong analytical, problem-solving, and decision-making skills with a keen attention to detail.
  • Excellent interpersonal and communication skills, with the ability to build strong relationships with vendors and internal stakeholders.
  • Experience with security assessment tools and vendor management platforms is preferred.
  • Relevant certifications (e.g., CISSP, CISM, CRISC, or equivalent) are highly desirable.

Additional Information:

  • Ability to work independently and collaboratively in a fast-paced environment.
  • Willingness to travel occasionally for vendor assessments and meetings.
  • Understanding of the insurance industry's specific challenges related to information security and third-party risk management.

Apply now in a few quick clicks

In order to submit this application, a Reed account will be created for you. As such, in addition to applying for this job, you will be signed up to all Reed’s services as part of the process. By submitting this application, you agree to Reed’s Terms and Conditions and acknowledge that your personal data will be transferred to Reed and processed by them in accordance with their Privacy Policy.