Cyber Third-Party Risk Assessors
About the role
About the role
This role will help establish a consistent, risk-based approach to cyber supplier assurance across third-party providers that access, process, host, transmit or support sensitive health information and critical services.
You’ll assess supplier cyber maturity, test the strength of security controls, review evidence, and identify where remediation, stronger oversight or escalation is needed. The work will suit someone who is comfortable moving between audit detail, risk judgement, supplier conversations and clear written reporting.
The skills and experience we need you to bring
- Strong background in third-party cyber risk, security assurance, IT audit or technology risk
- Experience reviewing supplier alignment with security, privacy, government or regulated-sector frameworks
- Confidence assessing control design and operating effectiveness
- Strong evidence gathering, documentation and written judgement
- Ability to identify critical data, systems, access paths and service dependencies
- Experience assessing subcontractor or fourth-party risk would be useful
- Comfortable documenting findings, residual risks and proportionate remediation actions
- Ability to work with suppliers and internal owners to agree and track treatment plans
- Exposure to health, government, banking, insurance, telecommunications or other regulated environments would be valuable
- Relevant experience with ISO 27001, GRC, supplier assurance, information security risk or privacy controls would fit well
- Wellbeing Discovery Sessions
- Welcome Packs
- Hnry discount
- Exclusive invites
- Optional Pay-As-You-Go PI/PL Insurance
Meet the Consultant