Business Analyst (Third Party Cyber Security)

Company: Caraffi
Apply for the Business Analyst (Third Party Cyber Security)
Location: Reading
Job Description:

Business Analyst – Third‑Party Cyber Security Risk (Transformation Programme)

Location: Reading (Hybrid, 2 days per week)

Duration: Initial 6 Months

Contract Type: Day Rate Inside IR35

Are you energised by building structure where there is none, shaping frameworks that drive consistency, and influencing how organisations manage cyber risk? This role offers the opportunity to play a pivotal part in a multi‑year cyber security transformation programme focused on strengthening third‑party and supplier risk management across a diverse, global business landscape.

You’ll join a dedicated cyber transformation team working across Procurement, Legal, Cyber Security, and Internal Audit to modernise how the organisation identifies, assesses, and manages critical suppliers. This is a hands‑on, analytical role ideal for someone who enjoys solving complex problems, engaging stakeholders, and designing practical, scalable solutions.

What You’ll Do

1. Develop a Clear, Evidence‑Based Critical Supplier Definition

  • Gather and analyse business requirements to shape a robust definition of “critical suppliers”.
  • Design a structured, user‑friendly framework that enables consistent supplier classification across the organisation.
  • Produce guidance materials, templates, and documentation to support long‑term adoption.

2. Support Business Units in Identifying Critical Suppliers

  • Engage stakeholders across multiple business units to embed the new framework.
  • Facilitate workshops, discovery sessions, and one‑to‑one support to guide teams through applying the criteria.
  • Consolidate outputs into a single, organisation‑wide view of critical suppliers.

3. Strengthen Cyber Security Contract Addendums

  • Analyse existing contract language to identify gaps in cyber, regulatory, and risk‑related clauses.
  • Collaborate with Legal, Procurement, and Cyber Security teams to enhance contractual protections for critical suppliers.
  • Support the creation of standardised, risk‑aligned contract language.

4. Contribute Across the Third‑Party Risk Transformation Programme

  • Provide business analysis expertise across additional workstreams.
  • Support process design, requirements gathering, governance development, and documentation.
  • Adapt to evolving priorities and help deliver a cohesive, multi‑phase transformation.

What You’ll Bring (Essential Skills & Experience)

This role is built for someone who is analytical, structured, and confident navigating complex stakeholder environments. The essential skills include:

  • Strong ability to gather, analyse, and translate business requirements into clear, structured outputs
  • Understanding of supplier risk, criticality, or third‑party risk concepts
  • Experience designing frameworks, models, or assessment criteria (ideally in risk, procurement, or cyber)
  • Ability to interpret or analyse contract clauses, particularly those relating to risk or security
  • Excellent communication skills, with the ability to articulate complex ideas in a clear, business‑friendly way
  • Adaptability, with comfort pivoting as programme priorities evolve
  • Strong relationship‑building skills, especially in federated or decentralised environments
  • Analytical mindset, able to evaluate processes, identify gaps, and propose improvements

Desirable Experience

  • Experience working with Legal, Procurement, Audit, or Compliance teams
  • Experience managing third‑party relationships or outsourced services
  • Familiarity with structured analysis techniques
  • Awareness of cyber‑related regulations (e.g., GDPR, NIS2, DORA)
  • Knowledge of third‑party risk frameworks such as ISO/IEC 27001 or 27036

If you’re excited by the idea of shaping how a global organisation manages third‑party cyber security risk—and you thrive in environments where you can bring clarity, structure, and influence—this role offers a rare opportunity to make a meaningful impact.

Posted: April 1st, 2026