Third Party Risk Management Lead

Company: La Fosse
Apply for the Third Party Risk Management Lead
Location: Greater London
Job Description:

Third Party Cyber Risk Lead – London/Hybrid – up to £90,000 + bonus + benefits

La Fosse has partnered with a leading global specialty insurer to hire a Third Party Cyber Risk Lead. This is a key role within their Cyber Governance team, owning and maturing third-party cyber risk management across an international vendor estate as the business continues to grow and evolve.

You’ll take ownership of the third-party security due diligence process end to end, helping shape how vendor cyber risk is assessed, monitored, and reported across the business. This role will work closely with Procurement, Legal, IT, and senior stakeholders to ensure cyber risk is embedded into the wider vendor management lifecycle in a pragmatic and scalable way.

Responsibilities

  • Own the third-party cyber risk process end to end, covering onboarding, assessment, and ongoing supplier oversight
  • Define supplier criticality and make sure assurance activity is proportionate, risk-based, and scalable
  • Run cyber due diligence for critical vendors and high-risk engagements in line with regulatory and business requirements
  • Deliver strong MI and reporting that gives leadership clear visibility of vendor risk exposure and control gaps
  • Partner with Procurement, Legal, and IT to embed security into supplier governance and decision-making
  • Provide expert input on supplier assessments, security reviews, and contractual risk considerations
  • Build the documentation, standards, and guidance needed to support a mature and consistent TPRM capability
  • Escalate key issues, track remediation, and help shape the ongoing maturity of the cyber risk function

Requirements

  • Proven experience in cyber risk, information security, or supplier assurance roles with a clear focus on third-party risk
  • Track record of standing up or improving vendor due diligence and security assessment processes
  • Good knowledge of recognised assurance frameworks including ISO 27001, SOC 2, CSA CAIQ, and related evidence reviews
  • Experience navigating regulated environments and applying requirements from frameworks such as DORA, NIS2, PRA, FCA, GDPR, NIST, and CIS
  • Confident communicating cyber risk in a way that is clear, commercial, and actionable
  • Strong stakeholder management skills with the ability to influence across technical and non-technical teams
  • Relevant certifications such as CISSP, CISM, CRISC, or ISO 27001 would be a plus
  • Exposure to GRC tooling, supplier risk platforms, and reporting tools such as Power BI is advantageous

#J-18808-Ljbffr…

Posted: March 25th, 2026