Supplier Assurance Lead

Morson Group

Manchester

Hybrid

GBP 55,000 - 92,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Morson Group is seeking a Senior Supplier Assurance Lead / Cyber Security Risk Manager to drive risk-based supplier assessments across a complex third-party ecosystem. This hybrid role in the North West focuses on managing evidence, controls, and governance to reduce cyber risk with suppliers.

You will lead assurance activities, engage stakeholders across procurement, legal and security, and ensure compliance with evolving regulatory requirements and industry standards.

Qualifications

  • Senior level experience in information security, cyber risk, or supplier assurance.
  • Proven ability to perform third-party cyber risk assessments and supplier assurance reviews.
  • Experience reviewing supplier security evidence such as penetration tests, audits and certifications.
  • Strong understanding of supplier risk management and cyber risk messaging to stakeholders.
  • Ability to communicate risk to technical and non-technical audiences and influence decision makers.
  • Experience with risk management frameworks, governance, and assurance methodologies.
  • Excellent stakeholder management and relationship-building skills.
  • Eligibility for UK SC clearance; active SC clearance preferred.

Responsibilities

  • Lead cyber security assessments of suppliers using public data, evidence and assurance tooling.
  • Assess supplier security documentation including penetration test reports, audits and SOC reports.
  • Manage the supplier assurance process, tracking, reporting, governance and metrics.
  • Provide risk-based recommendations for onboarding, renewals and ongoing engagements.
  • Ensure compliance with regulatory requirements in supplier assurance activities.
  • Maintain processes in line with best practice and evolving threats.
  • Collaborate with procurement, legal and operations to coordinate risk management.
  • Define cyber security requirements in supplier contracts and documents.
  • Coordinate security assessments covering information and physical security controls.
  • Identify improvements to processes, tooling and reporting for third-party risk management.
  • Review customer security requirements when the organisation acts as a supplier.

Skills

Cyber security
GRC
Third-party risk
Supplier assurance
Stakeholder management
Risk communication
Assessment tooling
ISO 27001 knowledge

Tools

Penetration testing reports review
SOC reports familiarity

Job description

Supplier Assurance Lead/ Cyber Security Risk Manager/ Third Party Cyber Risk Lead
£500 per day - Outside IR35 - North West Based - Hybrid

My client is looking for an experienced Supplier Assurance Lead to join their Cyber Security team, taking a lead role in identifying, assessing and managing cyber security risks across a complex supplier and third-party ecosystem.

This is a senior position requiring someone who can go beyond standard supplier due diligence exercises. Youll be expected to understand the underlying cyber security risks within the supply chain, provide risk-based recommendations, and work closely with procurement, commercial and security stakeholders to drive effective risk management throughout the supplier lifecycle.

Security Clearance

Eligibility for UK Security Check (SC) clearance is a mandatory requirement for this role. Candidates who already hold active SC clearance will be prioritised.

Essential Experience:
  • Significant experience within Information Security, Cyber Security GRC, Third-Party Risk Management or Supplier Assurance.
  • Proven experience performing supplier assurance reviews and third-party cyber security assessments.
  • Experience reviewing supplier security evidence including penetration testing reports, certifications, audit findings and assurance documentation.
  • Strong understanding of supplier risk management and third-party cyber security risk.
  • Experience assessing technical security controls and communicating risk clearly to both technical and non-technical stakeholders.
  • Strong analytical and problem-solving skills with the ability to evaluate complex technical information and determine business impact.
  • Experience working with risk management frameworks, governance processes and assurance methodologies.
  • Excellent stakeholder management and relationship-building skills.
  • Strong written and verbal communication skills with experience presenting security risks and recommendations to senior stakeholders.
  • Ability to obtain UK SC Security Clearance.
Key Responsibilities:
  • Lead cyber security assessments of prospective and existing suppliers using publicly available information, supplier-provided evidence and specialist assurance tooling.
  • Assess supplier security documentation including penetration testing reports, certifications, audit reports, SOC reports and other assurance evidence.
  • Manage the cyber security supplier assurance process, including assessment tracking, reporting, governance and metrics.
  • Provide risk-based recommendations and security advice regarding supplier onboarding, contract renewals and ongoing supplier engagements.
  • Ensure supplier assurance activities incorporate relevant legislative, regulatory and compliance requirements.
  • Maintain supplier assurance processes in line with industry best practice and the evolving threat landscape.
  • Work closely with procurement, commercial, legal and operational teams to ensure a coordinated approach to supplier risk management.
  • Support the definition of cyber security requirements within supplier contracts and associated security documentation.
  • Coordinate security assessments involving both information security and physical security controls where required.
  • Ensure appropriate governance processes are followed for suppliers handling sensitive or regulated information.
  • Identify opportunities to improve supplier assurance processes, tooling, reporting and overall third-party risk management capability.
  • Review and assess customer security requirements where the organisation acts as a supplier.
  • Act as the Cyber Security SME for supplier assurance and represent the function in discussions with internal and external stakeholders.
  • Contribute to the ongoing development and maturity of third-party risk management frameworks, processes and controls.
Desirable Experience:
  • Active UK SC Security Clearance.
  • Experience working within highly regulated or security-conscious environments.
  • Experience with supplier assurance platforms and third-party risk management tooling.
  • Knowledge of supply chain risk management and vendor security assurance.
  • Experience developing or enhancing supplier assurance processes and frameworks.
  • Understanding of ISO 27001, NIST, Cyber Essentials and similar security standards.
  • Experience supporting procurement and commercial teams with security-related contractual requirements.
  • Relevant certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor, ISO 27001 Lead Implementer or similar.

This is an excellent opportunity for an experienced cyber security professional to take ownership of supplier assurance activities within a complex environment, helping to strengthen third-party risk management and improve overall cyber resilience.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Supplier Assurance Lead
Supplier Assurance Lead

Morson Human Resources Limited • Greater Manchester

Hybrid
GBP 83,000 - 101,000
Cyber Risk Lead
Cyber Risk Lead

CPS Group (UK) Limited • Greater London

Hybrid
GBP 81,000 - 99,000
Cyber Security Consultant
Cyber Security Consultant

Experis • Preston, Greater London, Birmingham

Hybrid
GBP 111,000 - 116,000
Hybrid Cyber Risk: Supplier Assurance Lead (SC Cleared)
Hybrid Cyber Risk: Supplier Assurance Lead (SC Cleared)

Morson Human Resources Limited • Greater Manchester

Hybrid
GBP 83,000 - 101,000
Cyber Security Assurance Consultant - Contract
Cyber Security Assurance Consultant - Contract

SR2 REC LTD • Greater London, Manchester

Hybrid
GBP 92,000 - 97,000
Cyber Security Consultant
Cyber Security Consultant

Anson McCade • Cardiff

On-site
GBP 61,000 - 101,000
Interim Third Party Security Risk Manager
Interim Third Party Security Risk Manager

La Fosse • Greater London

Hybrid
GBP 70,000 - 90,000
Cyber Compliance Manager
Cyber Compliance Manager

Harvey Nash Group • Manchester

On-site
GBP 70,000 - 90,000
Senior Supplier Assurance Lead: Cyber Risk & Third-Party
Senior Supplier Assurance Lead: Cyber Risk & Third-Party

Morson Group • Manchester

Hybrid
GBP 55,000 - 92,000
Cyber Security Consultant
Cyber Security Consultant

CBSbutler Holdings Limited trading as CBSbutler • City Of London

Hybrid
GBP 91,000 - 119,000