Third Party Cyber Risk Lead

Tokio Marine HCC International

Greater London

On-site

GBP 60,000 - 80,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Competitive salary
Employee benefit package
Dynamic growth environment

Job summary

Tokio Marine HCC International in Greater London is seeking a Third Party Cyber Risk Lead to own and enhance their cyber risk management processes. You will partner with teams to streamline vendor risk management as the landscape grows.

The successful candidate will have experience in cyber risk management, a relevant degree, and necessary certifications. The role offers a competitive salary and benefits, along with the opportunity to shape the future of cyber risk strategy.

Qualifications

  • Experience in cyber/information security risk roles with a focus on third-party/vendor risk management.
  • Bachelor's degree in information security, Technology Risk Management or a related field.
  • Relevant professional certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Lead Auditor.

Responsibilities

  • Manage the third-party security due diligence process for TMHCC International vendors.
  • Ensure compliance with industry regulations and standards for third-party risk management.
  • Provide metrics to the Divisional IT Risk Reporting and Dashboards.

Skills

Cyber/information security risk management
Vendor security due diligence
Stakeholder communication
Analytical skills
Regulatory knowledge

Education

Bachelor’s degree in Information Security or related field
Relevant professional certifications (CISSP, CISM, etc.)

Tools

Vendor risk management platforms
GRC tooling
Power BI

Job description

Job Title

Third Party Cyber Risk Lead

Reporting to

Cyber Governance Manager

Direct Reports

None

Position Type

Permanent

Job Purpose

Reporting to the Cyber Governance Manager in the Business Information Security Office, you will own and mature TMHCC International’s third‑party cyber risk management processes, streamlining processes as the vendor landscape grows. You will partner with internal teams such as Procurement and Legal to prioritise risk, remediate issues and deliver clear management information on cyber risk across the third‑party portfolio.

Key Responsibilities
  • Own, manage, and evolve the third‑party security due diligence process for TMHCC International vendors, including onboarding and continuous monitoring.
  • Establish and maintain a vendor criticality assessment process; ensure the appropriate vendor due diligence and monitoring activities take place in accordance with vendor criticality.
  • Own and maintain ongoing due diligence requirements for critical and high‑risk suppliers in line with regulatory expectations, including DORA, NIS2, PRA and FCA requirements etc.
  • Build MI and dashboards to showcase security due diligence and third‑party risk management efforts for senior IT stakeholders and executives.
  • Collaborate with IT, Procurement, and Legal teams to embed third party security risk management controls into the overall vendor risk management process.
  • Ensure compliance with relevant industry regulations and standards (e.g., DORA, NIS2, CIS Controls, NIST, GDPR).
  • Provide security guidance on third party due diligence, contract reviews, and other ad‑hoc vendor security risk management queries.
  • Create and maintain vendor security risk management documentation (including process documentation) and training materials.
  • Stay current on emerging vendor security trends, tools, and technologies.
  • Support the Cyber Governance Manager by providing metrics to the Divisional IT Risk Reporting and Dashboards.
  • Escalate significant cyber risks and issues as they emerge to the Cyber Governance Manager and BISO for action or information.
Performance Objectives
  • Develop a strong understanding of TMHCC’s third‑party landscape and current organisational controls used within the vendor risk management process and take on responsibility for cyber third‑party risk management.
  • Identify gaps and improvement areas within the cyber third‑party risk processes, develop plans to further mature cyber security controls within this area, and own the implementation of these plans going forward.
Essential Skills and Experience
  • Experience in cyber/information security risk roles with a focus on third‑party/vendor risk management.
  • Bachelor’s degree in information security, Technology Risk Management or a related field.
  • Relevant professional certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Lead Auditor.
  • Experience in regulated industries, implementing relevant regulations and expectations for third‑party security risk management.
  • Proven experience designing, running, and improving vendor security due diligence processes.
  • Strong knowledge of security assurance certifications and assessments maintained by vendors (e.g., ISO 27001, SOC 2, CSA STAR/CAIQ, vendor security questionnaires).
  • Deep understanding of and ability to articulate the risk associated with vendor risk posture to both technical and non‑technical stakeholders.
  • Ability to coordinate and chair regular meetings and workshops with multiple stakeholders to provide guidance, collaboration and oversight of third‑party security risk management initiatives.
  • Confidence in presenting information and acting as a source of SME knowledge and guidance.
  • Analytical, conceptual thinking, planning and execution skills.
  • Ability to drive improvements and take charge of initiatives, backed with excellent coordination strength as well as assertiveness.
  • Results‑oriented and able to manage to measurable targets and desired outcomes.
  • A passion to champion a cyber security culture and continuous learning of latest cyber threat trends.
  • Strong communication skills with the ability to explain complex security issues to non‑technical stakeholders.
Desirable Qualifications
  • Experience with third party risk management platforms or GRC tooling.
  • Capability and experience in building actionable MI and dashboards (e.g., using Power BI) and turning data into clear decisions and narratives.
  • Experience of the Specialty and Lloyd’s/Companies market insurance industry.
What We Offer

The Tokio Marine HCC Group of Companies offers a competitive salary and employee benefit package. We are a successful, dynamic organization experiencing rapid growth and are seeking energetic and confident individuals to join our team of professionals.

EEO Statement

The Tokio Marine HCC Group of companies is an equal opportunity employer. Please visit www.tmhcc.com for more information about our companies.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Third Party Cyber Risk Lead
Third Party Cyber Risk Lead

Tokio Marine HCC • Greater London

On-site
GBP 70,000 - 90,000
Competitive salary
Employee benefit package
Opportunities for professional growth
Vendor Cyber Risk Lead — Third-Party Security
Vendor Cyber Risk Lead — Third-Party Security

Tokio Marine HCC • Greater London

On-site
GBP 70,000 - 90,000
Competitive salary
Employee benefit package
Opportunities for professional growth
Cyber Risk Lead
Cyber Risk Lead

CPS Group (UK) Limited • Greater London

Hybrid
GBP 81,000 - 99,000
Strategic Third-Party Cyber Risk Lead
Strategic Third-Party Cyber Risk Lead

Tokio Marine HCC International • Greater London

On-site
GBP 60,000 - 80,000
Competitive salary
Employee benefit package
Dynamic growth environment
Senior Cyber Development Underwriter - UK SME
Senior Cyber Development Underwriter - UK SME

Tokio Marine HCC International • Manchester

On-site
GBP 70,000 - 110,000
Cyber Security Consultant
Cyber Security Consultant

Tokio Marine Kiln group • Greater London

Hybrid
GBP 60,000 - 90,000
Cyber Security Consultant
Cyber Security Consultant

Tokio Marine Kiln • Greater London

On-site
GBP 70,000 - 110,000
Cyber Security Consultant
Cyber Security Consultant

Tokio Marine Kiln • City Of London

On-site
GBP 70,000 - 110,000
Senior Financial Crime Officer
Senior Financial Crime Officer

Tokio Marine HCC International • Greater London

Hybrid
GBP 90,000 - 120,000
Senior Financial Crime Officer
Senior Financial Crime Officer

Tokio Marine HCC • Greater London

On-site
GBP 70,000 - 110,000