Enable job alerts via email!
A leading renewable energy company is seeking a Third-Party Cyber Risk Manager to protect against cyber threats in the supply chain. This pivotal role involves risk assessment, compliance with NIS regulations, and team leadership. Candidates should have expertise in cyber governance and frameworks like NIST and ISO. The position offers a competitive salary, hybrid working, and comprehensive benefits designed for employee wellbeing.
Third Party Cyber Risk Manager page is loaded
Apply locations: United Kingdom, Glasgow | Posted 3 Days Ago | End Date: August 9, 2025 (11 days left to apply) | Job Requisition ID: R-20238
Third-Party Cyber Risk Manager
Location: Glasgow
Salary: £57-72K (plus up to 15% bonus and single healthcare cover)
Permanent, Hybrid Working
Help us create a better future, quicker
ScottishPower is seeking a dedicated and experienced Third-Party Cyber Risk Manager to join our dynamic global cyber security team. This pivotal role involves protecting our organization from cyber threats originating within our supply chain. You will be responsible for identifying, assessing, and mitigating third-party cyber risks, ensuring the integrity, confidentiality, and availability of our operations.
What you’ll be doing
As the owner of third-party cyber risk processes across SP Corporate, you’ll ensure full implementation of Iberdrola and ScottishPower methodologies. You’ll play a key role in our security transformation program, which is underway and set to deliver through 2027—driving compliance with NIS regulations and building a cyber-resilient business.
This is a leadership role with line management responsibility for a Third-Party Cyber Risk Analyst. You’ll guide and develop your team while collaborating with internal and external stakeholders, including legal, IT, and global cyber teams, to embed best practices and deliver strategic security solutions.
What you’ll bring
You’ll bring deep expertise in cyber governance and supply chain security, with a strong grasp of frameworks like NIST SP 800-161, ISO/IEC 27036, and ISO 28000. Your ability to interpret legal clauses, manage risk governance, and communicate effectively with both technical and non-technical audiences will be key to your success.
If you’re passionate about cyber security, thrive in a collaborative environment, and are ready to make a tangible impact on the resilience of critical infrastructure, we’d love to hear from you.
What’s in it for you
Enjoy a competitive salary reviewed annually, along with a range of benefits including a pension scheme with up to 10% company contribution, 36 days annual leave, holiday purchase options, share schemes, payroll giving, technology vouchers, and more. Our benefits are designed to support your wellbeing, work-life balance, and personal development.
Why ScottishPower
Part of the Iberdrola Group, ScottishPower is committed to renewable energy and sustainability. We invest over £6m daily to achieve Net Zero, offering diverse career opportunities within a global organization that values inclusion, diversity, and social purpose.
We support candidates with disabilities or special requirements during our recruitment process. For assistance, contact careers@scottishpower.com.
Mobility
Applicants must meet immigration requirements to work legally in the UK. We support necessary immigration processes where applicable.
Important
The advert closes at 23:59 GMT the day before the Job Posting End Date of August 9, 2025.
Iberdrola is a global leader in renewable energy, operating in multiple countries with a workforce of over 35,000. We focus on sustainable energy solutions, smart grids, large-scale storage, and digital transformation, leading the transition to a low-carbon future.