Third Party Risk Manager

Tesco Insurance and Money Services

Reigate

Hybrid

GBP 72,000 - 87,000

Full time

9 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Pension scheme
Virtual GP Service
Annual bonus
Generous holiday allowance (7.2 weeks)
Colleague Clubcard discounts
Family leave benefits
Learning opportunities and training
Buy as you Earn/Save as you Earn share

Job summary

Tesco Insurance and Money Services seeks a Third Party Risk Manager – Cyber to lead the design and operation of our cyber risk management with suppliers and partners. You will ensure risks are identified, assessed, treated and monitored in line with enterprise risk appetite and regulatory expectations.

You will provide guidance to GRC teams, support audits, and collaborate with Procurement, Legal, and Tech to drive pragmatic risk decisions. Hybrid working with travel to offices as needed.

Qualifications

  • Third‑party cyber risk expertise with ownership of risk processes.
  • Deep knowledge of supplier cyber risk and assurance models.
  • Experience supporting internal and external audits and regulatory reviews.
  • Ability to articulate and score supplier cyber risks against risk appetite.
  • Certifications such as CISSP/CISM/CRISC/CISA or ISO 27001 related preferred.

Responsibilities

  • Own and evolve the cyber third‑party risk management framework.
  • Lead risk assessments of suppliers, partners and third‑parties.
  • Oversee supplier assurance activity including questionnaires and onsite assessments.
  • Ensure risks are articulated, scored, and recorded with treatment plans.
  • Coordinate remediation tracking through to closure.
  • Act as primary contact for cyber third‑party risk during audits and reviews.
  • Collaborate with Procurement, Legal, Technology and Data Protection teams.
  • Provide clear reporting on risk posture and trends.
  • Coach GRC Managers and Analysts to build capability.

Skills

Cyber risk management
Supplier assurance
GRC
Stakeholder management
Regulatory knowledge
Audit support
Risk appetite
CISSP/CISM/CRISC/CISA
ISO 27001 lead implementer/auditor

Job description

About the role

Serving our customers, communities, and planet a little better every day.

Serving our customers, communities, and planet a little better every day.

Salary

Between £72,200 - £86,640 + annual bonus & benefits

Work Level

WL2

Location

Edinburgh, Reigate, Glasgow, Newcastle.

Office Attendance

Our roles are hybrid; however, you should be able to travel to our office, 1-3 days per week for this position.

Closing Date

Applications close 5th October at 5pm

Position

Third Party Risk Manager – Cyber

Reporting to the Lead GRC Manager, you’ll lead the design, operation and continuous improvement of our third‑party cyber risk management capability. You’ll ensure that cyber risks introduced through suppliers, partners and third‑parties are identified, assessed, treated and monitored in line with enterprise risk appetite, regulatory expectations and industry best practice.

You’ll play a critical role as a subject matter expert for cyber third‑party risk, providing clear direction, pragmatic risk decisions and senior‑level assurance that supplier cyber risks are being effectively managed.

What you’ll be doing
  • Own and evolve the cyber third‑party risk management framework, processes and standards, ensuring alignment with the wider enterprise GRC framework, procurement processes and supplier lifecycle.
  • Lead cyber risk assessments of suppliers, partners and third‑parties, including high‑risk and critical suppliers.
  • Oversee supplier assurance activity, including questionnaires, evidence reviews, attestations and onsite or remote assessments.
  • Ensure cyber risks are clearly articulated, scored and recorded consistently, with appropriate treatment plans in place.
  • Validate supplier remediation plans and track progress through to closure.
  • Act as the primary point of contact for cyber third‑party risk during internal audit, external audit and regulatory reviews.
  • Apply enterprise risk appetite when reviewing and approving supplier cyber risks, escalating unmanaged or unacceptable risks through the appropriate governance forums.
  • Partner closely with Procurement, Legal, Technology, Data Protection and Business teams to drive proportionate and pragmatic risk treatment decisions.
  • Produce clear reporting on supplier cyber risk posture, trends and systemic issues, contributing to enterprise‑level cyber and GRC reporting.
  • Provide specialist guidance and coaching to GRC Managers, Analysts and wider teams, helping to build capability across the function.
We need you to have (minimum experience)
  • Third‑party cyber risk expertise; significant experience in cyber security, third‑party risk management, supplier assurance or GRC. Demonstrate ownership of third‑party cyber risk processes and outcomes.
  • Deep knowledge of supplier cyber risk and assurance models, including proportionate, risk‑based assessment approaches.
  • Cyber risk assessment and assurance. Strong understanding of cyber threats, controls and assurance evidence.
  • Experience leading supplier assessments and reviewing assurance evidence for high‑risk or critical suppliers.
  • Ability to articulate, score and manage supplier cyber risks in line with agreed risk appetite.
  • Stakeholder Management and influence. Experience working closely with Procurement, Legal, Technology, Data Protection and Business teams.
  • Ability to influence senior stakeholders and suppliers without direct authority.
  • Confidence to constructively challenge suppliers and internal teams where cyber risks are not being managed effectively.
  • Regulatory & assurance knowledge. Experience supporting internal audit, external audit and regulatory reviews. Strong understanding of supplier assurance in a large, complex or regulated environment.
  • Ability to provide defensible assurance that supplier cyber risks are understood and managed within risk appetite.
  • Certifications: CISSP, CISM, CRISC, CISA; ISO 27001 Lead Implementer or Lead Auditor; third‑party risk or supplier assurance certifications would also be beneficial.
What’s in it for you
  • Prepare for your retirement with our colleague pension scheme.
  • Virtual GP Service for you and your family 365 days a year.
  • Performance related annual bonus.
  • Indulge in a generous holiday allowance with a minimum of 7.2 weeks, with the opportunity to buy more.
  • Embrace the benefits of our Colleague Clubcard, enjoy a 10% discount that increase to 15% every payday. As an added perk, we’ll give you a second card to share with someone else.
  • Benefit from our family‑oriented initiatives, encompassing enhanced maternity leave pay, a shared parental leave policy, and a generous 8‑week paid paternity leave.
  • A place to get on – take advantage of our ongoing learning opportunities and award‑winning training, to help you achieve the job and career you want.
  • Take part in our Buy as you Earn and Save as you Earn share schemes.
Everyone’s welcome

We want all our colleagues to always feel welcome and be themselves. We’re committed to building a more inclusive workplace and celebrating everything that makes colleagues unique, and value the richness and diversity this brings to our business. A more diverse business helps us deliver on our purpose to serve our customers, communities, and planet a little better every day.

Interviews

We also know the importance of balancing work with life’s other commitments. Please talk to us at interview about the flexibility you need, as we’re committed to exploring part‑time and flexible working opportunities, at every level of the organisation.

Interviews are expected to be held shortly after closing date.

Why Tesco Insurance and Money Services?

Seeing your impact all around you: there's no better feeling.

Lucky for us, we get to feel it all the time. Because whatever our role, we're helping our colleagues and serving our customers, communities and planet a little better every day.

We deal in the personal – from pet insurance for your best friend, and home insurance for peace of mind, to motor insurance for your dream car or travel money for that trip you’ve worked hard for.

Everything we do is about making things better. Not just for others, but for you too. It's why you'll get bags of choice and plenty of development. It's why you'll always be heard and find balance that works for you. It's why you'll feel totally at home in a place where everyone's welcome.

So, if you want a career where you can do good and feel good, you've found it.

Let's make everyday a little better.

Our story

Making Insurance and Money Services more rewarding and offering great value and choice - because we know little wins can make a big difference.

We began life in 1997 and now help more than 2 million customers protect what matters to them.

We want to deliver a helpful service in everything we do and to make life easier for our customers. Our policies are really easy to manage online for our customers, but we know that being able to speak to our customer service staff when you need to is really important. This is why our customer service centers are open seven days a week.

Delivering great customer service means having great people behind the scenes – people who understand our customers and are driven by doing the right thing for them. We offer colleagues a place where they can feel totally at home in a place where everyone's welcome, where they can be part of a great team focused on making a real difference for our customers.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Third Party Risk Manager
Third Party Risk Manager

Tesco • Reigate

On-site
GBP 72,200 - 86,640
Annual bonus
Hybrid working
Pension scheme
+1
Supplier Risk Analyst
Supplier Risk Analyst

Tesco PLC. • Newcastle upon Tyne

On-site
GBP 30,000 - 36,000
Annual bonus
Hybrid working
Generous pension (up to 7.5% employer)
+2
Risk Manager
Risk Manager

Tesco PLC. • Reigate

On-site
GBP 63,000 - 77,000
Generous pension up to 7.5%
Private Medical Insurance
Annual bonus
+5
Technical Underwriting Analyst
Technical Underwriting Analyst

Tesco Insurance • Reigate

Hybrid
GBP 30,000 - 37,000
Pension scheme (up to 7.5% employer)
Virtual GP Service
Performance related annual bonus
+5
Systems Engineer
Systems Engineer

Tesco Insurance • City of Edinburgh

On-site
GBP 38,000 - 52,000
Pension (up to 7.5% employer)
Virtual GP Service
Annual bonus potential
+5
Technical Underwriting Analyst
Technical Underwriting Analyst

Tesco Insurance • Reigate and Banstead

Hybrid
GBP 30,000 - 36,000
Pension scheme (up to 7.5% employer)
Virtual GP service
Annual bonus
+4
Engineering Lead
Engineering Lead

Tesco Insurance and Money Services • City of Edinburgh

Hybrid
GBP 81,000 - 99,000
Pension up to 7.5% employer
Private Medical Insurance
Annual bonus
+5
Data Engineer - Protect (South)
Data Engineer - Protect (South)

Tesco Insurance • Reigate

On-site
GBP 30,000 - 36,000
Pension 7.5%+
Private Medical Insurance
Annual bonus
+5
Software Engineer
Software Engineer

Tesco Insurance and Money Services • City of Edinburgh

Hybrid
GBP 51,000 - 63,000
Pension scheme
Bonus opportunities
Hybrid work model
+1
Data Engineer - Protect (South)
Data Engineer - Protect (South)

Tesco Insurance and Money Services • Reigate

Hybrid
GBP 30,000 - 36,000
Annual bonus
Private medical insurance
Pension plan
+5