Third Party Security Due Diligence Lead

swift

Greater London

On-site

GBP 90,000 - 120,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

SWIFT is seeking a Lead for the Third-Party Security Due Diligence function to ensure that suppliers, cloud services, and strategic partners are assessed, onboarded, and monitored in line with security and regulatory requirements.

The role manages end-to-end due diligence lifecycle, provides risk-based assessments, drives remediation, and supports compliance with frameworks including ISO 27001, NIST, DORA, NIS2, and GDPR.

Qualifications

  • Bachelor's degree in Information Security, Cybersecurity, Computer Science, Risk Management, Information Systems, or related field.
  • 7+ years' experience in cybersecurity, third-party security risk management, supplier assurance, or technology risk in regulated environments.
  • Strong understanding of third-party security risk management practices and supplier assurance methodologies.

Responsibilities

  • Lead end-to-end third-party security due diligence, onboarding, reassessment and offboarding.
  • Perform security risk assessments of third parties including cloud, data protection, and supply chain risks.
  • Advise stakeholders on risk, controls, and remediation; report to governance forums and risk committees.

Skills

Security risk management
Supplier assurance
Stakeholder management
Regulatory compliance

Education

Bachelor's degree in Information Security or related field

Job description

ABOUT US

We're the world's leading provider of secure financial messaging services, headquartered in Belgium. We are the way the world moves value - across borders, through cities and overseas. No other organisation can address the scale, precision, pace and trust that this demands, and we're proud to support the global economy.

We're unique too. We were established to find a better way for the global financial community to move value - a reliable, safe and secure approach that the community can trust, completely. We're always striving to be better and are constantly evolving in an ever-changing landscape, without undermining that trust. Five decades on, our vibrant community reflects the complexity and diversity of the financial ecosystem. We innovate diligently, test exhaustively, then implement fast. In a connected and exciting era, our mission has never been more relevant. Swift now has a presence in 200+ countries and legal territories to serve a community of more than 12,000 banks and financial institutions.

Job Summary

Lead the Third-Party Security Due Diligence function for SWIFT, ensuring that third-party suppliers, technology providers, cloud services, and strategic partners are assessed, onboarded, and monitored in line with SWIFT's security, resilience, regulatory, and operational risk requirements.The role is responsible for managing the end-to-end security due diligence lifecycle, providing expert risk-based assessments of third parties, driving remediation activities, and supporting compliance with applicable regulatory frameworks including DORA, NIS2, ISO 27001, and SWIFT's internal security standards.

Key Responsibilities
  • Security Due Diligence & Risk Assessment

    Lead the end-to-end third-party security due diligence process, from supplier onboarding through ongoing assurance, reassessment, and offboarding.

    Perform comprehensive security risk assessments of third parties, evaluating cybersecurity, resilience, data protection, cloud security, supply chain security, and operational risk exposures.

    Assess supplier security capabilities through review of questionnaires, policies, certifications, audit reports, penetration testing results, independent assurance reports, and supporting evidence.

    Evaluate control effectiveness against recognised frameworks and standards including ISO 27001, NIST Cybersecurity Framework, SOC reports, DORA, and relevant SWIFT security requirements.

    Identify security gaps, residual risks, and compensating controls, providing clear risk ratings and recommendations to stakeholders.

  • Supplier Assurance & Continuous Monitoring

    Establish and maintain a risk-based supplier assurance programme for critical and high-risk third parties.

    Drive remediation activities with suppliers and internal stakeholders to address identified security weaknesses and control deficiencies.

    Support ongoing monitoring activities, including reassessments, threat monitoring, breach notifications, security events, and changes in supplier risk profiles.

    Monitor supplier compliance with contractual security obligations and regulatory requirements.

  • Stakeholder Management & Advisory

    Partner closely with Procurement, Legal, Technology, Architecture, Operational Risk, Compliance, Data Protection, and Business teams to support supplier onboarding and risk decisions.

    Provide expert guidance on third-party security risks, risk acceptance decisions, mitigating controls, and supplier onboarding requirements.

    Present security due diligence outcomes, key risks, and recommendations to governance forums, senior management, and risk committees.

    Act as the subject matter expert for third-party security risk management and supplier assurance activities across the organisation.

  • Governance & Regulatory Compliance

    Contribute to the development and continuous improvement of SWIFT's Third-Party Security Risk Management and Supplier Assurance frameworks, methodologies, standards, and procedures.

    Ensure due diligence activities align with regulatory expectations and industry best practices, including DORA, NIS2, GDPR, EBA Guidelines, and relevant financial sector requirements.

    Support internal audits, regulatory reviews, and external examinations relating to third-party security risk management.

    Develop management reporting, KPIs, KRIs, and board-level metrics to demonstrate programme effectiveness and risk exposure.

Qualifications & Experience
Essential
  • Bachelor's degree in Information Security, Cybersecurity, Computer Science, Risk Management, Information Systems, or a related discipline.
  • Minimum 7 years' experience in cybersecurity, third-party security risk management, supplier assurance, security assurance, or technology risk within financial services, critical infrastructure, or a highly regulated environment.
  • Strong understanding of third-party security risk management practices and supplier assurance methodologies.
  • Practical experience conducting security assessments of cloud providers, SaaS vendors, technology s
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Third Party Security Due Diligence Lead
Third Party Security Due Diligence Lead

Swift • City of Westminster

On-site
GBP 90,000 - 130,000
Third Party Security Due Diligence Lead
Third Party Security Due Diligence Lead

Swift Software • Greater London

On-site
GBP 90,000 - 130,000
Third-Party Security Risk & Due Diligence Lead
Third-Party Security Risk & Due Diligence Lead

Swift • City of Westminster

On-site
GBP 90,000 - 130,000
Senior Third-Party Security Risk Lead
Senior Third-Party Security Risk Lead

Swift Software • Greater London

On-site
GBP 90,000 - 130,000
Global Third-Party Security Due Diligence Lead
Global Third-Party Security Due Diligence Lead

swift • Greater London

On-site
GBP 90,000 - 120,000
Interim Third Party Security Risk Manager
Interim Third Party Security Risk Manager

La Fosse • Greater London

Hybrid
GBP 70,000 - 90,000
Consultant - Third Party Risk
Consultant - Third Party Risk

MCS Group | Your Specialist Recruitment Consultancy • Belfast

On-site
GBP 45,000 - 65,000
Assessments & Exercises Director - Third Party Assurance
Assessments & Exercises Director - Third Party Assurance

JPMorgan Chase & Co. • Bournemouth

On-site
GBP 120,000 - 190,000
Third Party Risk Analyst
Third Party Risk Analyst

domesticandgeneral • Wimbledon

Hybrid
GBP 45,000 - 60,000
Supplier Risk Lead
Supplier Risk Lead

Ford Credit • Dunton

On-site
GBP 70,000 - 110,000