Cyber Risk Lead

CPS Group
UK
12 days ago
Apply on careers.cpsgroupuk.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
£90,000.0
Working hours
Regular working hours

Tech stack

Cyber Security Power BI

Job description

This is a great opportunity for an experienced Cyber Security / Third-Party Risk professional to take ownership of a growing vendor risk function and work closely with IT, Procurement, Legal and senior stakeholders., * Own and continuously improve the third-party cyber risk and security due diligence process.

  • Lead vendor criticality assessments and ensure appropriate due diligence and ongoing monitoring.
  • Manage cyber risk requirements for critical and high-risk suppliers.
  • Ensure compliance with regulations including DORA, NIS2, PRA, FCA and GDPR.
  • Develop MI, dashboards and reporting for senior IT stakeholders and executives.
  • Provide cyber security guidance across vendor assessments, contracts and risk management.
  • Identify gaps and drive improvements across third-party cyber risk processes.

Requirements

  • Proven experience in Cyber Security / Information Security Risk, with a focus on third-party or vendor risk.
  • Strong experience designing, managing and improving vendor security due diligence processes.
  • Knowledge of vendor security assessments (ideally CSA STAR/CAIQ, SOC 2, and ISO 27001)
  • Experience working within a regulated industry and understanding relevant regulatory requirements.
  • Strong understanding of third-party cyber risk and the ability to communicate risks to both technical and non-technical stakeholders.
  • Experience with GRC / third-party risk management platforms is desirable.
  • Experience producing MI and dashboards, ideally using Power BI, is desirable.
  • Relevant certifications such as CISSP, CISM, CRISC or ISO 27001 are advantageous.

About the company

CPS Group are supporting a global financial services organisation with the recruitment of a Cyber Risk Lead to own and develop their third-party cyber risk management framework.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on careers.cpsgroupuk.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:24 min

Moving the semantic layer upstream to avoid vendor lock-in

Piotr Menclewicz Piotr Menclewicz · Europe 2026 Virtual

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

3:48 min

Standardizing data access schemas with OData

Florian Bader Florian Bader · World Congress 2026 Europe

Videos

See all

Related articles

See all