> Markdown version of [/jobs/ext/3314225-information-security-third-party-assurance-analyst](https://www.wearedevelopers.com/jobs/ext/3314225-information-security-third-party-assurance-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Third Party Assurance Analyst - **Company:** Centrica - **Location:** Windsor, UK - **Contract:** Permanent contract - **Skills:** Cyber Security, Servicenow - **Published:** September 2, 2026 - **Apply:** https://www.totaljobs.com/job/third-party-analyst/centrica-chp-job107933778 ## About the Role * Experience in Information Security, Cyber Security, Risk, Compliance or Assurance, with a good understanding of how to balance strong controls with practical business needs. * Hands-on experience conducting supplier, vendor or third-party security assessments, including reviewing documentation, assurance reports and control evidence. * A solid understanding of information security frameworks and standards such as ISO 27001, NIST, Cyber Essentials and SOC reporting. * Strong analytical, organisational and problem-solving skills, with the ability to spot risks, join the dots and keep assurance activity moving in the right direction. * Confident communication skills, with the ability to explain technical and risk-based information clearly to both technical and non-technical audiences. * Experience using Governance, Risk and Compliance platforms such as Risk Ledger, Workiva, ServiceNow or similar tools, with strong stakeholder management skills and experience supporting contract reviews or supplier onboarding being a real bonus. ## Description * Operate the third-party security assessment process for procurement and business requests, making supplier assurance clear, consistent and easy to navigate. * Conduct supplier due diligence assessments by reviewing supplier responses, evidence, assurance reports and supporting documentation against Centrica's information security, privacy, risk and contractual requirements. * Identify, assess and document third-party security, privacy and technology risks, including control gaps, deviations, concessions and remediation actions. * Support supplier onboarding, reassessment and ongoing assurance activity across the supplier lifecycle, with a focus on critical and high-risk suppliers and a strong eye on emerging cyber threats and good practice. * Produce clear, evidence-based risk assessments, reports and recommendations that support business owners, governance forums and risk-based decision making. * Build strong relationships with Procurement, Legal, Privacy, Information Security, Technology GRC, Service Owners, Project Delivery Teams and suppliers, while helping improve assurance processes, documentation and standards.