Oliver James are partnered with a globally renowned reinsurance company in their search for a Cyber Security Governance, Risk & Compliance (GRC) and Third-Party Risk Management (TPRM) Lead. This role will play a crucial part in strengthening the organisation’s security posture, focusing heavily on vendor risk, regulatory readiness, and cyber governance.
Oliver James are partnered with a globally renowned reinsurance company in their search for a Cyber Security Governance, Risk & Compliance (GRC) and Third-Party Risk Management (TPRM) Lead. This role will play a crucial part in strengthening the organisation’s security posture, focusing heavily on vendor risk, regulatory readiness, and cyber governance.
Based in the City of London with a flexible hybrid model (average 4 days on-site), this position carries a package of c£155,000 inclusive of bonus and LTIP and exclusive of exceptional benefits and annual/loyalty bonuses.
Key Responsibilities
Third-Party Risk Management:Lead and own the third-party vendor risk assessment process across a portfolio of 100-120 vendors. Review and validate vendor security documentation (e.g., SOC 2, ISO 27001), evaluate control effectiveness, and coordinate remediation efforts for identified gaps. Ensure relevant business stakeholders are informed of potential risks.
Governance, Risk & Compliance (GRC):Actively contribute to broader GRC initiatives, including:
Security Controls and Collaboration:Research and interpret both technical and non-technical security controls. Collaborate with infrastructure, engineering, and business teams to ensure appropriate control implementation aligned with organisational security goals.
Executive Reporting:Track, prioritise, and report on risk and compliance status, key issues, and mitigation progress to leadership teams.
Key Requirements
Highly Desirable Experience
Certifications (Preferred)