Job type
- Full-time
Job description
Contract
6 months (inside IR35)
Rate
Up to £550/day
Role overview
Client is seeking an experienced cyber risk professional to design and implement their cyber risk management strategy with a strong focus on third‑party/supply chain risk. You’ll stand up repeatable processes, select and configure tooling (Risk Ledger and similar), and embed NIST 800‑161-aligned controls across the supplier lifecycle.
Key responsibilities
- Design and implement a pragmatic cyber risk management strategy and operating model.
- Lead third‑party cyber risk management (TPRM): supplier onboarding, due diligence, risk scoring, continuous monitoring, and remediation tracking
- Map and embed NIST SP 800‑161 (C‑SCRM) guidance into policies, controls, and assessments across organisational tiers.
- Select, configure and roll out TPRM tooling (e.g., Risk Ledger; “Bitsight”-style external rating/monitoring tools) and maintain the risk register/ledger.
- Develop procedures/runbooks for risk assessments, exception handling, and incident escalation related to suppliers.
- Produce clear reporting for senior stakeholders on supply chain risk posture, concentrations, and nth‑party dependencies.
- Proven track record designing/implementing cyber risk and TPRM programmes.
- Hands‑on experience applying NIST 800‑161 (or equivalent C‑SCRM/TPRM frameworks).
- Practical experience with TPRM platforms (Risk Ledger or similar) and external cyber rating/monitoring tools.
- Experience working in regulated environments (defence, critical national infrastructure, public sector).
- Familiarity with ISO 27001, Cyber Essentials, and supplier assurance workflows.
- Active SC clearance (must be current and verifiable).
Commercials
- Inside IR35, up to £550/day.
- 6-month initial term, onsite in South Wales.
#J-18808-Ljbffr