707,628open jobs
41,965companies
100,608added this week
Browse all
Salary
$97k – $116k per year
Location
Remote/Hybrid (Edinburgh, United Kingdom)
Overview
Company
Impact
Profile match
Tesco is a leading British multinational retailer that stands as the largest grocery store chain in the United Kingdom. Headquartered in Welwyn Garden City, England, the company operates thousands of supermarkets, convenience stores, and a major e-commerce platform. It offers a wide variety of products ranging from fresh food and clothing to household items and financial services.

About the role

Serving our customers, communities, and planet a little better every day.

Salary - Between £72,200 - £86,640 + annual bonus & benefits

Work Level - WL2

Location - Edinburgh, Reigate, Glasgow, Newcastle. Permanent.

Office Attendance - Our roles are hybrid; however, you should be able to travel to our office, 1-3 days per week for this position.

Closing Date - Applications close 5th October at 5pm

We’re looking for a Third Party Risk Manager - Cyber to join our Insurance, Money & Services team.

Reporting to the Lead GRC Manager, you’ll lead the design, operation and continuous improvement of our third-party cyber risk management capability. You’ll ensure that cyber risks introduced through suppliers, partners and third parties are identified, assessed, treated and monitored in line with enterprise risk appetite, regulatory expectations and industry best practice.

You’ll play a critical role as a subject matter expert for cyber third-party risk, providing clear direction, pragmatic risk decisions and senior-level assurance that supplier cyber risks are being effectively managed.

What you’ll be doing

  • Own and evolve the cyber third-party risk management framework, processes and standards, ensuring alignment with the wider enterprise GRC framework, procurement processes and supplier lifecycle.
  • Lead cyber risk assessments of suppliers, partners and third parties, including high-risk and critical suppliers.
  • Oversee supplier assurance activity, including questionnaires, evidence reviews, attestations and onsite or remote assessments.
  • Ensure cyber risks are clearly articulated, scored and recorded consistently, with appropriate treatment plans in place.
  • Validate supplier remediation plans and track progress through to closure.
  • Act as the primary point of contact for cyber third-party risk during internal audit, external audit and regulatory reviews.
  • Apply enterprise risk appetite when reviewing and approving supplier cyber risks, escalating unmanaged or unacceptable risks through the appropriate governance forums.
  • Partner closely with Procurement, Legal, Technology, Data Protection and Business teams to drive proportionate and pragmatic risk treatment decisions.
  • Produce clear reporting on supplier cyber risk posture, trends and systemic issues, contributing to enterprise-level cyber and GRC reporting.
  • Provide specialist guidance and coaching to GRC Managers, Analysts and wider teams, helping to build capability across the function.

We need you to have (minimum experience)

  • Third-party cyber risk expertise

o Significant experience in cyber security, third-party risk management, supplier assurance or GRC.

o Demonstrate ownership of third-party cyber risk processes and outcomes.

o Deep knowledge of supplier cyber risk and assurance models, including proportionate, risk-based assessment approaches.

  • Cyber risk assessment and assurance

o Strong understanding of cyber threats, controls and assurance evidence.

o Experience leading supplier assessments and reviewing assurance evidence for high-risk or critical suppliers.

o Ability to articulate, score and manage supplier cyber risks in line with agreed risk appetite.

  • Stakeholder Management and influence

o Experience working closely with Procurement, Legal, Technology, Data Protection and Business teams.

o Ability to influence senior stakeholders and suppliers without direct authority.

o Confidence to constructively challenge suppliers and internal teams where cyber risks are not being managed effectively.

  • Regulatory & assurance knowledge

o Experience supporting internal audit, external audit and regulatory reviews.

o Strong understanding of supplier assurance in a large, complex or regulated environment.

o Ability to provide defensible assurance that supplier cyber risks are understood and managed within risk appetite.

  • Certifications

o CISSP, CISM, CRISC, CISA

o ISO 27001 Lead Implementer or Lead Auditor

o Third-party risk or supplier assurance certifications would also be beneficial

We don’t expect you to tick every box, and if you feel you hit most of the brief, it’s worth exploring to further develop your career here with us.

What’s in it for you

  • Prepare for your retirement with our colleague pension scheme.
  • Virtual GP Service for you and your family 365 days a year.
  • Performance related annual bonus.
  • Indulge in a generous holiday allowance with a minimum of 7.2 weeks, with the opportunity to buy more.
  • Embrace the benefits of our Colleague Clubcard, enjoy a 10% discount that increase to 15% every payday. As an added perk, we’ll give you a second card to share with someone else.
  • Benefit from our family-oriented initiatives, encompassing enhanced maternity leave pay, a shared parental leave policy, and a generous 8-week paid paternity leave.
  • A place to get on - take advantage of our ongoing learning opportunities and award-winning training, to help you achieve the job and career you want.
  • Take part in our Buy as you Earn and Save as your Earn share schemes.

Everyone’s welcome

We want all our colleagues to always feel welcome and be themselves. We’re committed to building a more inclusive workplace and celebrating everything that makes colleagues unique, and value the richness and diversity this brings to our business. A more diverse business helps us deliver on our purpose to serve our customers, communities, and planet a little better every day.

Interviews

We also know the importance of balancing work with life’s other commitments. Please talk to us at interview about the flexibility you need, as we’re committed to exploring part time and flexible working opportunities, at every level of the organisation.

Interviews are expected to be held shortly after closing date.

Why Tesco Insurance and Money Services?

Seeing your impact all around you: there's no better feeling.

Lucky for us, we get to feel it all the time. Because whatever our role, we're helping our colleagues and serving our customers, communities and planet a little better every day.

We deal in the personal - from pet insurance for your best friend, and home insurance for peace of mind, to motor insurance for your dream car or travel money for that trip you’ve worked hard for.

Everything we do is about making things better. Not just for others, but for you too. It's why you'll get bags of choice and plenty of development. It's why you'll always be heard and find balance that works for you. It's why you'll feel totally at home in a place where everyone's welcome.

So, if you want a career where you can do good and feel good, you've found it.

Let's make everyday a little better.

Our story

Making Insurance and Money Services more rewarding and offering great value and choice - because we know little wins can make a big difference.

We began life in 1997 and now help more than 2 million customers protect what matters to them.

We want to deliver a helpful service in everything we do and to make life easier for our customers. Our policies are really easy to manage online for our customers, but we know that being able to speak to our customer service staff when you need to is really important. This is why our customer service centers are open seven days a week.

Delivering great customer service means having great people behind the scenes - people who understand our customers and are driven by doing the right thing for them. We offer colleagues a place where they can feel totally at home in a place where everyone's welcome, where they can be part of a great team focused on making a real difference for our customers.

How to apply

We value our people and diverse teams and believe the variety of backgrounds and experiences make us stronger to achieve our goals.

Our colleagues are working hybrid, taking time to meet with colleagues in our offices for moments that matter, such as team catch ups, planning meetings and more. If you’re interested in finding out more about what a career at Tesco Insurance and Money Services looks like, click apply to find out more!

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
707,628 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Edinburgh
$37k – $89k per year (Estimated) • In office • Full-Time • Bengaluru
Python
PowerShell
Bash
DevOps
GCP
Azure
AWS
IAM
Linux
Windows
TCP/IP
DNS
DHCP
VPN
Wi-Fi
Cybersecurity
Okta
ISO 27001
SOC 2
Microsoft Entra ID
Active Directory
Management
Google Workspace
Apply
$33k – $86k per year (Estimated) • In office • 8+ years exp • Bengaluru
DevOps
Incident Management
VPN
Cybersecurity
ISO 27001
SOC 2
Zero Trust
Least Privilege
Active Directory
SIEM
DLP
Apply
$100k – $113k per year • Remote • 7+ years exp • Bachelor's Degree
Python
DevOps
Terraform
IAM
Cybersecurity
ISO 27001
CIS Benchmarks
PCI DSS
SOC 2
HIPAA
Zero Trust
SIEM
Apply
$100k – $170k per year • Remote • 12+ years exp • Bachelor's Degree
Python
DevOps
Terraform
IAM
Cybersecurity
ISO 27001
CIS Benchmarks
PCI DSS
SOC 2
HIPAA
Zero Trust
SIEM
Apply
$53k – $121k per year (Estimated) • Remote/Hybrid • 12+ years exp • Bachelor's Degree
DevOps
CI/CD
Cloudflare
DNS
Cybersecurity
ISO 27001
Zero Trust
Apply
In office
Apply
In office • 2+ years exp • Bachelor's Degree
Apply
In office
Apply
Governance Assistant 7 hours ago
$48k – $51k per year • Remote/Hybrid • Confidential • Full-Time • Edinburgh
Management
SharePoint
Agile
Microsoft Office
Apply
$34k per year • In office • Part-Time • Edinburgh
Apply
$121k – $227k per year (Estimated) • Remote/Hybrid • Full-Time • Master's Degree • Edinburgh
Apply
Driver 1 day ago
$42k per year • In office • Full-Time • Bachelor's Degree • Dundee • Edinburgh
Apply
$63k – $146k per year (Estimated) • Remote/Hybrid • Full-Time • Edinburgh
DevOps
Terraform
Ansible
GCP
Azure
CI/CD
AWS
BGP
OSPF
Cybersecurity
FortiGate
Apply
See all jobs
This is one of many
707,628 more open roles from verified company boards, updated every day.