
Deliver two core security assurance functions within the hub: ensure that security requirements are embedded into projects and solutions from inception through to delivery (Security by Design), and manage the end-to-end information security risk assessment lifecycle for hub-scope third-party suppliers (Third Party Risk Management).
Act as the primary operational assurance interface between the hub and the Group GRC function.
Responsibilities:
- Hub-scope third-party supplier population.
- Operates within globally standardised frameworks - Group Security by Design framework and TPRM process - defined by the Group GRC function.
- Follow-the-sun assurance model alongside two peer hub roles (Americas, Asia, Europe).
- Scope covers hub-based projects, initiatives, and supplier relationships across all business segments within the hub geography.
- Maintain consistent security assessment quality across a varied project pipeline - ranging from infrastructure changes to business application deployments - where project teams have differing levels of security maturity.
- Balance thoroughness of TPRM assessment with hub operational pace and procurement timelines.
- Influence project owners, business stakeholders, and vendors to act on security findings without direct authority.
- Manage end-to-end TPRM accountability at hub level while feeding outcomes into the global risk picture owned by HQ GRC.
- Navigate regional regulatory context (data protection, sector-specific obligations) that affects both assessment tracks.
Intake assessment:
- Review projects and initiatives at inception to identify information security requirements, risks, and applicable controls.
- Conduct structured security intake assessments using the Group Security by Design framework; document outputs and agree requirements with project teams.
- Ensure security requirements are formally captured in project scope and tracked as delivery obligations.
Delivery assurance:
- Assess delivered solutions against the agreed security requirements and Group security architecture baseline prior to go-live.
- Document findings, assign risk ratings, and agree remediation or acceptance decisions with the project owner and Hub Security Lead.
- Maintain a hub-level register of Security by Design assessments, findings, and closure status; report into Group GRC on the defined cadence.
Third Party Risk Management:
- Manage the end-to-end TPRM assessment lifecycle for hub-scope suppliers: initial scoping, questionnaire issuance, response review, risk scoring, findings documentation, remediation tracking, and formal sign-off.
- Operate within the global TPRM platform and process framework defined by HQ GRC; maintain data quality and completeness for the hub supplier population.
- Conduct risk-based prioritisation of the hub supplier population to determine assessment frequency and depth.
- Engage hub-based business units and procurement teams to ensure third-party assurance is embedded in sourcing and contract renewal activity.
- Escalate significant supplier risk findings to the Hub Security Lead and Head of GRC; track remediation to closure.
- Contribute hub TPRM outcomes to the global consolidated third-party risk picture owned by HQ GRC.
- All hub projects above the agreed risk threshold receive a Security by Design intake assessment before design is locked.
- Security by Design delivery assurance completed and documented before go-live for all in-scope projects.
- Hub-scope third-party suppliers assessed, risk-scored, and tracked end-to-end within agreed timescales.
- Significant findings (Security by Design and TPRM) escalated and remediation tracked to closure.
- Hub assessment registers accurate, current, and submitted to Group GRC on cadence.
Required Skills:
- 5 - 10 years of experience as a Compliance Officer.
- Practical experience conducting security assessments in a project or solution delivery context.
- Experience managing third-party supplier security assessments end-to-end.
- Working knowledge of security architecture principles sufficient to assess solutions against a defined baseline.
- Familiarity with TPRM platforms and risk scoring methodologies.
- Ability to engage and influence project owners, procurement teams, and vendors without direct authority.
- Desirable certifications: CISA, CRISC, ISO27001 LI, ISO27001 LA, CISSP (Associate).
- Professional proficiency in English (working language); additional hub language an advantage.
- Rigorous, organised, with strong written documentation discipline.
- Analytical and problem-solving capabilities.
- Rigorous management of results.
- Business consulting (influencing without authority).
- Innovation and Change.
- Learning Development.
Didn’t find the job appropriate? Report this Job