Shape the Future of AIJoin one of the UK's fastest-growing companies and become a Professional Development Expert in Artificial Intelligence.

View Roles

Third Party Information Security Risk Management Specialist

WTW
West Midlands
2 weeks ago
Applications closed

Related Jobs

View all jobs

Third Party Information Security Risk Management Specialist

Security Manager - Logistics

Cyber Risk Consultant

Cyber Risk Consultant

Cyber Security Analyst

Cyber Security Analyst

Drive Risk Awareness. Strengthen Supply Chain Security.

We’re looking for an experiencedInformation Security Risk Management Specialistto help safeguard WTW’s global operations byidentifying and managing information security risks across our supply chain.


In this key role, you’ll be responsible fordeveloping and implementing risk management strategies, performing in-depth supplier security assessments, and ensuring compliance withindustry standards, regulatory requirements, and internal WTW policies.


You'll play a critical part in enhancing our third-party risk posture by working closely with internal teams and external partners toassess vulnerabilities, mitigate threats, and embed security best practicesthroughout the supply chain.


If you have a strong background in information security, risk management, and a passion for making businesses more resilient—we’d love to hear from you.


The Role


This role will support the ongoing operations of WTW Technology and Cyber Risk and Controls & Regulatory engagement function in:

Evaluate supplier information security practices, policies and systems or risk exposure.  Enhance risk assessment methodologies for supplier relationship management. Conduct thorough security assessments of suppliers to identify potential risks and vulnerabilities. Engage with procurement, legal and other stakeholder to integrate security requirements into supplier contracts. Collaborate with suppliers to develop and implement risk mitigation plans. Identify supplier risks and security gaps and support of tracking and remediation.  Guide and support the Third-Party Security Assessment team with assessments and due diligence activities in line with Information and Cyber Security requirements. Provide guidance and support to internal teams on supplier risk management best practices. Stay up to date with the latest information security trends, threats, and technologies. Provide reports and recommendations to management on supplier risk and mitigation activities. Ensure adherence to relevant regulations, WTW standards, and industry best practices.

At WTW, we trust you to know your work and the people, tools and environment you need to be successful. The majority of our colleagues work in a ”hybrid” style, with a mix of remote, in-person and in office interactions dependent on the needs of the team, role and clients. Our flexibility is rooted in trust and “hybrid” is not a one-size-fits-all solution. We understand flexibility is key to supporting an inclusive and diverse workforce and so we encourage requests for all types of flexible working as well as location-based arrangements. Please speak to your recruiter to discuss more.

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Automate Your Cyber Security Jobs Search: Using ChatGPT, RSS & Alerts to Save Hours Each Week

Cyber roles drop across consultancies, MSSPs, hyperscalers, banks, gov & start-ups every day—often buried in ATS portals or duplicated across boards. The fix is simple: put discovery on autopilot with keyword-rich alerts, RSS feeds & a reusable ChatGPT workflow that triages listings, ranks fit, & tailors your CV in minutes. This copy-paste playbook is built for www.cybersecurityjobs.tech readers. It’s UK-centric, practical, & designed to save you hours each week. What You’ll Have Working In 30 Minutes A role & keyword map spanning SecOps/Detection, DFIR, AppSec, Cloud Security, GRC, Red Team, Threat Intel, IAM/PAM, OT/ICS & Vulnerability Management. Shareable Boolean search strings for Google & job boards to cut noise fast. Always-on alerts & RSS feeds delivering fresh roles to your inbox/reader. A ChatGPT “Cyber Job Scout” prompt that deduplicates, scores fit & outputs tailored actions. A simple pipeline tracker so deadlines & follow-ups never slip.

10 Cyber Security Recruitment Agencies in the UK You Should Know (2025 Job‑Seeker Guide)

UK cyber security hiring remains resilient in 2025, driven by nation-state threats, cloud security investments, and NCSC regulatory pressures. Lightcast reports +42 % YoY growth in UK roles mentioning “SOC”, “cyber risk”, “offensive security” or “GRC”. Yet despite 30,000 active cyber professionals, monthly live vacancies remain in the 2,500–2,900 range. The result: strong demand across public and private sector. We reviewed 50 + consultancies and included only those that: Are registered in the UK (Companies House) Operate a dedicated Cyber Security / InfoSec / Risk & Compliance desk Posted at least 5 UK cyber security roles between March and June 2025 This guide includes 2025 salary ranges, key skills, interview prep tips, and a verified recruiter directory.

Cyber Security Jobs Skills Radar 2026: Emerging Frameworks, Tools & Certifications to Learn Now

Cyber threats are evolving—and so must the people defending against them. As ransomware, AI-enhanced phishing, and supply chain attacks grow more advanced, UK employers are urgently hiring cyber security professionals with the right mix of strategic and hands-on skills. Welcome to the Cyber Security Jobs Skills Radar 2026, your go-to guide for the most in-demand tools, frameworks, certifications, and technologies shaping the UK's cyber workforce. Whether you're a SOC analyst, penetration tester, or cloud security architect, this annual radar is designed to help you stay ahead of the market.