Menu

Business Analyst – Third Party Risk

GRC Jobs
  • Hybrid-WFH/London or Reading 2 days a week
  • £450-£550 per day (Inside IR35)
Apply for this job

We are seeking an experienced Cyber Security Third Party Risk Business Analyst to support a major third-party risk transformation programme, with a focus on defining and managing critical suppliers across the organisation.

This role will work closely with Procurement, Legal, Cyber Security, Risk, and business stakeholders to design frameworks, strengthen contractual controls, and embed consistent supplier risk practices.

Key Responsibilities

  • Develop a clear, evidence-based definition and framework for identifying and classifying critical suppliers.
  • Design practical tools, guidance, and documentation to enable consistent application across business units.
  • Facilitate workshops and stakeholder sessions to support supplier classification and consolidate outputs into an organisation-wide view.
  • Review and enhance security contract addendums, strengthening cyber, regulatory, and risk-related clauses.
  • Support broader third-party risk initiatives including process design, governance development, and operating model improvements.

Skills & Experience

  • Strong Business Analysis experience, with the ability to translate complex requirements into structured outputs.
  • Understanding of third-party risk, supplier risk, or criticality frameworks.
  • Experience designing risk models, frameworks, or assessment criteria.
  • Ability to analyse contract clauses, particularly security or risk-related content.
  • Strong stakeholder engagement skills, with experience working across Legal, Procurement, Risk, or Cyber teams.
  • Familiarity with regulations and frameworks such as GDPR, NIS2, DORA, ISO 27001, or ISO 27036 is advantageous.
  • Analytical mindset with experience identifying gaps and driving process improvements.
  • Comfortable operating in complex, federated environments.

Barclay Simpson, recognised specialists in Cyber Security jobs and recruitment: https://www.barclaysimpson.com/specialisms/cyber-security-jobs/

Job listing posted by Barclay Simpson: https://www.barclaysimpson.com/job/business-analyst-third-party-risk/

Apply for this job
Upload your CV/resume or any other relevant file. Max. file size: 2 MB.
I consent to the storing and processing of my personal data as detailed in Barclay Simpson’s Privacy Policy.

We seek individuals from a diverse talent pool and encourage applicants from underrepresented groups to apply to our vacancies. Our commitment to fair recruitment processes means that we welcome applicants from all backgrounds, regardless of their lived experience or personal characteristics. We also invite applicants who meet most of the listed requirements, even if not all, to apply. If you require any adjustments to the application process, please let us know.

Barclay Simpson acts as an Employment Agency for permanent positions and an Employment Business for temporary/contract engagements.