About the Role
TMHCC International is seeking a Third Party Cyber Risk Lead to own and mature its third-party cyber risk management processes. This role involves streamlining processes, partnering with internal teams to prioritize risk, remediate issues, and deliver clear management information on cyber risk across the third-party portfolio.
Responsibilities
- Own, manage, and evolve the third-party security due diligence process for TMHCC International vendors, including onboarding and continuous monitoring.
- Establish and maintain a vendor criticality assessment process.
- Ensure appropriate vendor due diligence and monitoring activities take place in accordance with vendor criticality.
- Own and maintain ongoing due diligence requirements for critical and high-risk suppliers in line with regulatory expectations, including DORA, NIS2, PRA and FCA requirements etc.
- Build MI and dashboards to showcase security due diligence and third-party risk management efforts for senior IT stakeholders and executives.
- Collaborate with IT, Procurement, and Legal teams to embed third party security risk management controls into the overall vendor risk management process.
- Ensure compliance with relevant industry regulations and standards (e.g., DORA, NIS2, CIS Controls, NIST, GDPR).
- Provide security guidance on third party due diligence, contract reviews, and other ad-hoc vendor security risk management queries.
- Create and maintain vendor security risk management documentation (including process documentation) and training materials.
- Stay current on emerging vendor security trends, tools, and technologies.
- Support the Cyber Governance Manager by providing metrics to the Divisional IT Risk Reporting and Dashboards.
- Escalate significant cyber risks and issues as they emerge to the Cyber Governance Manager and BISO for action or information.
Requirements
- Experience in cyber/information security risk roles with a focus on third-party/vendor risk management.
- Experience in regulated industries, implementing relevant regulations and expectations for third-party security risk management.
- Proven experience designing, running, and improving vendor security due diligence processes.
- Deep understanding of and ability to articulate the risk associated with vendor risk posture to both technical and non-technical stakeholders.
- Ability to coordinate and chair regular meetings and workshops with multiple stakeholders to provide guidance, collaboration and oversight of third-party security risk management initiatives.
- Confidence in presenting information and acting as a source of SME knowledge and guidance.
- Analytical, conceptual thinking, planning and execution skills.
- Ability to drive improvements and take charge of initiatives, backed with excellent coordination strength as well as assertiveness.
- Results-orientated and able to manage to measurable targets and desired outcomes.
- A passion to champion a cyber security culture and continuous learning of latest cyber threat trends.
- Strong communication skills with the ability to explain complex security issues to non-technical stakeholders.
Skills
- CISSP
- CISM
- CRISC
- ISO 27001 Lead Implementer/Lead Auditor
- Security assurance certifications and assessments (e.g., ISO 27001, SOC 2, CSA STAR/CAIQ, vendor security questionnaires)
- Third party risk management platforms or GRC tooling
- Building actionable MI and dashboards (e.g. using Power BI)
- Specialty and Lloyd’s/Companies market insurance industry
Location
- Remote
Work Type
- Permanent
- Full-time
Experience Level
- Lead
Education Level
- Bachelor’s degree in information security, Technology Risk Management or a related field.
Benefits
- Competitive salary
- Employee benefit package
About the Company
- TMHCC is one of the world’s leading Specialty Insurers.
- With deep expertise in our chosen lines of business, our unparalleled track record and a solid balance sheet, TMHCC evaluates and manages risk like no one else in the industry.
- Looking beyond profit, empowering our people and delivering on our commitments are at the core of our customer values, along with a desire to grow and provide creative and innovative solutions to our clients.
- Operations sits at the heart of TMHCC, ensuring the smooth running of all business processes — from policy administration and claims handling to data, technology, and delivery.
- We focus on driving efficiency which enables our teams across the business to deliver exceptional results every day.
- IT is the foundation for TMHCC’s success - enabling the business to grow, compete, and innovate through technology, security, and solution design.
- From shaping strategy to delivering resilient operations, we ensure every capability is aligned to business value.
- Our inclusive and collaborative culture empowers everyone to explore ideas, solve meaningful challenges, and build fulfilling careers that make a real impact.
- The Tokio Marine HCC Group of Companies offers a competitive salary and employee benefit package.
- We are a successful, dynamic organization experiencing rapid growth and are seeking energetic and confident individuals to join our team of professionals.
- Your success is our priority.
- In a world that is rapidly changing, TMHCC enables you to take on opportunities with confidence.
- At Tokio Marine HCC, we pride ourselves on hiring the smartest, most conscientious people, who want to make a difference no matter their background.
- And then we give them the support and trust they need.
- We’re always looking for curious, creative transformative thinkers who want to change the status quo and have a passion for doing the right thing.
Equal Opportunity
- The Tokio Marine HCC Group of companies is an equal opportunity employer.
