Security Analyst
Salary: £63,000 - 103,000 per year
Requirements:- Minimum 3 years experience in Information Security, Cyber Risk Management, Third-Party Risk Management, Supplier Assurance, or GRC functions.
- Demonstrable experience working on third-party security risk programmes within medium to large enterprises.
- Experience supporting organisations operating across multiple jurisdictions, including the UK and European Union.
- Experience reviewing supplier security assessments, due diligence questionnaires, audit reports, and compliance evidence.
- Experience supporting security and risk activities related to mergers and acquisitions.
- Solid hands-on experience in TPRM, security risk, or GRC.
- Proven ability to independently deliver third-party assessments end-to-end.
- Strong understanding of regulatory frameworks such as GDPR, ISO 27001, and ISO 42001.
- Regular interaction with stakeholders, with limited strategic ownership.
- Collaborate with cross-functional teams including Legal, Procurement, Privacy, and Compliance.
- Provide clear, risk-based insights to stakeholders and support decision-making.
- Support audit, regulatory, and customer assurance requirements.
- Leverage GRC platforms such as OneTrust, BitSight, and internal SaaS solutions to manage TPSA activities.
- Support month-end SLA reporting and develop dashboards using Power BI and SharePoint.
- Contribute to governance forums and risk review meetings.
- Ensure adherence to TPSA tiering models, standards, and processes.
- Maintain oversight of third-party risks throughout the vendor lifecycle.
- Perform periodic reassessments and continuous monitoring activities.
- Track remediation activities and risk treatment plans through closure.
- Maintain third-party risk registers, dashboards, and management reporting.
- Escalate material risks and control deficiencies to appropriate governance forums.
- Partner with Procurement, Legal, Compliance, Privacy, Enterprise Risk, Internal Audit, and Technology teams.
- Provide risk-based recommendations to business stakeholders and decision-makers.
- Support customer assurance requests and regulatory inquiries where required.
- Participate in governance committees and risk review meetings.
- Use Governance, Risk & Compliance platforms and applications such as OneTrust, Drata, and Swiss GRC.
- Support development of assessment methodologies, risk scoring models, and reporting frameworks.
- AI
- Support
- Power BI
- Security
- SharePoint
- Network
More:
We are NTT DATA, a $30+ billion business and technology services, AI and digital infrastructure leader co-innovating solutions with clients and partners globally for business and societal impact. We serve 75% of the Fortune Global 100, operate in over 70 countries, and are part of NTT Group, which invests over $3 billion annually in R&D. We offer tailored benefits that support physical, emotional, and financial wellbeing, along with continuous learning and development opportunities and flexible work options. We are a Global Top Employer committed to equal opportunities, equity, diversity, and inclusion, and we actively support applicants with disabilities and long-term health conditions. This role is based in the United Kingdom/Remote and reports to the Head of Information Security.
last updated 36 week of 2026