Supplier Assurance Lead at Morson Edge, North West, £Contract Rate

Contract Description

Supplier Assurance Lead/ Cyber Security Risk Manager/ Third Party Cyber Risk Lead

£500 per day - Outside IR35 - North West Based - Hybrid

My client is looking for an experienced Supplier Assurance Lead to join their Cyber Security team, taking a lead role in identifying, assessing and managing cyber security risks across a complex supplier and third-party ecosystem.

This is a senior position requiring someone who can go beyond standard supplier due diligence exercises. Youll be expected to understand the underlying cyber security risks within the supply chain, provide risk-based recommendations, and work closely with procurement, commercial and security stakeholders to drive effective risk management throughout the supplier lifecycle.

Security Clearance

Eligibility for UK Security Check (SC) clearance is a mandatory requirement for this role. Candidates who already hold active SC clearance will be prioritised.

Essential Experience:

  • Significant experience within Information Security, Cyber Security GRC, Third-Party Risk Management or Supplier Assurance.
  • Proven experience performing supplier assurance reviews and third-party cyber security assessments.
  • Experience reviewing supplier security evidence including penetration testing reports, certifications, audit findings and assurance documentation.
  • Strong understanding of supplier risk management and third-party cyber security risk.
  • Experience assessing technical security controls and communicating risk clearly to both technical and non-technical stakeholders.
  • Strong analytical and problem-solving skills with the ability to evaluate complex technical information and determine business impact.
  • Experience working with risk management frameworks, governance processes and assurance methodologies.
  • Excellent stakeholder management and relationship-building skills.
  • Strong written and verbal communication skills with experience presenting security risks and recommendations to senior stakeholders.
  • Ability to obtain UK SC Security Clearance.

Key Responsibilities:

  • Lead cyber security assessments of prospective and existing suppliers using publicly available information, supplier-provided evidence and specialist assurance tooling.
  • Assess supplier security documentation including penetration testing reports, certifications, audit reports, SOC reports and other assurance evidence.
  • Manage the cyber security supplier assurance process, including assessment tracking, reporting, governance and metrics.
  • Provide risk-based recommendations and security advice regarding supplier onboarding, contract renewals and ongoing supplier engagements.
  • Ensure supplier assurance activities incorporate relevant legislative, regulatory and compliance requirements.
  • Maintain supplier assurance processes in line with industry best practice and the evolving threat landscape.
  • Work closely with procurement, commercial, legal and operational teams to ensure a coordinated approach to supplier risk management.
  • Support the definition of cyber security requirements within supplier contracts and associated security documentation.
  • Coordinate security assessments involving both information security and physical security controls where required.
  • Ensure appropriate governance processes are followed for suppliers handling sensitive or regulated information.
  • Identify opportunities to improve supplier assurance processes, tooling, reporting and overall third-party risk management capability.
  • Review and assess customer security requirements where the organisation acts as a supplier.
  • Act as the Cyber Security SME for supplier assurance and represent the function in discussions with internal and external stakeholders.
  • Contribute to the ongoing development and maturity of third-party risk management frameworks, processes and controls.

Desirable Experience:

  • Active UK SC Security Clearance.
  • Experience working within highly regulated or security-conscious environments.
  • Experience with supplier assurance platforms and third-party risk management tooling.
  • Knowledge of supply chain risk management and vendor security assurance.
  • Experience developing or enhancing supplier assurance processes and frameworks.
  • Understanding of ISO 27001, NIST, Cyber Essentials and similar security standards.
  • Experience supporting procurement and commercial teams with security-related contractual requirements.
  • Relevant certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor, ISO 27001 Lead Implementer or similar.


This is an excellent opportunity for an experienced cyber security professional to take ownership of supplier assurance activities within a complex environment, helping to strengthen third-party risk management and improve overall cyber resilience.