
3rd Party Risk Analyst
- London
- Permanent
- Full-time
- Maintain and measure the information security posture of 3rd Party vendors to reduce risk to Informa and ensure our organisation remains compliant with relevant legislation and security policy.
- Perform vendor security assessments in line with security best practice and the Informa InfoSec Management framework and policies.
- Liaise with business stakeholders to advise them on the status of vendor security risk.
- Report on the status and risk profile of assessed and unassessed vendors to the InfoSec team and the risk committee as needed.
- Work with Legal and Procurement to ensure 3rd party risks are managed end to end.
- Support the current 3rd Party Risk Analyst with their 3rd party security risk assessments
- Suggest and drive improvements to the effectiveness and efficiency of the 3rd party security risk process
- Contribute to the overall Information Security programme of improvements across the Group.
- Experience in managing 3rd Party vendors security assessments.
- Excellent stakeholder management and engagement skills; experience of negotiating and managing internal and external stakeholders and third parties.
- The ability to 'translate' technical security issues to business risk
- Able to suggest pragmatic technical and organisational controls to manage identified risks
- Comfortable explaining complex problems in a simple, clear and concise manner to the various parts of the group.
- Excellent written and verbal communication and presentation skills.
- Effective and creative problem-solving skills.
- Proven track record of operating in time critical, diverse, creative and corporate Environments.
- Experience of working with multiple stakeholders and able to adjust approach where necessary
- Understanding of (InfoSec) risk management concepts
- Understanding of the guiding principles behind ISO27001 and related standards.
- Ability and confidence to prioritise and balance conflicting and diverse demands from technical and business perspectives.
- Experience in working with Governance Risk Compliance (GRC) tools, especially tools used for 3rd party risk assessments / management
- CISA/CRISC desired but not essential.
- Great community: a welcoming culture with in-person and online social events, our fantastic Walk the World charity day and active diversity and inclusion networks
- Broader impact: take up to four days per year to volunteer, with charity match funding available too
- Career opportunity: the opportunity to develop your career with bespoke training and learning, mentoring platforms and on-demand access to thousands of courses on LinkedIn Learning. When it's time for the next step, we encourage and support internal job moves
- Time out: 25 days annual leave, rising to 27 days after two years, plus a birthday leave day and the chance to work from (almost!) anywhere for up to four weeks a year
- A flexible range of personal benefits to choose from, plus company funded private medical cover
- A ShareMatch scheme that allows you to become an Informa shareholder with free matching shares
- Strong wellbeing support through EAP assistance, mental health first aiders, a healthy living subsidy, access to health apps and more
- Recognition for great work, with global awards and kudos programmes
- As an international company, the chance to collaborate with teams around the world