Security Analyst

Company: NTT DATA
Apply for the Security Analyst
Location: London
Job Description:

Overview

In this role you will oversee third-party security and risk across a multi-entity environment, partnering with Legal, Privacy, Compliance and Procurement to ensure governance and regulatory alignment. You will assess supplier controls, monitor risks through the vendor lifecycle, and support audits and customer assurance. You’ll leverage GRC tools and dashboards to drive consistent risk insights and remediation. This is a hands-on, cross-functional position with impact on risk posture and regulatory compliance across UK/EU operations.

Pay / Benefits

  • flexible work options
  • tailored benefits
  • learning and development opportunities

Responsibilities

  • Collaborate with Legal, Procurement, Privacy, and Compliance to assess and manage risks
  • Provide risk-based insights to support decision-making
  • Support audit, regulatory, and customer assurance activities
  • Leverage GRC platforms (OneTrust, BitSight, internal SaaS) to manage TPSA activities
  • Develop dashboards and reports using Power BI and SharePoint for risk governance
  • Contribute to governance forums and risk review meetings
  • Ensure adherence to TPSA tiering models, standards, and processes
  • Maintain third-party risk registers, dashboards, and management reporting
  • Escalate material risks to governance forums
  • Perform periodic reassessments and continuous monitoring across the vendor lifecycle

Key requirements

  • Minimum 3 years in Information Security, Cyber Risk Management, TPRM, Supplier Assurance, or GRC
  • Experience in third-party security risk programmes within medium to large enterprises
  • Experience across UK and EU jurisdictions
  • Experience reviewing supplier security assessments, due diligence questionnaires, audit reports, and compliance evidence
  • Experience supporting security and risk activities related to mergers and acquisitions
  • Strong hands-on experience in TPRM, security risk, or GRC
  • Proven ability to independently deliver third-party assessments end-to-end
  • Knowledge of GDPR, ISO 27001, ISO 42001
  • Stakeholder management
  • Clear, risk-based communication
  • Cross-functional collaboration
  • GRC platforms (OneTrust, Drata, Swiss GRC; BitSight)
  • Power BI and SharePoint for reporting
  • Risk scoring models and reporting frameworks

…

Posted: October 1st, 2026