Overview
In this role you assess cyber and digital safety risks across easyJet’s supplier network and collaborate with internal stakeholders to drive remediation. You help strengthen the supplier risk framework and monitor risk indicators to keep risks within appetite. You will translate technical findings for business audiences and support governance with timely reporting. This position sits in the Digital Safety team, enabling safer digital operations across a fast-moving airline. You will contribute to protecting a complex supplier ecosystem while working with cross-functional peers to deliver tangible improvements.
Pay / Benefits
- up to 20% bonus
- 7% pension contributions
- Medical Cash Plan
- staff travel benefits
- 25 days of annual leave + bank holidays
- annual holiday credit
Responsibilities
- Conduct third-party supplier risk assessments including due diligence and risk analysis
- Track and drive assessments through the assurance lifecycle
- Engage with suppliers to review findings and agree remediation actions
- Develop and improve the third-party risk management framework
- Report risk insights and trends to governance forums
- Manage unresolved supplier security risks and escalation
- Partner with supplier relationship managers to maintain visibility of risk exposure
- Collaborate with SMEs to evaluate findings and plan remediation
- Contribute to risk documentation and runbooks
- Participate in supplier contract reviews and provide risk-based recommendations
- Perform ongoing supplier monitoring and reassessment
- Support supplier prioritisation based on risk changes
- Contribute to risk metrics and KPIs for programme effectiveness
- Support risk reporting, compliance activities and audit readiness
- Maintain risk and exception registers and related reporting
- Facilitate meetings, document decisions and track actions
Key requirements
- At least two years’ experience in information security, IT audit, GRC or third-party risk management
- Knowledge of ISO 27001, SOC 2, PCI-DSS and GDPR
- Experience analysing technical documentation and assessing control effectiveness
- Relevant information security or risk management qualifications or equivalent experience
- Strong written and verbal communication translating technical risks to business audiences
- Proactive, organized workload management
- Analytical and problem-solving skills
- Ability to build effective stakeholder relationships
- Experience producing reports and supporting governance activities
- Commitment to continuous learning and subject matter expertise
- Collaborative, delivery-focused mindset
- strong communication
- proactive
- organized
- ISO 27001
- SOC 2
- PCI-DSS
…
