Third Party Security Due Diligence Lead
GB01 SWIFT UK and Ireland · London, United Kingdom
About The Role
ABOUT US
We’re the world’s leading provider of secure financial messaging services, headquartered in Belgium. We are the way the world moves value – across borders, through cities and overseas. No other organisation can address the scale, precision, pace and trust that this demands, and we’re proud to support the global economy.
We’re unique too. We were established to find a better way for the global financial community to move value – a reliable, safe and secure approach that the community can trust, completely. We’re always striving to be better and are constantly evolving in an ever-changing landscape, without undermining that trust. Five decades on, our vibrant community reflects the complexity and diversity of the financial ecosystem. We innovate diligently, test exhaustively, then implement fast. In a connected and exciting era, our mission has never been more relevant. Swift now has a presence in 200+ countries and legal territories to serve a community of more than 12,000 banks and financial institutions.
Job Summary
Lead the Third-Party Security Due Diligence function for SWIFT, ensuring that third-party suppliers, technology providers, cloud services, and strategic partners are assessed, onboarded, and monitored in line with SWIFT's security, resilience, regulatory, and operational risk requirements.
The role is responsible for managing the end-to-end security due diligence lifecycle, providing expert risk-based assessments of third parties, driving remediation activities, and supporting compliance with applicable regulatory frameworks including DORA, NIS2, ISO 27001, and SWIFT's internal security standards.
Key Responsibilities
Security Due Diligence & Risk Assessment
- Lead the end-to-end third-party security due diligence process, from supplier onboarding through ongoing assurance, reassessment, and offboarding.
- Perform comprehensive security risk assessments of third parties, evaluating cybersecurity, resilience, data protection, cloud security, supply chain security, and operational risk exposures.
- Assess supplier security capabilities through review of questionnaires, policies, certifications, audit reports, penetration testing results, independent assurance reports, and supporting evidence.
- Evaluate control effectiveness against recognised frameworks and standards including ISO 27001, NIST Cybersecurity Framework, SOC reports, DORA, and relevant SWIFT security requirements.
- Identify security gaps, residual risks, and compensating controls, providing clear risk ratings and recommendations to stakeholders.
Supplier Assurance & Continuous Monitoring
- Establish and maintain a risk-based supplier assurance programme for critical and high-risk third parties.
- Drive remediation activities with suppliers and internal stakeholders to address identified security weaknesses and control deficiencies.
- Support ongoing monitoring activities, including reassessments, threat monitoring, breach notifications, security events, and changes in supplier risk profiles.
- Monitor supplier compliance with contractual security obligations and regulatory requirements.
Stakeholder Management & Advisory
- Partner closely with Procurement, Legal, Technology, Architecture, Operational Risk, Compliance, Data Protection, and Business teams to support supplier onboarding and risk decisions.
- Provide expert guidance on third-party security risks, risk acceptance decisions, mitigating controls, and supplier onboarding requirements.
- Present security due diligence outcomes, key risks, and recommendations to governance forums, senior management, and risk committees.
- Act as the subject matter expert for third-party security risk management and supplier assurance activities across the organisation.
Governance & Regulatory Compliance
- Contribute to the development and continuous improvement of SWIFT's Third-Party Security Risk Management and Supplier Assurance frameworks, methodologies, standards, and procedures.
- Ensure due diligence activities align with regulatory expectations and industry best practices, including DORA, NIS2, GDPR, EBA Guidelines, and relevant financial sector requirements.
- Support internal audits, regulatory reviews, and external examinations relating to third-party security risk management.
- Develop management reporting, KPIs, KRIs, and board-level metrics to demonstrate programme effectiveness and risk exposure.
Qualifications & Experience
Essential
- Bachelor's degree in Information Security, Cybersecurity, Computer Science, Risk Management, Information Systems, or a related discipline.
- Minimum 7 years' experience in cybersecurity, third-party security risk management, supplier assurance, security assurance, or technology risk within financial services, critical infrastructure, or a highly regulated environment.
- Strong understanding of third-party security risk management practices and supplier assurance methodologies.
- Practical experience conducting security assessments of cloud providers, SaaS vendors, technology suppliers, and outsourced service providers.
- Strong understanding of security frameworks and standards including ISO 27001, NIST, SOC 1/2, CIS Controls, and cloud security best practices.
- Experience evaluating security controls across identity management, network security, encryption, vulnerability management, incident response, resilience, data protection, and secure software development.
- Excellent risk analysis, stakeholder management, and report-writing skills.
- Ability to communicate complex security risks clearly to technical and non-technical audiences, including senior executives.
Desirable
- Experience supporting regulatory requirements such as DORA, NIS2, EBA Guidelines on Outsourcing, FCA/PRA regulations, or equivalent frameworks.
- Experience in financial services, payments, or highly regulated environments.
- Familiarity with supply chain security, concentration risk, AI supplier assessments, and cloud service provider due diligence.
- Certifications such as CISSP, CISM, CRISC, CISA, CCSP, ISO 27001 Lead Auditor, or equivalent.
- Experience using Governance, Risk & Compliance (GRC) platforms and third-party risk management tools.
Success Measures
- Timely completion of third-party security assessments.
- Effective identification and treatment of supplier security risks.
- Strong stakeholder satisfaction and onboarding support.
- Successful support of regulatory, audit, and assurance activities.
- Continuous improvement of the third-party security risk and supplier assurance programme.
What we offer
We give you the freedom to be yourself. We are creating an environment of unique individuals – like you – with different perspectives on the financial industry and the world. A diverse and inclusive environment in which everyone’s voice counts and where you can reach your full potential.
We are committed to an inclusive and accessible recruitment process. If you require a reasonable accommodation related to accessibility during your application or interview, please contact accessibility-Sysgroup@swift.com or indicate this in your application.
Please note that this mailbox is not monitored for general recruitment enquiries and should only be used for accessibility or accommodation-related requests (for example related to vision, hearing or neurodiversity).
All requests are confidential and will not affect your candidacy.
Don’t meet every single requirement? At Swift, we are dedicated to building a workplace where people can bring their full selves and ideas to the team, so if you are excited about this role, we encourage you to apply even if you do not meet every single qualification.
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
