Third Party Risk Analyst; Supplier Assurance
Listed on 2026-09-01
-
IT/Tech
Information Security & Data Protection, Cybersecurity
Job Description - Third Party Risk Analyst (Supplier Assurance) (17236)
Third Party Risk Analyst (Supplier Assurance) ( 17236 )
Third Party Risk Analyst (Supplier Assurance)
We are easy
Jet – a FTSE listed, £multi-billion low-cost airline that serves tens of millions of customers every single year. If you’re reading this, you have probably already been an easy
Jet customer, and you’ll know that there is no more iconic (or Orange!) travel brand in Europe.
We fly more than 1,207 routes, connecting 38 countries across Europe, and employ more than 18,000 colleagues. We’re on a mission to make low-cost travel easy – and whatever your role here, you’ll connect millions of people to what they love using Europe’s best airline network, great value fares, and friendly service.
What makes us easy
Jet? Our Promise Behaviours - we are Safe, Bold, Welcoming and Challenging. Four Behaviours. One Spirit. One easy
Jet.
- Have experience in information security, IT audit, governance, risk and compliance, or supplier risk management.
- Enjoy analysing risk, engaging with stakeholders and helping drive meaningful improvements.
- Are confident communicating technical concepts to non-technical audiences.
- Thrive in a collaborative environment where you can influence positive outcomes across the business.
- Want to play a key role in protecting a complex and fast-moving digital landscape.
Our Digital Safety team is made up of cyber security professionals dedicated to ensuring that Digital Safety is as embedded within easy
Jet as Aircraft Safety. Working closely with Operational, Commercial, Regulatory and Audit teams, we help safeguard the organisation from evolving digital risks.
This role works alongside the Supplier Resilience Lead, Senior Digital Safety Risk Manager, Head of Digital Safety Assurance and the wider Digital Safety team to strengthen our approach to supplier and third-party risk management.
THE ROLEAs a Third Party Risk Analyst (Supplier Assurance), you'll help assess, monitor and manage cyber and digital safety risks across easy
Jet’s supplier network. You'll work closely with internal stakeholders and external suppliers to identify risks, evaluate controls and support remediation activities, ensuring risks remain within our agreed appetite.
Key responsibilities include:
- Conducting third-party supplier risk assessments, including due diligence reviews, supplier questionnaires and risk analysis.
- Tracking and driving supplier assessments through the full assurance lifecycle.
- Engaging with suppliers to review findings and agree risk remediation activities.
- Supporting the ongoing development and improvement of easy
Jet’s third-party risk management framework. - Reporting supplier risk insights and trends through appropriate governance forums.
- Supporting the management and escalation of unresolved supplier security risks.
- Partnering with supplier relationship managers to maintain visibility of supplier risk exposure.
- Working with subject matter experts to evaluate findings and develop remediation plans.
- Contributing to third-party risk documentation, processes and operational runbooks.
- Participating in supplier contract reviews and providing risk-based recommendations.
- Performing ongoing monitoring and reassessment of suppliers based on risk and oversight requirements.
- Supporting supplier prioritisation activities based on changing risk profiles.
- Contributing to risk metrics and KPIs that measure the effectiveness of the third-party risk programme.
- Supporting risk reporting, compliance activities and audit preparedness.
- Maintaining risk registers, exception registers and associated reporting.
- Facilitating meetings, documenting decisions and tracking associated actions.
- A minimum of two years' experience within information security, IT audit, GRC or third-party risk management.
- Understanding of recognised security, compliance and risk frameworks such as ISO 27001, SOC 2, PCI-DSS and GDPR.
- Experience analysing technical documentation and assessing control effectiveness.
- Relevant information security or risk management qualifications, or equivalent knowledge and experience.
- Strong written and verbal…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: