Marks and Spencer Logo

Marks and Spencer

TPRM Specialist

Posted 5 Days Ago
Be an Early Applicant
In-Office or Remote
Hiring Remotely in United Kingdom
Mid level
In-Office or Remote
Hiring Remotely in United Kingdom
Mid level
Lead third‑party security assessments across vendor selection, onboarding and monitoring. Assess supplier security posture, recommend remediation, act as supplier contact, support KPIs and dashboards, and collaborate with Legal, Procurement, Data Protection and Privacy to improve TPRM controls and programme.
The summary above was generated by AI

We are looking for an experienced Third Party Risk Management Specialist to support the assessment, management and ongoing improvement of supplier security risk across M&S. Working within our Cyber Security function, you will help ensure that third parties meet our security standards and contractual requirements throughout the full supplier lifecycle.

 

You will oversee third party security assessments, provide guidance to suppliers and internal teams, and support the development of our third party security risk management programme. This role is ideal for someone with strong cybersecurity governance experience, confident stakeholder management skills, and the ability to coach and support others in a fast-moving environment.

 

Due to high interest, this role may close earlier than advertised. We recommend applying as soon as possible.

 

What you’ll do

 

  • Lead third party risk assessments across vendor selection, onboarding and ongoing monitoring

  • Assess supplier security posture against M&S standards, identifying risks and recommending practical remediation actions

  • Act as a key point of contact for suppliers, providing guidance on security queries, incidents and mitigation activity

  • Support reporting on third party security risk posture, including KPIs, dashboards and management insight

  • Collaborate with Legal, Procurement, Data Protection and Privacy teams to strengthen contractual security controls and improve the wider TPRM programme

 

Who you are

 

  • Strong experience in third party security, supplier risk management or cybersecurity governance

  • Good understanding of cybersecurity risk assessment, reporting, policies, processes and standards

  • Experience assessing third parties against organisational security requirements, ideally within a large or global organisation

  • Strong analytical, organisation and time management skills, with the ability to manage multiple priorities and recommend practical improvements

  • Excellent communication and stakeholder management skills, with confidence engaging suppliers, internal teams and coaching others

 

Supporting qualifications in technology, information security or service management would be beneficial, such as COBIT, ITIL, a Computer Science degree or a Cyber Security degree.

 

What’s in it for you?

 

Working at M&S means being part of something bigger - helping to deliver quality, value and service to millions of customers every day. We’re inclusive, fast-moving and always evolving, with a strong sense of purpose and a focus on doing the right thing.

 

Here are just a few of the benefits that make working here even more rewarding:

 

  • Competitive holiday allowance with the option to buy more

  • Discretionary bonus schemes linked to your performance and ours

  • Strong pension and life assurance to help plan for the future

  • Tailored induction and training to support your development from day one

  • Exclusive perks and savings through our M&S Choices portal

  • Market-leading family policies, including parental, adoption and neonatal leave

  • 24/7 wellbeing support, including virtual GP access and mental health services

  • One paid volunteer day a year to support a cause that matters to you

 

Everyone’s welcome

 

We are ambitious about the future of retail. We’re disrupting, innovating and leading the industry into a more conscientious, inspiring digital era. We’re transforming how we work together and offering our most exciting opportunities yet. Marks & Spencer strives to be an inclusive organisation, trusted and admired by our colleagues, customers and suppliers. Join us and make change happen.

 

We are committed to building diverse and representative teams, where everyone can bring their whole selves to work and be at their best. We support each other and work together to win together.

 

If you feel you'd benefit from any support or reasonable adjustments during any stage of the recruitment process, please don’t hesitate to let us know when completing your application. This information will be picked up by our team so we can help you perform at your best.

 

#LI-hybrid #hybridrole #LI-DR1

Similar Jobs

An Hour Ago
Remote or Hybrid
Senior level
Senior level
Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Lead consulting engagements to improve pricing and revenue strategies for technology clients. Supervise and mentor teams, manage client relationships, apply pricing models and digital solutions, analyze market dynamics to drive profitability, and ensure project quality and timelines.
Top Skills: Anaplan
2 Hours Ago
In-Office or Remote
Senior level
Senior level
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
The Senior Account Executive will drive high-velocity deals in AI and Digital Native companies, engaging founders and CTOs while leveraging local market knowledge to convert prospects into customers.
Top Skills: Ai-First WorkflowsCloudCollaboration PlatformsDeveloper ToolingInfrastructureItsmSaaS
4 Hours Ago
In-Office or Remote
Junior
Junior
Greentech • Hardware • Internet of Things • Machine Learning • Software • Business Intelligence • Agriculture
The Business Development Executive will drive business growth, execute sales strategies, build customer relationships, and meet growth targets primarily in the agricultural sector. This role involves high autonomy and working closely with teams to optimize customer satisfaction and expand Halter's market presence.

What you need to know about the Belfast Tech Scene

If asked to name the birthplace of the RMS Titanic, you might not say Belfast. Similarly, if asked to name Europe's leading destination for foreign direct investment in new software development, Belfast might not come to mind. Yet, both are true. The city has emerged as a tech powerhouse, recently ranked among the best in the U.K. for tech careers — especially for software developers. It also leads the U.K. with the highest percentage of software development jobs advertised.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account