CSI GLOBAL LTD
Third Party Security Assessment Consultant

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Role: Third Party Security Assessment Consultant
Location: Sheffield, UK
Type: Contract - Inside IR35
Primary Skills
- Supply Chain Risk Management (SCRM)
- Consulting experience
- Proposing Technical solutions
- RFP Contract proposing
Nice to Have
- Experience in the Financial Services sector
- Knowledge of Security Architecture and Risk Management
Responsibilities
- Provide end-to-end cybersecurity consultancy during supplier selection, onboarding, and assessment processes
- Assess cyber risks associated with third-party suppliers and recommend appropriate risk mitigation measures
- Support the development and enhancement of third-party security assessment and consultancy frameworks
- Participate in solution design and architecture discussions to identify secure and compliant solutions
- Collaborate with cybersecurity procurement, third-party management, risk, and business teams
- Perform quality assurance reviews of third-party security assessment outcomes
- Provide subject matter expertise on cyber risks, security controls, and supplier security posture
- Support critical projects involving third-party suppliers and external service providers
- Assist with audit, regulatory risk, and control-related reviews and information requests
- Prepare reports, recommendations, presentations, and risk assessments for senior stakeholders
- Deliver training, guidance, and knowledge sharing to security assessment teams
- Contribute to continuous improvement of third-party security assessment processes and governance
- Influence stakeholders and drive risk-based decision-making across supplier engagements
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
To be successful in this role you should have
- Strong experience in Supply Chain Risk Management (SCRM) or Third-Party Risk Management
- Consultancy experience within Cybersecurity Risk Management or Technology domains
- Experience proposing technical solutions and participating in architecture or solution design discussions
- Experience supporting RFP processes, vendor assessments, contract reviews, and supplier onboarding
- Strong understanding of Risk and Control Management frameworks
- Ability to identify and communicate security risks, threats, vulnerabilities, and control gaps
- Experience engaging with business, technology, risk, audit, and regulatory stakeholders
- Strong stakeholder management, communication, and influencing skills
- Experience working in complex enterprise or regulated environments
- Knowledge of Cloud Security, particularly SaaS environments
- Understanding of AI-related security risks and controls is desirable
- Industry certifications such as CISSP, CISA, CISM, CRISC, or CCSP are advantageous
- Experience in Financial Services or other regulated industries is preferred


Get help with your application
Your very own career expert that helps elevate your application to the next level.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills