Rodeo
Get started

Swift

Third Party Security Due Diligence Lead

London
Posted about 18 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

About Us

We’re the world’s leading provider of secure financial messaging services, headquartered in Belgium. We are the way the world moves value – across borders, through cities and overseas. No other organisation can address the scale, precision, pace and trust that this demands, and we’re proud to support the global economy.

We’re unique too. We were established to find a better way for the global financial community to move value – a reliable, safe and secure approach that the community can trust, completely. We’re always striving to be better and are constantly evolving in an ever-changing landscape, without undermining that trust. Five decades on, our vibrant community reflects the complexity and diversity of the financial ecosystem. We innovate diligently, test exhaustively, then implement fast. In a connected and exciting era, our mission has never been more relevant. Swift now has a presence in 200+ countries and legal territories to serve a community of more than 12,000 banks and financial institutions.

Job Summary

Lead the Third-Party Security Due Diligence function for SWIFT, ensuring that third-party suppliers, technology providers, cloud services, and strategic partners are assessed, onboarded, and monitored in line with SWIFT's security, resilience, regulatory, and operational risk requirements.

The role is responsible for managing the end-to-end security due diligence lifecycle, providing expert risk-based assessments of third parties, driving remediation activities, and supporting compliance with applicable regulatory frameworks including DORA, NIS2, ISO 27001, and SWIFT's internal security standards.

Key Responsibilities

Security Due Diligence & Risk Assessment

  • Lead the end-to-end third-party security due diligence process, from supplier onboarding through ongoing assurance, reassessment, and offboarding.
  • Perform comprehensive security risk assessments of third parties, evaluating cybersecurity, resilience, data protection, cloud security, supply chain security, and operational risk exposures.
  • Assess supplier security capabilities through review of questionnaires, policies, certifications, audit reports, penetration testing results, independent assurance reports, and supporting evidence.
  • Evaluate control effectiveness against recognised frameworks and standards including ISO 27001, NIST Cybersecurity Framework, SOC reports, DORA, and relevant SWIFT security requirements.
  • Identify security gaps, residual risks, and compensating controls, providing clear risk ratings and recommendations to stakeholders.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Supplier Assurance & Continuous Monitoring

  • Establish and maintain a risk-based supplier assurance programme for critical and high-risk third parties.
  • Drive remediation activities with suppliers and internal stakeholders to address identified security weaknesses and control deficiencies.
  • Support ongoing monitoring activities, including reassessments, threat monitoring, breach notifications, security events, and changes in supplier risk profiles.
  • Monitor supplier compliance with contractual security obligations and regulatory requirements.

Stakeholder Management & Advisory

  • Partner closely with Procurement, Legal, Technology, Architecture, Operational Risk, Compliance, Data Protection, and Business teams to support supplier onboarding and risk decisions.
  • Provide expert guidance on third-party security risks, risk acceptance decisions, mitigating controls, and supplier onboarding requirements.
  • Present security due diligence outcomes, key risks, and recommendations to governance forums, senior management, and risk committees.
  • Act as the subject matter expert for third-party security risk management and supplier assurance activities across the organisation.

Governance & Regulatory Compliance

  • Contribute to the development and continuous improvement of SWIFT's Third-Party Security Risk Management and Supplier Assurance frameworks, methodologies, standards, and procedures.
  • Ensure due diligence activities align with regulatory expectations and industry best practices, including DORA, NIS2, GDPR, EBA Guidelines, and relevant financial sector requirements.
  • Support internal audits, regulatory reviews, and external examinations relating to third-party security risk management.
  • Develop management reporting, KPIs, KRIs, and board-level metrics to demonstrate programme effectiveness and risk exposure.

Essential

Qualifications & Experience

  • Bachelor's degree in Information Security, Cybersecurity, Computer Science, Risk Management, Information Systems, or a related discipline.
  • Minimum 7 years' experience in cybersecurity, third-party security risk management, supplier assurance, security assurance, or technology risk within financial services, critical infrastructure, or a highly regulated environment.
  • Strong understanding of third-party security risk management practices and supplier assurance methodologies.
  • Practical experience conducting security assessments of cloud providers, SaaS vendors, technology suppliers, and outsourced service providers.
  • Strong understanding of security frameworks and standards including ISO 27001, NIST, SOC 1/2, CIS Controls, and cloud security best practices.
  • Experience evaluating security controls across identity management, network security, encryption, vulnerability management, incident response, resilience, data protection, and secure software development.
  • Excellent risk analysis, stakeholder management, and report-writing skills.
  • Ability to communicate complex security risks clearly to technical and non-technical audiences, including senior executives.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Desirable

  • Experience supporting regulatory requirements such as DORA, NIS2, EBA Guidelines on Outsourcing, FCA/PRA regulations, or equivalent frameworks.
  • Experience in financial services, payments, or highly regulated environments.
  • Familiarity with supply chain security, concentration risk, AI supplier assessments, and cloud service provider due diligence.
  • Certifications such as CISSP, CISM, CRISC, CISA, CCSP, ISO 27001 Lead Auditor, or equivalent.
  • Experience using Governance, Risk & Compliance (GRC) platforms and third-party risk management tools.

Success Measures

  • Timely completion of third-party security assessments.
  • Effective identification and treatment of supplier security risks.
  • Strong stakeholder satisfaction and onboarding support.
  • Successful support of regulatory, audit, and assurance activities.
  • Continuous improvement of the third-party security risk and supplier assurance programme.

What We Offer

We give you the freedom to be yourself. We are creating an environment of unique individuals – like you – with different perspectives on the financial industry and the world. A diverse and inclusive environment in which everyone’s voice counts and where you can reach your full potential.

We are committed to an inclusive and accessible recruitment process. If you require a reasonable accommodation related to accessibility during your application or interview, please contact accessibility-Sysgroup@swift.com or indicate this in your application.

Please note that this mailbox is not monitored for general recruitment enquiries and should only be used for accessibility or accommodation-related requests (for example related to vision, hearing or neurodiversity).

All requests are confidential and will not affect your candidacy.

Don’t meet every single requirement? At Swift, we are dedicated to building a workplace where people can bring their full selves and ideas to the team, so if you are excited about this role, we encourage you to apply even if you do not meet every single qualification.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Third-Party Security Due Diligence
Cybersecurity Risk Assessment
Supplier Assurance
Cloud Security
ISO 27001
NIST Cybersecurity Framework
DORA Compliance
NIS2 Compliance
SOC Reports
Risk Mitigation
Stakeholder Management
Regulatory Compliance
Data Protection
Supply Chain Security
GRC Platforms
Operational Risk Management

Location

London, England, United Kingdom

Sign up to applySee more jobs like this