SWIFT logo

Third Party Security Due Diligence Lead

SWIFT

On-site
London, UK
Full-time
Senior
7+ yrs
Salary not listedPosted 1h ago

Real job — pulled straight from SWIFT’s careers page · Verified September 4, 2026 · No reposts.

Job description

SWIFT is hiring a Third Party Security Due Diligence Lead — a full-time, based in London, UK role. Apply directly on SWIFT's careers page below.

Third Party Security Due Diligence Lead

Location: London, United Kingdom

Job Description

ABOUT US

We’re the world’s leading provider of secure financial messaging services, headquartered in Belgium. We are the way the world moves value – across borders, through cities and overseas. No other organisation can address the scale, precision, pace and trust that this demands, and we’re proud to support the global economy. 

We’re unique too. We were established to find a better way for the global financial community to move value – a reliable, safe and secure approach that the community can trust, completely. We’re always striving to be better and are constantly evolving in an ever-changing landscape, without undermining that trust. Five decades on, our vibrant community reflects the complexity and diversity of the financial ecosystem. We innovate diligently, test exhaustively, then implement fast. In a connected and exciting era, our mission has never been more relevant. Swift now has a presence in 200+ countries and legal territories to serve a community of more than 12,000 banks and financial institutions.

Job Summary

Lead the Third-Party Security Due Diligence function for SWIFT, ensuring that third-party suppliers, technology providers, cloud services, and strategic partners are assessed, onboarded, and monitored in line with SWIFT's security, resilience, regulatory, and operational risk requirements.

The role is responsible for managing the end-to-end security due diligence lifecycle, providing expert risk-based assessments of third parties, driving remediation activities, and supporting compliance with applicable regulatory frameworks including DORA, NIS2, ISO 27001, and SWIFT's internal security standards.

Key Responsibilities

Security Due Diligence & Risk Assessment

  • Lead the end-to-end third-party security due diligence process, from supplier onboarding through ongoing assurance, reassessment, and offboarding.
  • Perform comprehensive security risk assessments of third parties, evaluating cybersecurity, resilience, data protection, cloud security, supply chain security, and operational risk exposures.
  • Assess supplier security capabilities through review of questionnaires, policies, certifications, audit reports, penetration testing results, independent assurance reports, and supporting evidence.
  • Evaluate control effectiveness against recognised frameworks and standards including ISO 27001, NIST Cybersecurity Framework, SOC reports, DORA, and relevant SWIFT security requirements.
  • Identify security gaps, residual risks, and compensating controls, providing clear risk ratings and recommendations to stakeholders.

Supplier Assurance & Continuous Monitoring

  • Establish and maintain a risk-based supplier assurance programme for critical and high-risk third parties.
  • Drive remediation activities with suppliers and internal stakeholders to address identified security weaknesses and control deficiencies.
  • Support ongoing monitoring activities, including reassessments, threat monitoring, breach notifications, security events, and changes in supplier risk profiles.
  • Monitor supplier compliance with contractual security obligations and regulatory requirements.

Stakeholder Management & Advisory

  • Partner closely with Procurement, Legal, Technology, Architecture, Operational Risk, Compliance, Data Protection, and Business teams to support supplier onboarding and risk decisions.
  • Provide expert guidance on third-party security risks, risk acceptance decisions, mitigating controls, and supplier onboarding requirements.
  • Present security due diligence outcomes, key risks, and recommendations to governance forums, senior management, and risk committees.
  • Act as the subject matter expert for third-party security risk management and supplier assurance activities across the organisation.

Governance & Regulatory Compliance

  • Contribute to the development and continuous improvement of SWIFT's Third-Party Security Risk Management and Supplier Assurance frameworks, methodologies, standards, and procedures.
  • Ensure due diligence activities align with regulatory expectations and industry best practices, including DORA, NIS2, GDPR, EBA Guidelines, and relevant financial sector requirements.
  • Support internal audits, regulatory reviews, and external examinations relating to third-party security risk management.
  • Develop management reporting, KPIs, KRIs, and board-level metrics to demonstrate programme effectiveness and risk exposure.

Qualifications & Experience

Essential

  • Bachelor's degree in Information Security, Cybersecurity, Computer Science, Risk Management, Information Systems, or a related discipline.
  • Minimum 7 years' experience in cybersecurity, third-party security risk management, supplier assurance, security assurance, or technology risk within financial services, critical infrastructure, or a highly regulated environment.
  • Strong understanding of third-party security risk management practices and supplier assurance methodologies.
  • Practical experience conducting security assessments of cloud providers, SaaS vendors, technology suppliers, and outsourced service providers.
  • Strong understanding of security frameworks and standards including ISO 27001, NIST, SOC 1/2, CIS Controls, and cloud security best practices.
  • Experience evaluating security controls across identity management, network security, encryption, vulnerability management, incident response, resilience, data protection, and secure software development.
  • Excellent risk analysis, stakeholder management, and report-writing skills.
  • Ability to communicate complex security risks clearly to technical and non-technical audiences, including senior executives.

Desirable

  • Experience supporting regulatory requirements such as DORA, NIS2, EBA Guidelines on Outsourcing, FCA/PRA regulations, or equivalent frameworks.
  • Experience in financial services, payments, or highly regulated environments.
  • Familiarity with supply chain security, concentration risk, AI supplier assessments, and cloud service provider due diligence.
  • Certifications such as CISSP, CISM, CRISC, CISA, CCSP, ISO 27001 Lead Auditor, or equivalent.
  • Experience using Governance, Risk & Compliance (GRC) platforms and third-party risk management tools.

Success Measures

  • Timely completion of third-party security assessments.
  • Effective identification and treatment of supplier security risks.
  • Strong stakeholder satisfaction and onboarding support.
  • Successful support of regulatory, audit, and assurance activities.
  • Continuous improvement of the third-party security risk and supplier assurance programme.

What we offer

We give you the freedom to be yourself. We are creating an environment of unique individuals – like you – with different perspectives on the financial industry and the world. A diverse and inclusive environment in which everyone’s voice counts and where you can reach your full potential.

We are committed to an inclusive and accessible recruitment process. If you require a reasonable accommodation related to accessibility during your application or interview, please contact accessibility-Sysgroup@swift.com or indicate this in your application.

Please note that this mailbox is not monitored for general recruitment enquiries and should only be used for accessibility or accommodation-related requests (for example related to vision, hearing or neurodiversity).

All requests are confidential and will not affect your candidacy.

Don’t meet every single requirement? At Swift, we are dedicated to building a workplace where people can bring their full selves and ideas to the team, so if you are excited about this role, we encourage you to apply even if you do not meet every single qualification.

Get Third Party Security Due Diligence Lead jobs like this

New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.

Email me new jobs
Arctic Wolf logo

Triage Cybersecurity Analyst

Frankfurt, DEU
✓ From careers page· 16m ago
Arctic Wolf logo

Cyber Security Werkstudent

Frankfurt, Hessen
✓ From careers page· 16m ago
Space Dynamics Laboratory logo

Multidisciplinary Systems Engineer

$159k–$210k
✓ From careers page· 17m ago
Space Dynamics Laboratory logo

Multidisciplinary Systems Engineer

$176k–$225kRemote · US-eligible
✓ From careers page· 17m ago

Frequently asked questions

What skills are required for Third Party Security Due Diligence Lead at SWIFT?

The required skills for Third Party Security Due Diligence Lead at SWIFT include: Cybersecurity, ISO 27001, GDPR, CISSP, CISM, CISA.

What is the seniority level for Third Party Security Due Diligence Lead at SWIFT?

Third Party Security Due Diligence Lead at SWIFT is a Senior level position.

How do I apply for Third Party Security Due Diligence Lead at SWIFT?

You can view the full description and apply for Third Party Security Due Diligence Lead at SWIFT on EchoJobs: https://echojobs.io/job/swift-third-party-security-due-diligence-lead-kyd2k.