About this role
Basic information
Business Line
Enabling Functions
Job Type
Permanent / FTC
Date published
23-Jul-2026
Req #
24023
Job description
Connect to your Industry
As Deloitte UK’s reliance on third parties continues to grow, effective third-party risk management is increasingly critical to protecting the firm from financial, operational, regulatory and reputational risk. Regulators and clients are placing greater scrutiny on how organisations manage their extended supply chain, including the extent to which third parties meet relevant regulatory, contractual and policy requirements.
This role sits within Deloitte’s second line of defence and plays a key part in managing the firm’s Third-Party Risk Management (TPRM) capability. The TPRM programme helps the business identify, assess and manage the risks that arise when Deloitte procures or uses third-party goods and services, whether to support the firm’s operations or the delivery of client engagements.
You will play a pivotal role in helping the business make informed, risk-based decisions about third-party relationships and in strengthening how associated risks are understood, governed and managed across the firm.
Connect to your career at Deloitte
Deloitte drives progress. Using our vast range of expertise, we help our clients' become leaders wherever they choose to compete. To do this, we invest in outstanding people. We build teams of future thinkers, with diverse talents and backgrounds, and empower them all to reach for and achieve more.
What brings us all together at Deloitte? It’s how we approach the thousands of decisions we make every day. How we behave, our beliefs and our attitudes. In other words: our values. Whatever we do, wherever we are in the world, we lead the way, serve with integrity, take care of each other, foster inclusion, and collaborate for measurable impact. These five shared values lead every decision we make and action we take, guiding us to deliver impact how and where it matters most.
Connect to your opportunity
This is a high-impact opportunity to help safeguard Deloitte UK’s Third-Party risk landscape at a time of increasing regulatory scrutiny, growing reliance on external suppliers and continued focus on operational resilience across the supply chain during a period of transformation. You will support our Managed Service in their day-to-day operation in the form of escalation and oversight while helping to deliver enhancements that strengthen how the firm identifies, manages and mitigates third-party risk and transforms our process into keeping up in an ever changing space.
The role is a 12-month fixed-term Manager position within the Third-Party Risk Management team in Quality, Risk and Security (QRS), providing paternity cover while ensuring continuity of business-as-usual delivery and maintaining momentum across strategic priorities.
You will work closely with stakeholders across the business, Extended Enterprise, QRS SMEs and Managed Service teams to support effective delivery, clear governance and continuous improvement across the TPRM programme.
Key Responsibilities
•
Support the development and operationalisation of the TPRM strategy, helping to shape future capability and embed sustainable improvements across the programme.
•
Own and enhance the TPRM Policy and Framework, ensuring it remains clear, proportionate and aligned to regulatory expectations, firm strategy, requirements and good practice.
•
Leading conversations with regulators, clients and internal stakeholders with requests for assurances across our TPRM Programme.
•
Oversee the day-to-day operation of the TPRM framework, ensuring consistent delivery of risk assessment, oversight and governance activities across the firm.
•
Provide oversight of Managed Service, ensuring service quality, effective ways of working and alignment with Deloitte’s TPRM standards.
•
Act as a key escalation point for TPRM-related matters, providing clear risk judgement, practical guidance and timely resolution of issues.
•
Own the development and production of management information, governance reporting and SteerCo outputs, ensuring stakeholders have clear insight into TPRM performance, risks, opportunities and priorities.
•
Use dashboards and performance data to track TPRM delivery, monitor outcomes and identify opportunities to improve the framework and end-to-end Third-Party Lifecycle process.
•
Monitor regulatory developments, internal policy requirements and emerging third-party risk themes, translating insight into practical actions that inform decision-making and strengthen adherence across the business.
•
Drive strategic initiatives on behalf of the program including ESG, critical third parties, nth party risk, external data providers, data and process improvement, ensuring delivery remains aligned to firmwide priorities and emerging risk themes.
•
Engage and collaborate with stakeholders at all levels across the business, QRM, Risk, Procurement, Vendor Management and third parties to support effective third-party risk management outcomes.
•
Set communication and awareness strategies for TPRM and wider supply chain risk management with oversight of documented accessible guidance both internally and externally.
•
Support junior TPRM team members, the Managed Service and the Assistant Manager, providing direction, coaching and oversight to enable effective delivery and continuous improvement.
Connect to your skills and professional experience
Candidates should possess the following skills and experience:
Essential
•
Proven ability to lead on projects, manage competing priorities and deliver high-quality outputs in a fast-paced environment.
•
Proven experience in risk management, ideally within a regulated, professional/financial services or complex corporate environment.
•
Strong understanding of third-party risk management frameworks, good practice and associated governance, oversight and assurance activities.
•
Working knowledge of key third-party risk domains, including information and data security, financial crime, business continuity, operational resilience, ESG, and contractual risk.
•
Ability to apply sound risk judgement, identify material issues and determine when escalation to senior stakeholders is needed.
•
Experience developing, implementing or enhancing risk and control frameworks, processes, policies or governance arrangements.
•
Strong stakeholder management skills, with the ability to influence, challenge and advise senior stakeholders, practitioners and third parties.
•
Excellent written and verbal communication skills, with the ability to explain risk concepts clearly and pragmatically to both technical and non-technical audiences.
•
Strong analytical skills, with the ability to interpret information, draw clear conclusions and translate insight into practical action.
•
Collaborative and delivery-focused approach, with the ability to build strong working relationships across teams, functions and geographies.
•
Ability to operate effectively in ambiguity, balancing risk, commerciality and proportionality when making recommendations.
•
Commitment to continuous improvement, with a rigorous, responsive and outcome-focused approach to delivery.
•
Experience supporting, coaching or guiding junior colleagues, helping to build capability and maintain delivery quality.
Desirable
•
Experience in third-party risk management, procurement, information security, outsourcing, operational resilience or internal risk management.
•
Experience designing, implementing or improving tools, dashboards, workflows or reporting to support third-party risk management.
•
Experience operating in a matrixed, distributed or international team environment, including working with managed service delivery models.
•
Familiarity with professional services, Big 4 or partnership environments.
About security roles for ex-police
Security management, operations and consultancy roles. Years of operational policing — command, incident response, public order — translate directly into corporate security, and employers in this sector actively rate police experience.
See all security jobs in Cardiff →Why this fits a police background — match score 93/100
- Financial crime & fraud
- Incident command & response
- Risk & threat assessment
- Working to legislation & regulation
- Training & coaching delivery
What security roles pay ex-police
Advertised UK ranges, editorial estimates reviewed July 2026
| Security officer (SIA) | £24,000–£29,000 |
| Security supervisor / team leader | £28,000–£34,000 |
| Site / security manager | £38,000–£52,000 |
| Regional / operations security manager | £50,000–£65,000 |