Skip to main content
AfterDuty

Third-Party Resilience Analyst

GB Bank · London, Greater London

Type
Full-time
Posted
3 days ago

Overview

Your incident command and multi-agency coordination experience translates directly to operational resilience and third-party oversight.

About this role

About us

Join one of the UK’s fastest growing and award-winning banks.

We are a team of ambitious, passionate, hardworking, and committed people who have successfully created and launched one of the UK’s newest specialist property finance banks. As we embark on an exciting journey of growth, we are seeking exceptional new team members who possess both the ambition and drive to contribute to our vision. At GB Bank, we believe that career progression should not only be achievable but accelerated, enabling our employees to reach their potential in a supportive and dynamic atmosphere.

Our environment is fast-paced and collaborative, where your efforts are recognised, rewarded, and make a tangible impact. We take pride in fostering and open and inclusive culture that not only embraces change but also encourages continuous learning and professional development.

In this role, you will

The Third-Party Resilience Analyst supports the day-to-day management of GB Bank’s third-party and supplier arrangements, helping to ensure suppliers are properly onboarded, assessed, monitored, evidenced and managed throughout their lifecycle.

This is a predominantly third-party role. The clear majority of time is expected to be spent on supplier records, tiering, due diligence, contracts, service reviews, relationship management, actions, remediation and MI. The role also supports the wider Operational Resilience framework where supplier arrangements underpin Important Business Services, business continuity, scenario testing, crisis response or regulatory evidence. That wider resilience support will be limited to areas where there is a supplier dependency, third-party disruption or evidence requirement, and should always link back to supplier oversight or the resilience of outsourced and third-party services.

Key areas of responsibility

Supplier Records, Tiering & Documentation

  • Maintain accurate supplier records in RiskSmart and the supplier register, including contacts, service description, owner, criticality tier and regulatory overlay attributes.
  • Work with supplier owners to complete the Internal Assessment and prepare a draft criticality tier (1–4) and overlay attributes (outsourcing, Material Outsourcing, MTP, IBS support, customer data, ICT/DORA) for confirmation by the Head of Operational Resilience.
  • Keep supporting templates, checklists, trackers and guidance up to date, flagging where day-to-day practice and the documented procedure have drifted apart.
  • Maintain version control, filing and the audit trail so supplier records are always review-ready.

Onboarding & Due Diligence Support

  • Issue and chase due diligence questionnaires (DD1/DD2, cloud security, data protection, modern slavery, fourth-party checklist) and track completion to the due date.
  • Carry out first-pass review of supplier responses across financial stability, sanctions and screening, cyber and information security, data protection, business continuity and resilience, summarising the key points and flagging gaps for review.
  • Support DPIA screening: issue the supplier information request once the service owner has completed the Bank’s section, chase the return, and record the outcome against the supplier.
  • Coordinate input from Procurement, Legal, Risk, Compliance, InfoSec, Technology, Financial Crime and Operations, and keep the onboarding checklist and evidence pack complete.

Contracts, Renewals & Commercial Administration

  • Maintain the contracts tracker including key dates, notice periods, auto-renewal windows and obligations — and give supplier owners early warning of what is coming up.
  • Check contracts against the Bank’s clause checklist and flag missing protections (audit and regulator access, sub-outsourcing, resilience and BC obligations, incident notification, exit and transition) for review.
  • Support renewals, variations and offboarding by collating information and preparing the paperwork.
  • Support invoice and cost checks, highlighting trends or anomalies worth a closer look.

Ongoing Monitoring, Service Reviews & MI

  • Schedule supplier service reviews in line with tier, prepare the packs, capture notes and actions, and follow up afterwards.
  • Track performance against SLAs and KPIs, chase overdue reviews, assurance and capability assessments, and keep the action and remediation log current.
  • Produce regular MI on the supplier population, tiering, due diligence completion, overdue actions, incidents and emerging themes for onward reporting to ERC and ExCo.
  • Escalate issues promptly and clearly rather than waiting for the next review.

Supplier Incidents & Communications Support

  • Act as an early point of contact for supplier-related issues: log, triage, gather the facts, escalate promptly and track through to resolution.
  • Keep supplier notification, escalation and out-of-hours contact details accurate and tested.
  • Help maintain the contact lists, templates and channels used to communicate during third-party disruption.

Supplier Dependency & Operational Resilience Support

  • Maintain the link between supplier records and the Bank’s Important Business Services, helping to evidence which third parties support IBS delivery and where changes, incidents or new suppliers may require the mapping to be refreshed.
  • Support supplier-related elements of business continuity, exit, workaround and disaster recovery planning, with particular focus on Tier 1 suppliers and services that support critical or important activities.
  • Help gather supplier evidence for scenario tests, BC testing, resilience exercises, incident reviews and self-assessment activity, ensuring supplier dependencies, vulnerabilities, lessons learned and actions are captured and followed through.
  • Support wider operational resilience activity on an as-needed basis where there is a clear supplier dependency, third-party disruption or evidence requirement.

Regulatory Awareness

The Analyst supports the Bank’s third-party oversight and supplier evidence activity, and is expected to work in line with:

  • FCA and PRA expectations for outsourcing and third-party risk management, including SYSC, SS2/21 and PS26/2.
  • How third-party arrangements support the Bank’s Operational Resilience Policy, Important Business Services and impact tolerance evidence.
  • Clear, consistent documentation of supplier oversight activity and audit-ready evidence.
  • UK GDPR and the Data Protection Act 2018 when handling customer or colleague data.
  • Identifying and escalating concentration or dependency concerns within the supplier portfolio.

Full training and support will be provided on the regulatory framework — we are looking for interest and good judgement, not a ready-made expert.

A bit about you

Essential

  • Strong organisation: comfortable juggling multiple suppliers and deadlines, chasing information and keeping trackers accurate without being prompted.
  • High attention to detail — accurate records, spotting inconsistencies and gaps in information.
  • Clear, confident and professional written and verbal communication; you will be emailing suppliers and colleagues at all levels.
  • Confident with Excel (filtering, sorting, basic formulas and pivot tables) and comfortable with Word, PowerPoint and Teams.
  • Curiosity and a genuine willingness to learn about supplier risk, third-party oversight, financial services regulation and how suppliers support operational resilience.
  • Comfortable using everyday AI tools such as Microsoft Copilot to work more efficiently, while building real subject knowledge of your own. We expect AI to help you do the job well, not to do the thinking for you.
  • Sound judgement and discretion when handling confidential or sensitive information.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background — match score 75/100

  • Financial crime & fraud
  • Intelligence & OSINT
  • Incident command & response
  • Working to legislation & regulation

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • £35,000 – £40,000Estimated

    Your risk assessment and incident management skills from policing are directly applicable to this GRC role.

    Posted 3 days ago

  • Full-time

    Your investigative mindset and evidence-handling discipline from policing transfer directly to digital forensics and incident response.

    Posted 4 days ago

  • GRC Manager - 6 month FTC

    Trayport · London

    Full-time

    Your experience managing risk, policy, and regulatory compliance under frameworks like PACE transfers directly to GRC.

    Posted 6 days ago

  • Director - Risk Management

    SHI International · London

    Full-time

    Your threat assessment and multi-agency command experience directly transfer to building enterprise risk frameworks and governance.

    Posted 6 days ago