Job Summary
This role could be based in India and Poland. When you start the application process you will be presented with a drop down menu showing all countries, please ensure that you select a country where the role is based.
Client & Third Party Security (CTPS) is a specialist team within the Bank’s Group Threat Management (GTM) function, forming part of Information & Cyber Security (ICS). The team plays a critical role in delivering the Group’s ICS Strategy by helping build a comprehensive, threat-focused understanding of its external ecosystem, including third party vendors, key partners, and clients. CTPS helps protect the Bank by managing third-party cyber risk end-to-end through delivery of Third Party Security Assessments, contractual control oversight, third party continuous monitoring, detection, analysis and investigation of third party incidents, and targeted remediation of third party security observations. As the threat landscape continues to evolve, CTPS is going through an exciting transformation to become more threat-led, risk-focused and efficient — strengthening supply chain security capabilities and improving detection and remediation of interconnected third-party risks.
The Lead, Third Party Continuous Monitoring will be responsible for leading the Bank’s third party continuous monitoring function, ensuring the proactive identification, assessment, escalation and management of cyber security alerts across the organisation’s third party ecosystem. Sitting within CTPS, the role will oversee a team of analysts responsible for monitoring external attack surface intelligence, threat signals and other risk indicators to detect emerging threats, material changes in third party security posture and potential areas of elevated third party residual risk.
The role will work closely with teams responsible for third party security assessments, incident investigations, remediation of third party control gaps, threat intelligence, Supply Chain Management and broader Third Party Risk Management stakeholders. It will ensure monitoring outputs are investigated in a timely and consistent manner, significant risks are escalated appropriately, and insights are used to inform reassessments, remediation priorities, incident response activity and wider control uplift.
The role will be accountable for maintaining a robust, intelligence-led continuous monitoring capability aligned to industry good practice, regulatory expectations and the Bank’s ICS strategy. This includes driving improvements to monitoring tools, data sources, alerting logic, operating procedures, reporting and governance..
Key Responsibilities
Strategy
• Lead the development and implementation of CTPS’ third party continuous monitoring maturity roadmap, aligned to the Bank’s ICS strategy and the objective of building a more dynamic, intelligence-led and proactive third party security risk capability.
• Shape the future-state continuous monitoring model for the Bank’s third party ecosystem, ensuring monitoring coverage is risk-based, scalable and focused on vendors that present the greatest potential exposure.
• Drive the evolution of continuous monitoring from periodic external attack surface review to a more integrated capability that informs assessments, reassessments, incident investigations, control remediation and residual risk decisions.
• Identify and implement opportunities to enhance the Bank’s security posture through improved monitoring tooling, data sources, alerting, analytics, automation and intelligence-led prioritisation.
• Contribute to strategic initiatives across CTPS and TPRM that strengthen third party cyber resilience and improve the Bank’s ability to detect and respond to emerging supplier risks.
Business
• Maintain awareness and understanding of the Group’s business strategy, operating model, third party ecosystem, critical dependencies and wider cyber, technology, geopolitical and market environment.
• Ensure continuous monitoring outputs provide timely and actionable insight into material changes in vendor security posture, external attack surface exposure and emerging areas of third party cyber risk.
• Support business continuity by enabling earlier identification and escalation of cyber risks that may impact critical suppliers, services, markets, clients or operational resilience.
• Partner with third party security assessment, risk remediation, incident investigation, SCM and business-facing teams to ensure monitoring insights are translated into appropriate risk management actions.
• Provide clear reporting and risk articulation to senior stakeholders on significant monitoring findings, trends, exposure themes, remediation progress and residual risk implications.
Processes
• Responsible for leading and supervising the third party continuous monitoring process, including detection, triage, assessment, escalation, tracking and closure of monitoring findings.
• Oversee monitoring of external attack surface intelligence and other risk indicators to identify emerging threats, vulnerabilities, exposed services, control deterioration and material changes in vendor security posture.
• Define and maintain operating procedures for alert review, investigation, prioritisation, escalation, evidence capture and follow-up with relevant CTPS, TPRM and business stakeholders.
• Ensure significant monitoring findings are assessed consistently and linked to appropriate downstream actions, including targeted reassessments, remediation plans, incident investigations or governance escalation.
• Develop and maintain reporting processes, dashboards and management information that provide visibility of monitoring coverage, finding volumes, risk themes, ageing, remediation status and control trends.
• Regularly review and improve continuous monitoring processes, tooling configuration, alert thresholds and data quality controls to ensure the capability remains effective, efficient and aligned to industry good practice.
People & Talent
• Lead, manage and develop a team of analysts responsible for third party continuous monitoring, external attack surface analysis and investigation of monitoring findings.
• Lead through example by promoting a culture of urgency, analytical rigour, ownership, collaboration, continuous improvement and evidence-based risk decision-making.
• Set clear expectations for quality, timeliness, investigation standards, documentation, stakeholder engagement and escalation discipline across continuous monitoring activities.
• Ensure team members receive appropriate training and development in external attack surface management, vulnerability analysis, threat intelligence, third party security risk and risk reporting.
• Review team structure, capacity and workload plans to ensure the function can support increasing monitoring demand, expanding vendor coverage and evolving threat-led requirements
Risk Management
• Identify, assess, monitor and support mitigation of cyber security risks arising from the Bank’s third party ecosystem, with a focus on external attack surface exposure, vulnerability indicators, emerging threats and control deterioration.
• Provide risk-based recommendations to prioritise remediation activity, reassessment triggers, incident investigation support and escalation of significant third party exposures.
• Work with third party assessment and control gap remediation teams to ensure continuous monitoring insights inform control uplift, issue management and residual risk treatment.
• Provide effective challenge where vendor remediation plans, risk acceptances or business decisions do not sufficiently address the underlying cyber risk exposure.
• Identify systemic themes across monitoring findings and recommend actions to reduce recurring third party security weaknesses across the vendor population.
Governance
• Provide oversight and direction for the Bank’s third party continuous monitoring capability, ensuring monitoring arrangements, escalation pathways, operating procedures and reporting remain effective.
• Ensure continuous monitoring outputs are aligned to CTPS governance requirements, ICS risk appetite, third party security standards and relevant regulatory expectations.
• Provide clear, evidence-based updates to governance forums on monitoring trends, key risk indicators, material findings, remediation progress and residual risk implications.
• Maintain awareness and understanding of the regulatory framework relevant to third party security risk, operational resilience, cyber resilience, outsourcing and technology risk management.
• Ensure monitoring outputs are appropriately documented, auditable and suitable for senior management review, control testing, audit, regulatory engagement or post-incident analysis.
Regulatory & Business Conduct
• Display exemplary conduct and live by the Group’s Values and Code of Conduct.
• Take personal responsibility for embedding the highest standards of ethics, including regulatory and business conduct, across Standard Chartered Bank. This includes understanding and ensuring compliance with, in letter and spirit, all applicable laws, regulations, guidelines and the Group Code of Conduct.
• Effectively and collaboratively identify, escalate, mitigate and resolve risk, conduct and compliance matters.
Key stakeholders
• Head, Client & Third Party Security (and wider team)
• Cyber Intelligence Centre
• Threat Assessment & Countermeasures
• Global Head, Group Threat Management
• Technology & Operations Third Party Risk Management Utility
• Supply Chain Management
• Risk stakeholders across 1st, 2nd and 3rd lines of defence
Other Responsibilities
• Embed Here for good and Group’s brand and values in the CTPS team
Skills and Experience
- Excellent Communication: Proficient in articulating complex cyber risk concepts clearly to technical and non-technical stakeholders across writing, presentation and verbal communication.
- External Attack Surface Management: Experience in identifying and monitoring exposed vulnerabilities and risks in third party digital ecosystems.
- Continuous Monitoring Operations: Proven ability managing sustained surveillance activities, including alert triage, investigation workflows and escalation procedures.
- Vulnerability Risk Assessment: Skilled in assessing the impact and likelihood of cyber vulnerabilities to prioritise mitigation efforts effectively.
- Third Party Risk Management: Deep understanding of managing cyber risks introduced by vendors, suppliers and partners aligned to regulatory and industry standards.
- Cyber Threat Intelligence Integration: Ability to leverage threat intelligence sources to enhance monitoring accuracy and incident response.
- Proficiency with Monitoring Tooling and Automation: Hands-on experience with security monitoring platforms, data analytics tools, and automation to streamline detection and response.
- Stakeholder Management: Experience building collaborative relationships and influencing across diverse teams and leadership levels.
Qualifications
- Fluency in English, both written and spoken, is essential to effectively liaise with global stakeholders and teams.
- Advanced certifications in cyber security such as CISSP, CISM, or Certified Third Party Risk Professional (CTPRP) are highly desirable.
- Relevant academic background in computer science, information security, or related disciplines is advantageous.
- Continuous professional development and participation in cyber security forums or workshops is encouraged to stay current with emerging industry practices.
- 5+ years of revelant experience in Third Party Continuous Monitoring/ Cyber Security.
About Standard Chartered
We're an international bank, nimble enough to act, big enough for impact. For more than 170 years, we've worked to make a positive difference for our clients, communities, and each other. We question the status quo, love a challenge and enjoy finding new opportunities to grow and do better than before. If you're looking for a career with purpose and you want to work for a bank making a difference, we want to hear from you. You can count on us to celebrate your unique talents and we can't wait to see the talents you can bring us.
Our purpose, to drive commerce and prosperity through our unique diversity, together with our brand promise, to be here for good are achieved by how we each live our valued behaviours. When you work with us, you'll see how we value difference and advocate inclusion.
Together we:
- Do the right thing and are assertive, challenge one another, and live with integrity, while putting the client at the heart of what we do
- Never settle, continuously striving to improve and innovate, keeping things simple and learning from doing well, and not so well
- Are better together, we can be ourselves, be inclusive, see more good in others, and work collectively to build for the long term
What we offer
In line with our Fair Pay Charter, we offer a competitive salary and benefits to support your mental, physical, financial and social wellbeing.
- Core bank funding for retirement savings, medical and life insurance, with flexible and voluntary benefits available in some locations.
- Time-off including annual leave, parental/maternity (20 weeks), sabbatical (12 months maximum) and volunteering leave (3 days), along with minimum global standards for annual and public holiday, which is combined to 30 days minimum.
- Flexible working options based around home and office locations, with flexible working patterns.
- Proactive wellbeing support through Unmind, a market-leading digital wellbeing platform, development courses for resilience and other human skills, global Employee Assistance Programme, sick leave, mental health first-aiders and all sorts of self-help toolkits
- A continuous learning culture to support your growth, with opportunities to reskill and upskill and access to physical, virtual and digital learning.
- Being part of an inclusive and values driven organisation, one that embraces and celebrates our unique diversity, across our teams, business functions and geographies - everyone feels respected and can realise their full potential.