Job Summary
This role could be based in India or Poland. When you start the application process you will be presented with a drop-down menu showing all countries, please ensure that you only select a country where the role is based
The Client & Third Party Security (CTPS) team is an integral part of the Bank's Group Threat Management (GTM) within the Information & Cyber Security (ICS) division. Our mandate focuses on protecting the Bank against emerging cyber threats through deep external ecosystem insights, including third-party vendors, partners, and clients. CTPS is pivotal in managing third-party cyber risk lifecycles — from assessments, contractual control, continuous monitoring, incident investigation, to remediation.
The Lead, Third Party Governance, Reporting & Performance will spearhead a dedicated team ensuring the delivery of comprehensive operational performance oversight, management information reporting, and governance committee communications. This leadership role demands precision in articulating performance metrics, key control status, risk assessments, and escalation of critical findings to promote informed risk-based decision making.
You will oversee timely and consistent reporting across global business units and governance structures, guaranteeing transparent visibility of third party cyber risks, operational performance compared to agreed standards, and actionable insights to inform stakeholders and drive continuous improvement. This role is positioned at the confluence of security, risk management, and operational excellence, offering a unique leadership opportunity to influence and enhance supply chain security at a global scale.
Key Responsibilities
Strategy
• Transform CTPS’ approach to governance, reporting and performance, ensuring it aligns to the Group’s wider business strategy, risk appetite and third party security risk priorities.
• Shape the future-state approach for operational performance management, KPI reporting, key control reporting and governance engagement across CTPS.
• Drive the evolution of CTPS reporting from retrospective performance updates towards more forward-looking, insight-led management information that supports risk-based decision-making.
• Contribute to strategic transformation initiatives, including improved metric governance, reporting automation, control reporting maturity and integration with centralised TPRM tooling and processes.
• Identify opportunities to simplify, standardise and strengthen reporting across country, regional, business, function and Group governance forums.
Business
• Maintain awareness and understanding of the wider business, regulatory, operational and third party risk environment in which the Group operates.
• Ensure senior stakeholders receive accurate, timely, action-oriented and business-relevant insight into CTPS operational performance, KPI trends, control effectiveness and residual risk exposure.
• Support business and function stakeholders by clearly articulating how third party cyber security performance impacts risk acceptance, operational resilience, client outcomes and regulatory confidence.
• Deliver high-quality reporting outputs that enable country, regional and Group committees to understand performance against thresholds, areas of deterioration and required management actions.
• Balance competing reporting demands across businesses, functions, markets and governance forums while maintaining consistency, quality and accuracy of CTPS messaging.
Processes
• Responsible for overseeing the CTPS operational performance reporting process, including calculation, validation, quality assurance and submission of KPIs, KRIs, key controls and supporting commentary.
• Ensure metric definitions, calculation methodologies, data sources, assumptions, exclusions and thresholds are documented, understood and applied consistently.
• Supervise the production of governance reporting packs, dashboards, committee updates and management information across relevant CTPS processes.
• Ensure performance issues, threshold breaches, overdue actions and deteriorating trends are identified, recorded, escalated and tracked through agreed processes.
• Maintain repeatable, controlled and auditable reporting processes that support effective oversight under the Operational Risk Framework.
• Partner with process owners to ensure operational reporting accurately reflects delivery performance, control outcomes, remediation progress and residual risk.
People & Talent
• Lead through example by building a culture of accuracy, ownership, transparency, constructive challenge and continuous improvement across the Governance, Reporting & Performance team.
• Set clear expectations for reporting quality, timeliness, risk judgement, attention to detail and stakeholder management.
• Ensure team members are appropriately trained and developed in data analysis, KPI calculation, control reporting, governance writing, risk articulation and committee engagement.
• Provide effective supervision, coaching and quality assurance to ensure critical reporting activities are performed to the required standard.
• Employ, engage and retain high-quality people, with appropriate succession planning for key reporting, governance and performance management roles.
• Review team structure, capacity plans and workload allocation to ensure the team can meet increasing reporting demand and governance commitments.
• Set and monitor objectives for direct reports, provide regular feedback and assess performance in line with agreed responsibilities and outcomes.
Risk Management
• Identify, assess, monitor and escalate risks arising from deteriorating CTPS operational performance, KPI breaches, control weaknesses, reporting inaccuracies or delayed remediation.
• Interpret performance and control data to identify key risk themes, emerging trends, systemic issues and areas requiring management attention.
• Support the development and tracking of action plans to remediate performance issues, control gaps, overdue actions or reporting deficiencies.
• Ensure operational performance reporting clearly links metric deterioration, threshold breaches and control outcomes to the Bank’s third party security residual risk profile.
• Provide evidence-based challenge to process owners where commentary, metrics or action plans do not adequately explain or address the underlying risk.
• Support responsibilities under the Group’s Risk Management Framework by ensuring CTPS performance and control reporting is accurate, timely, complete and appropriately escalated.
• Ensure senior management has a clear view of where performance remains within tolerance, where risk is increasing and where management intervention is required.
Governance
• Own the delivery of CTPS governance reporting across country, regional, business, function and Group risk committees.
• Ensure reporting is aligned to relevant governance standards, committee expectations, regulatory requirements and the Group’s risk management framework.
• Assess the effectiveness of CTPS governance reporting arrangements and drive improvements where reporting does not provide sufficient oversight, transparency or challenge.
• Ensure consistent articulation of CTPS’ operational performance, KPI position, key control outcomes, remediation progress and residual risk across governance forums.
• Support senior leaders with committee preparation, including briefing materials, key messages, anticipated challenge points and clear articulation of management actions.
• Maintain awareness and understanding of the regulatory framework relevant to third party security risk, operational resilience, control effectiveness and management information.
• Escalate material reporting issues, control concerns, threshold breaches or unresolved performance deterioration through appropriate CTPS, ICS and Group governance channels.
• Partner with Risk, Control, SCM, TPRM and CTPS stakeholders to ensure governance reporting supports effective oversight, decision-making and accountability.
Regulatory & Business Conduct
• Display exemplary conduct and live by the Group’s Values and Code of Conduct.
• Take personal responsibility for embedding the highest standards of ethics, including regulatory and business conduct, across Standard Chartered Bank. This includes understanding and ensuring compliance with, in letter and spirit, all applicable laws, regulations, guidelines and the Group Code of Conduct.
• Effectively and collaboratively identify, escalate, mitigate and resolve risk, conduct and compliance matters.
Key stakeholders
• Head, Client & Third Party Security (and wider team)
• Global Head, Group Threat Management
• Technology & Operations Third Party Risk Management Utility
• Supply Chain Management
• Risk stakeholders across 1st, 2nd and 3rd lines of defence
Other Responsibilities
• Embed Here for good and Group’s brand and values in the CTPS team
Skills and Experience
Candidates should demonstrate comprehensive expertise in the following areas:
- Exceptional verbal and written communication skills, capable of distilling complex technical data into accessible insights for diverse audiences.
- Strong governance and reporting acumen, with a proven track record of overseeing operational performance metrics, key control monitoring, and management information systems.
- Thorough understanding of risk management principles, specifically related to third party cyber security risks and the broader cybersecurity risk landscape.
- Experienced in third party risk management frameworks and methodologies, including assessment, monitoring, and incident escalation processes.
- Proficient in business intelligence, management information (MI), and dashboarding tools, enabling effective visualization and communication of performance data.
- Advanced stakeholder engagement and relationship management capabilities, vital for successful collaboration across multiple business units, geographies, and governance levels.
- Candidates will have minimum experience of 8+ years in financial services or similarly regulated industries, familiarity with cyber security and third party risk management technologies, and the ability to lead cross-functional teams through complex transformation initiatives.
Qualifications
Essential Qualification:
- Fluency in English is required to effectively communicate in this global role.
- Desirable qualifications include relevant professional certifications in risk management, cyber security, data analytics, or governance (such as CRISC, CISM, CGEIT, or equivalent), as well as prior experience in a leadership capacity within third party risk or information security functions.
About Standard Chartered
We're an international bank, nimble enough to act, big enough for impact. For more than 170 years, we've worked to make a positive difference for our clients, communities, and each other. We question the status quo, love a challenge and enjoy finding new opportunities to grow and do better than before. If you're looking for a career with purpose and you want to work for a bank making a difference, we want to hear from you. You can count on us to celebrate your unique talents and we can't wait to see the talents you can bring us.
Our purpose, to drive commerce and prosperity through our unique diversity, together with our brand promise, to be here for good are achieved by how we each live our valued behaviours. When you work with us, you'll see how we value difference and advocate inclusion.
Together we:
- Do the right thing and are assertive, challenge one another, and live with integrity, while putting the client at the heart of what we do
- Never settle, continuously striving to improve and innovate, keeping things simple and learning from doing well, and not so well
- Are better together, we can be ourselves, be inclusive, see more good in others, and work collectively to build for the long term
What we offer
In line with our Fair Pay Charter, we offer a competitive salary and benefits to support your mental, physical, financial and social wellbeing.
- Core bank funding for retirement savings, medical and life insurance, with flexible and voluntary benefits available in some locations.
- Time-off including annual leave, parental/maternity (20 weeks), sabbatical (12 months maximum) and volunteering leave (3 days), along with minimum global standards for annual and public holiday, which is combined to 30 days minimum.
- Flexible working options based around home and office locations, with flexible working patterns.
- Proactive wellbeing support through Unmind, a market-leading digital wellbeing platform, development courses for resilience and other human skills, global Employee Assistance Programme, sick leave, mental health first-aiders and all sorts of self-help toolkits
- A continuous learning culture to support your growth, with opportunities to reskill and upskill and access to physical, virtual and digital learning.
- Being part of an inclusive and values driven organisation, one that embraces and celebrates our unique diversity, across our teams, business functions and geographies - everyone feels respected and can realise their full potential.