Software Engineer
We’re a purpose-driven, world-class consumer company putting everyday health in the hands of millions.
Welcome to Haleon. We’re a purpose-driven, world-class consumer company putting everyday health in the hands of millions. In just three years since our launch, we’ve grown, evolved and are now entering an exciting new chapter – one filled with bold ambitions and enormous opportunity. Our trusted portfolio of brands – including Sensodyne®, Panadol®, Advil®, Voltaren®, Theraflu®, Otrivin®, and Centrum® – lead in resilient and growing categories. What sets us apart is our unique blend of deep human understanding and trusted science. Now it’s time to fully realise the full potential of our business and our people. We do this through our Win as One strategy. It puts our purpose – to deliver better everyday health with humanity – at the heart of everything we do. It unites us, inspires us, and challenges us to be better every day, driven by our agile, performance-focused culture.
About the role
The Third-Party Security Risk Analyst is responsible for performing high‑quality third‑party cybersecurity risk assessments and continuous monitoring activities across the full supplier lifecycle, including Onboarding, Due Diligence, Contracting, Continuous Monitoring, and Offboarding.
The role conducts inherent risk reviews, detailed due‑diligence assessments, evaluates supplier controls, identifies security gaps, and works with suppliers and internal teams to define remediation plans. The Analyst also supports ongoing monitoring activities, including periodic reassessments, threat‑driven reviews, incident follow‑ups, and supplier offboarding validation.
The Analyst works closely with the Third-Party Security Risk Operations Lead to ensure consistent execution of methodologies, adherence to SLAs, high‑quality documentation, and accurate risk reporting.
Role Responsibilities
Execute TPSRM activities across the full lifecycle, including onboarding risk segmentation, due diligence assessments, contracting security review, continuous monitoring tasks, and supplier offboarding checks.
Perform detailed third-party cybersecurity risk assessments, analyzing supplier responses, evaluating inherent and residual risks, validating supporting evidence, and documenting findings in accordance with TPSRM methodology.
Identify security gaps and support remediation governance, including proposing remediation actions, tracking supplier commitments, validating closure evidence, and escalating overdue or high-risk items.
Support continuous monitoring, conducting periodic reassessments, reviewing supplier security alerts/events, following up on incidents, and supporting onsite visit preparation where required.
Coordinate operational interactions with suppliers, business requestors, Procurement, TPRM, Legal, and security engineering teams, ensuring that assessments and risk decisions are completed efficiently and accurately.
Posted August 6, 2026