Information Security - Risk Analyst (Third Party Risk)
Maritime and Coastguard Agency
- Department
- Maritime and Coastguard Agency
- Location
- Southampton
- Openings
- 1 post
- Grade
- HEO
- Salary
- £37,090
- Closing
- 21 days left
- Profession
- Operational Delivery, Finance
- Contract
- Permanent
- Security clearance
- SC
- Working pattern
- Flexible working, Full-time, Job share, Part-time
Job summary
Can you spot security risks before they put vital information and services at risk?
Do you thrive on turning third-party security issues into clear, practical recommendations?
Have you got the skills to influence stakeholders and strengthen security across a diverse supplier network?
If so, we’d love to hear from you!
The Maritime and Coastguard Agency (MCA) is seeking an Information Security – Risk Analyst (Third-Party Risk) to join their team. Information Security is the practice of assuring the security, confidentiality, integrity and availability of information, assets, technology, people, systems and services throughout the MCA and its suppliers.
The role of the Information Security team is to contribute to and influence the Information Security strategy and function through internal consultation, evaluation, and assessment. The team promotes security best practice and ensures that information security requirements are fully considered and implemented as part of the design throughout projects and operational processes.
Joining our department comes with many benefits, including:
- Employer pension contribution of 28.97% of your salary. Read more about Civil Service Pensions here
- 25 days annual leave, increasing by 1 day each year of service (up to a maximum of 30 days annual leave), plus 8 bank holidays and a privilege day for the King’s birthday
- Flexible working options where we encourage a great work-life balance.
Read more in the Benefits section below!
Find out more about what it's like working at: Maritime and Coastguard Agency - Department for Transport Careers
What they’re looking for
- Required experience:
- To be successful in this role you will need to have the following experience:
- Demonstrates the ability to apply security, risk management or assurance principles to identify, assess and communicate risks
- Ability to communicate security and risk-related information to both technical and non-technical stakeholders.
- Able to use information from a range of sources to support risk assessment, decision-making and governance activities.
- Experience of building relationships and influencing stakeholders, working collaboratively and inclusively, sharing information and knowledge to achieve shared outcomes.
- Additional Information
- Operational Delivery Profession (ODP) is the largest and most diverse professional community across the Civil Service. Many of us will have an association with several professional communities or specialisms, ODP applies to all public facing roles / or a role that is primarily aligned to supporting the work of those with public facing roles. All critical to the delivery of UK public services.
- https://www.youtube.com/watch?v=gkR_okX2T1U
- Working hours, office attendance and travel requirements
- Full time roles consist of 37 hours per week.
- Whilst we welcome applications from those looking to work with us on a part time basis, there is a business requirement for the successful candidate to be able to work at least 30 hours per week.
- This role is suitable for hybrid working, which is a non-contractual arrangement where a combination of workplace and home-based working can be accommodated subject to business requirements.
- The expectation at present is a minimum of 60% of your working time a month will be spent at either your designated workplace (one of the locations cited in the advert) or, when required for business reasons, in another office/work location/visiting stakeholders. Your designated workplace will be your contractual place of work. There may be occasions where you are required to attend above the minimum expectation.
- Some UK travel required, including overnight stays.
- If you have a question about hybrid working, part time/job share hours, flexible working, travelling for work, or require a reasonable adjustment, please contact the Vacancy Holder during the recruitment process to avoid possible disappointment later in the process should your working arrangements not be compatible with the requirements of the role (see below for contact details).
- Visa Sponsorship
- Please note that we will only offer sponsorship for a skilled worker visa where a role has been deemed to be business critical. This role does not meet that category, and we will not sponsor a visa. Therefore, this role is not open to applications from those who require sponsorship – candidates must ensure they have the appropriate right to work in the UK before applying. Should you apply for this role and be found to require sponsorship, your application will be rejected and any provisional offer of employment withdrawn.
Behaviours you’ll be assessed on
This advert says the panel will score you against these behaviours at HEO level. Each one links to worked examples.
Job description
As an Information Security - Risk Analyst (Third-Party Risk) you will help safeguard the MCA’s information and assets by assessing suppliers against security requirements and identifying, communicating and escalating third-party risks. You will work with technical and non-technical stakeholders to support informed, risk-based decisions, ongoing supplier reviews and proportionate remediation plans, while helping to improve third-party risk processes, reporting and governance.
This role is aligned to the skills set out in the Government Security Professions Framework
Your responsibilities will include, but aren’t limited to:
- Conducting proportionate security risk assessments for all suppliers participating in tender processes and communicating findings and recommendations to stakeholders.
- Interpreting third‑party security risks and communicating clearly and proportionately with technical and non‑technical stakeholders.
- Identifying and escalating third-party security risks in line with organisational risk appetite.
- Working with Protective Security, Contract Management and Procurement to support supplier reviews and proportionate remediation plans the reduce supply chain risks.
- Supporting the Third-Party Risk Specialist to develop KPIs for monitoring and reporting third-party risk.
- Supporting the effective operation of the Third‑Party Risk Operational Security Working Group by coordinating meetings, capturing decisions and actions, and supporting follow‑
- Contributing to continuous improvement of Third-Party Risk Management processes and deputising for the Third-Party Risk Specialist in internal and external forums
- Working flexibly with the Protective Security team, providing cover where required
Nationality requirements
This job is broadly open to the following groups:
- UK nationals
- nationals of the Republic of Ireland
- nationals of Commonwealth countries who have the right to work in the UK
- nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS) (opens in a new window)
- nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS)
- individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020
- Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service
Further information on nationality requirements (opens in a new window)
Selection process
This vacancy is using Success Profiles (opens in a new window), and will assess your Behaviours and Experience.
How to apply:
Our selection process ensures a comprehensive assessment of each applicant's skills, and potential fit within our organisation.
The selection process for this role will be:
Stage 1: Sift of CV and personal statement
Stage 2: Interview
You must be successful at each stage to progress to the next stage.
Stage 1: Sift
At sift, you will be assessed against the following Success Profile elements:
- Experience – you will be asked to provide a CV (unlimited wordcount) and personal statement (500-word count). Please provide evidence of your Experience of the following: Demonstrates the ability to apply security, risk management or assurance principles to identify, assess and communicate risks
- Experience of building relationships and influencing stakeholders working collaboratively and inclusively, sharing information and knowledge to achieve shared outcomes.
Should a large number of applications be received, an initial sift may be conducted using the lead Success Profile element, Demonstrates the ability to apply security, risk management or assurance principles to identify, assess and communicate risks.
Candidates who pass the initial sift may be progressed to a full sift or progressed straight to assessment/interview.
The sift will take place week commencing 19/10/2026.
Stage 2: Interview
At interview stage, you will be assessed against the following Success Profile elements:
- Behaviours Making Effective Decisions
- Communicating and Influencing
- Working Together
- Delivering at Pace
- Experience
You will also be required to create and deliver a presentation to assess Experience and the Behaviour Making Effective Decisions. Guidance will be provided if you are invited to interview.
The interviews will take place week commencing 26/10/2026.
This interview will be conducted in person at our Southampton office (Spring Place, 105 Commercial Road, Southampton, SO15 5EG). Further details will be provided to you should you be selected for interview.
You can find out more about our hiring process, how to apply, and application and interview guidance on our careers site (opens in a new window).
Please note that we will try to meet the dates set out in the advert. There may be occasions when these dates will change.
Further information on the selection process
Feedback on your application can only be provided if you attend an interview or assessment.
Adverts with a reserve list
We will also hold a 12 month reserve list for this role, which may lead to potential opportunities beyond the role you applied for. You can read more about our reserve lists here.
Appointments for this position will be made in order of merit. If you are successful in the selection process but there are no further available posts for the advertised role, you may be contacted to discuss an offer for a lower graded role (with similar experience and responsibility requirements).
Reasonable Adjustments
As a Disability Confident Leader employer, we are committed to ensuring that the recruitment process is fair, accessible and allows all candidates to perform at their best. If a person with a visible or non-visible disability is substantially disadvantaged, we have a duty to make reasonable changes to our processes.
Complete the “Assistance required” section in the “Additional requirements” page of your application form to tell us what changes or help you might need during the recruitment process. For instance, you may need wheelchair access at an interview, or if you’re deaf, a Language Service Professional.
If you need a reasonable adjustment so that you can complete your application, you should contact Government Recruitment Service via dftrecruitment.grs@cabinetoffice.gov.uk as soon as possible before the closing date to discuss your needs.
Document Accessibility
This job advert contains links to the DfT Careers website. Our website provides useful guidance and information that can support you during the application process. If you are experiencing accessibility problems with any attachments on this advert or the information on our website, please contact the email address in the 'Contact point for applicants' section.
Further Information
For more information about how we hire, and for useful tips on submitting your application for this role, visit the How We Hire page of our DfT Careers website. You can find detailed information about the recruitment process and what to expect when applying for a role.
If you are unsuccessful in the selection process, your application may be considered for a lower graded position if your demonstrated skills and experience meet the requirements of the alternative position. Candidates will be considered in order of merit.
Pre-employment Checking
If your application is successful but you have been dismissed from the Civil Service, your application could be removed at the pre-employment checking stage depending on the nature of the dismissal.
Applicants who are successful at interview will be, as part of pre-employment screening, subject to a check on the Internal Fraud Database (IFD). This check will provide information about employees who have been dismissed for fraud or dishonesty offences. This check also applies to employees who resign or otherwise leave before being dismissed for fraud or dishonesty had their employment continued. Any applicant’s details held on the IFD will be refused employment. A candidate is not eligible to apply for a role within the Civil Service if the application is made within a 5-year period following a dismissal for carrying out internal fraud against government.
All external applicants and current employees of accredited non-departmental public bodies (NDPBs) will be required to undergo a Social Media Check. A Social Media Check is a review of your publicly available online activity, typically across platforms like LinkedIn, Facebook, X (formerly Twitter), Instagram, and others. The purpose is to identify any public posts or content that could raise concerns for employers, such as:
- Hate speech or discriminatory behaviour
- Threats or acts of violence
- Illegal activity or substance misuse
- Sexually explicit material
- Extremist views or affiliations
Importantly, this check does not involve hacking into your accounts or accessing private messages. It only considers content you have chosen to make public. Employers use this kind of screening to help ensure their workplace remains safe, inclusive, and aligned with company values. It’s not about judging your personality or lifestyle - it’s about checking for potential red flags that might affect the role or company culture. If you have questions or concerns about the social media check, we would be happy to explain in more detail what’s being looked at and how your data is handled securely and fairly.
For further information on National Security Vetting please visit the Demystifying Vetting website.
Feedback will only be provided if you attend an interview or assessment.
Practise before you apply
Civil Service panels score every answer against the Success Profiles behaviours at HEO level. Practise STAR answers and get them marked against the same framework.
3 free questions · No card needed
Similar vacancies
- Regulator - Investigation and Enforcement (HEO) · Building Safety Regulator · £38,005+
- DIO European Support Group Facilities Manager · Ministry of Defence · £37,330
- Information Security and Monitoring Specialist · Department for Work and Pensions · £44,355+
- Compliance Inspector · Department for Transport · £37,090+
- Presenting Officer · Home Office · £41,750+