- Hiring from
- United Kingdom
- Work type
- Remote
- Posted
- Sep 29, 2026
Is this job info correct?
To own the end-to-end supplier lifecycle for the Group: bringing new suppliers on board safely, evidencing that they meet our regulatory, security and contractual obligations, and ensuring the services we pay for are delivered. The role is the owner of the Vanta platform as the single source of truth for supplier risk, contract management and renewals.
Suppliers in scope:
Full Group third-party base, from critical outsourced services to tail spend.
Systems owned:
Vanta (supplier & risk management), contract repository, renewals calendar
Frameworks:
TSA obligations, ISO 27001, GDPR/data protection, sanctions & financial crime checks
Key stakeholders:
Legal, Information Security, Risk & Compliance, Finance, service/contract owners
How success is measured*
Suppliers in scope:
Full Group third-party base, from critical outsourced services to tail spend.
Systems owned:
Vanta (supplier & risk management), contract repository, renewals calendar
Frameworks:
TSA obligations, ISO 27001, GDPR/data protection, sanctions & financial crime checks
Key stakeholders:
Legal, Information Security, Risk & Compliance, Finance, service/contract owners
How success is measured*
- 100% of critical suppliers with current, approved due diligence on file.
- Zero contracts auto-renewing without a documented commercial review.
- Average supplier onboarding time under 10 working days, request to approved record.
- TSA and ISO 27001 supplier evidence available on demand, audit-ready.
- Vanta fully adopted as the single source of truth for supplier and contract data.
- Quarterly service reviews held for every critical contracted service.
Key Responsibilities
1. Supplier due diligence
- Operate and continuously improve a risk-tiered due diligence framework covering financial standing, information security, data protection, sanctions/financial crime and ESG.
- Ensure every critical supplier is assessed before contract signature and re-assessed on an agreed cycle.
- Maintain a clear, documented risk position for each supplier, with escalation routes for high-risk findings.
2. Supplier onboarding
- Deliver a single, documented onboarding route from supplier request through to approved supplier record.
- Set and meet onboarding SLAs; prevent unapproved spend entering the business.
- Act as the point of contact for the business on "how do I onboard this supplier?"
3. In-contract management of services received
- Own the performance cadence for contracted services: SLA/KPI reporting, service reviews, issue and remediation tracking.
- Evidence that the Group receives the service it is paying for and drive corrective action where it does not.
- Track contractual obligations on both sides and flag under-delivery, scope creep or unbilled change.
4. Regulatory and security compliance
- Evidence supplier compliance with TSA obligations, ISO 27001 controls and wider regulatory requirements.
- Maintain an audit-ready evidence trail; support internal and external audits and customer assurance requests.
- Keep the supplier control environment current as regulations and the supplier base change.
5. Vanta set-up and ongoing use
- Lead the set-up, configuration and rollout of Vanta for supplier management and contract management.
- Keep supplier records, controls, evidence and contract data complete and current within the platform.
- Train and support users across the business; drive adoption so Vanta is the single source of truth.
6. Contract management and renewals
- Maintain a complete contract register with owner, value, term, notice periods and key dates.
- Run a forward-looking renewals pipeline so no contract auto-renews by default and every renewal is a deliberate commercial decision.
- Support the Group Procurement Director on renegotiation, consolidation and savings opportunities.
Skills, Knowledge and Expertise
Essential:
- Proven experience in supplier / third-party risk management or procurement operations.
- Hands-on supplier due diligence and onboarding in a regulated environment.
- Working knowledge of ISO 27001 and information security assessment of suppliers.
- Contract management experience: registers, obligations, renewals and negotiation support.
- Confident using GRC or supplier management platforms (Vanta or similar).
- Strong data discipline and accurate record keeping.
Desirable:
- Experience of businesses with requirements of regulatory compliance e.g. TSA ISO27001 or similar
- Experience implementing a new system and driving adoption across a business.
Benefits
At Nasstar, we know the importance of looking after our employees – after all, it’s the team that underpins our business!
In addition to a competitive salary, supportive teams, and a real opportunity to progress in your career with a forward-thinking organisation, our benefits package includes:
- 25 days’ holiday (excluding bank holidays) + Your Birthday Off
- Flexible working – it’s important to maintain a work/life balance, as such, we will consider any written request for flexible working
- Virtual working – we practice what we preach and empower our people to work remotely
- Top tech – Leading services and solutions aren’t just for our clients; we supply best-of-breed software and hardware for all our staff too
- 4x annual salary life assurance
- Health cash plan
- Retail discounts and other perks from major brands