Group Procurement and Compliance Manager
TOMIA · 1 day ago
Key Responsibilities
Procurement & Supplier Management
-
Lead all procurement activities for goods and services across the Tomia Business Unit, ensuring commercial value, quality and compliance with corporate procurement policies.
-
Develop and maintain effective relationships with suppliers and strategic vendors to support long-term business objectives.
-
Lead commercial negotiations for new contracts, renewals and amendments, achieving optimal commercial terms while minimising business risk.
-
Manage the complete procurement lifecycle from business requirement through supplier selection, contracting and ongoing supplier management.
-
Maintain and continuously improve supplier governance, ensuring accurate information is recorded within the Vendor Management System.
-
Develop supplier performance measures and conduct regular supplier reviews to monitor service, quality and contractual performance.
-
Identify, assess and mitigate supplier risks through effective risk management and contingency planning.
-
Monitor contract expiry dates and proactively manage contract renewals to ensure uninterrupted service.
-
Identify opportunities for supplier consolidation, process improvement and cost optimisation while maintaining required service quality.
-
Produce procurement reporting and analytics, including supplier spend, savings achieved, contract status and procurement performance.
-
Partner with Finance, Legal, Information Security and business stakeholders to ensure procurement decisions support organisational priorities.
Compliance & Governance
-
Own and manage the compliance framework across the Tomia Business Unit.
-
Lead the implementation, maintenance and continual improvement of ISO 27001, ISO 27017 and ISO 27018 management systems across Tomia, MACH and Telarix.
-
Coordinate annual surveillance and recertification audits, ensuring successful certification outcomes.
-
Manage relationships with internal and external auditors throughout audit planning, execution and remediation activities.
-
Coordinate the implementation and maintenance of SOC 1 controls and associated audit requirements.
-
Track compliance actions, audit findings and remediation plans to ensure timely completion by functional teams.
-
Develop, maintain and regularly review corporate policies, standards and procedures to ensure continued compliance with regulatory and business requirements.
-
Create and deliver the annual compliance work plan, monitoring progress and reporting against objectives.
-
Prepare regular compliance reports, dashboards and risk updates for senior leadership.
-
Promote a culture of compliance by developing awareness programmes, communications and training across the organisation.
-
Support customer due diligence by completing compliance, information security and governance questionnaires for RFPs, tenders and customer audits.
-
Coordinate carbon footprint reporting and sustainability data to support corporate ESG objectives.
-
Monitor emerging regulatory requirements and industry best practice, recommending improvements where appropriate.
Stakeholder Management
-
Build strong working relationships across Procurement, Finance, Legal, Information Security, IT, Operations, Sales and Product teams.
-
Provide expert advice to business leaders on procurement strategy, supplier governance and compliance obligations.
-
Influence stakeholders to ensure governance requirements are embedded into business processes.
-
Act as the primary point of contact for procurement and compliance matters within the Business Unit.
Knowledge, Skills & Experience
Essential
-
Experience managing procurement and supplier governance within a global organisation.
-
Strong commercial negotiation and contract management experience.
-
Experience implementing and maintaining ISO 27001 and related information security standards.
-
Experience supporting external audits and certification programmes.
-
Knowledge of supplier risk management and third-party governance.
-
Strong understanding of procurement best practice and purchasing controls.
-
Excellent stakeholder management and influencing skills.
-
Strong analytical and reporting capability.
-
Excellent organisational skills with the ability to manage multiple priorities.
-
High attention to detail and commitment to continuous improvement.
Desirable
-
Experience with ISO 27017 and ISO 27018.
-
Experience supporting SOC 1 or SOC 2 audit programmes.
-
Knowledge of ESG and carbon reporting requirements.
-
Experience working within software, telecommunications or technology organisations.
-
Professional procurement qualification (CIPS) or equivalent.
-
Information Security or Compliance qualification (ISO Lead Implementer/Lead Auditor or similar).