31 Jul
|
Hays
|
Melbourne
TPRM Security Analyst,
Long term contract
Day Rate $750 to $850
Immediate start
Your new company:
Join a leading Victorian State Government Agency delivering a critical Cyber Resilience Program aimed at strengthening cyber security capabilities across a large and complex environment. They are investing heavily in secure digital services and is seeking an experienced security professional to help assess and manage risks associated with third-party suppliers, cloud platforms, SaaS solutions, and AI-enabled technologies.
Your new role:
As a TPRM Security Analyst, you will play a critical role in evaluating the security posture of suppliers, products, cloud services, and emerging AI solutions. You will conduct detailed security assessments, identify risks and control gaps, validate supplier evidence, and provide clear recommendations to support informed risk-based decisions.
Key responsibilities include
- Conducting security assessments of suppliers, cloud platforms, SaaS products, and AI-enabled solutions.
- Reviewing security architecture, data flows, and technical configurations.
- Assessing identity and access management, APIs, encryption, logging, network security, vulnerability management, and tenant isolation controls.
- Evaluating AI-related security risks, including LLM providers, model training, data retention, prompt handling, embeddings, RAG architectures, AI agents, and third-party sub processors.
- Reviewing supplier evidence such as certifications, penetration testing reports, architecture diagrams, and security documentation.
- Documenting security risks, treatment plans, control gaps, and residual risk assessments.
- Providing approval, conditional approval, exemption, or non-approval recommendations.
- Presenting assessment outcomes to governance forums and senior stakeholders.
- Collaborating closely with Procurement, Legal, Privacy, Technology, and Information Security teams.
- Coordinating and quality-assuring assessments delivered by external security providers.
What you'll need to succeed: To be successful in this role, you will have:
- Demonstrated experience in Third-Party Risk Management (TPRM), supplier assurance, security governance, or product security assessments.
- Strong knowledge of cloud, SaaS, API, identity, and technical security controls.
- Experience assessing Azure, AWS, or multi-tenant cloud environments.
- Understanding of Generative AI architectures and associated cyber security risks.
- Experience validating supplier security controls through evidence-based assessments.
- Strong analytical thinking, risk assessment, report writing, and stakeholder engagement skills.
- The ability to work independently, manage competing priorities, and deliver outcomes within agreed timeframes.
- Experience working within government, education, financial services, or other regulated industries.
- Knowledge of security frameworks and standards such as VPDSS, ISO 27001, SOC 2, NIST, ISM, PSPF, and Essential Eight.
- Relevant cyber security, risk, audit, governance, or cloud certifications.
What you'll get in return:
- Work within a highly visible and strategically important government initiative.
- Collaborative and supportive team environment.
- Adaptable working arrangements and a strong focus on professional development.
What you need to do now: Speak to our Experts in Technology for a confidential discussion or send through your updated resume for immediate consideration.
Hays appreciates the importance of workforce diversity and inclusion. We are an equal-opportunities employer and have policies, procedures and relationships in place to promote our understanding of all forms of diversity.
📌 Information Security Analyst (Melbourne)
🏢 Hays
📍 Melbourne