22 Sep
|
Talent International
|
New South Wales
22 Sep
Talent International
New South Wales
Job Description
n
5-month contract commencing around November ********** working hours per month
n
Sydney or Brisbane – hybrid working
n
Baseline security clearance required
n
Strong experience in third-party/vendor cyber risk assessments, security controls, risk treatment and stakeholder engagement
n
n
Join a cyber security team that is expanding and maturing its Third-Party Risk Management capability across a large and complex technology setting. You will play a hands-on role assessing the security posture of suppliers and service providers, identifying material risks and helping business stakeholders make informed decisions about how those risks should be managed.
n
Your duties will include:
n
n
Conduct end-to-end third-party security risk assessments, from initial vendor intake and risk tiering through to final assessment outcomes.
n
Review security questionnaires, supporting evidence and externally available security information to assess supplier security posture.
n
Identify and assess information and cyber security risks, including likelihood, consequence and appropriate risk treatments.
n
Prepare clear and structured risk assessment reports for business stakeholders and cyber security leadership.
n
Use platforms such as UpGuard to conduct assessments, interpret security ratings and translate findings into meaningful risk information.
n
Work with business owners, service owners and suppliers to clarify findings, agree remediation actions and establish appropriate timeframes.
n
Contribute to the ongoing improvement of third-party risk processes, assessment methodologies, questionnaires and templates.
n
n
Skills and Experience we are looking for:
n
n
Demonstrated experience conducting third-party, supplier or vendor cyber security risk assessments.
n
Strong understanding of inherent and residual risk, risk ratings, likelihood and consequence assessment, and treatment planning.
n
Experience assessing security controls across areas such as encryption, access management, vulnerability management, backups, penetration testing and incident response.
n
Strong written communication skills, with the ability to produce concise and defensible cyber risk assessments.
n
Ability to communicate security risks effectively with both technical and non-technical stakeholders.
n
Familiarity with Australian Government security frameworks such as the PSPF, ISM and Essential Eight, along with frameworks including ISO ***** or NIST CSF, will be highly regarded.
n
Relevant cyber security qualifications or certifications such as CISSP, CCSP, CISM or ISO ***** Lead Auditor will also be viewed favourably.
n
📌 Cyber Risk Specialist (New South Wales)
🏢 Talent International
📍 New South Wales