? Sydney (Marsfield/Westmead) or Brisbane (St Lucia) | Hybrid
? 5-Month Contract
? Must be able to obtain Baseline Security Clearance
About the Role
We are seeking a Third-Party Risk Cyber Risk Specialist to support a leading Australian research and technology organisation in strengthening its Third-Party Risk Management (TPRM) capability. You will play a key role in conducting end-to-end security risk assessments of vendors, suppliers, and third-party service providers, helping ensure cyber risks are effectively identified, assessed, and managed.
Key Responsibilities
- Conduct end-to-end third-party security risk assessments, including vendor onboarding, risk tiering, evidence review, analysis, and reporting.
- Evaluate vendor security controls across areas such as access management, vulnerability management, incident response, encryption, backup and recovery.
- Assess and communicate cyber and information security risks, including likelihood, impact, and remediation recommendations.
- Prepare explicit and actionable risk assessment reports for technical and business stakeholders.
- Utilise UpGuard and other risk management platforms to perform assessments and monitor vendor security posture.
- Collaborate with business owners, service providers, and cyber security teams to manage remediation activities.
- Maintain assessment documentation and support continuous improvement of TPRM processes and methodologies.
- Track assessments, issues, and actions through governance and workflow tools such as Jira.
Key Requirements
Essential
- Demonstrated experience in Third-Party Risk Management (TPRM),
vendor risk management, supplier risk assessments, or cyber risk assessment roles.
- Strong understanding of information security and cyber risk management principles.
- Experience assessing security controls and vendor security postures.
- Knowledge of risk identification, risk treatment planning, and risk reporting.
- Excellent stakeholder engagement and communication skills.
- Ability to work independently across multiple concurrent assessments.
Highly Desirable
- Knowledge of Australian Government security frameworks including PSPF and ISM.
- Familiarity with ISO 27001, NIST Cyber Security Framework, and Essential Eight.
- Experience using UpGuard or similar third-party risk management platforms.
- Relevant certifications such as CISSP, CISM, CCSP, or ISO 27001 Lead Auditor.
- Understanding of privacy and data breach obligations within Australia.
What's on Offer
- Opportunity to work within a growing Cyber Resilience team.
- Exposure to enterprise-scale third-party risk and cyber security programs.
- Hybrid working model with preferred locations in Sydney or Brisbane.
- Collaborative environment focused on strengthening cyber resilience across a diverse vendor ecosystem.
If this sounds like you then apply today! If you’re interested or know someone who might be — feel free to send an updated resume to
[email protected] . If all aligns, you will be reached out.
We believe in working for a place that works for you. We have many flexible working options within our team so talk to us about which arrangements would work best for you.
📌 Third-Party Cyber Risk Specialist (Sydney)
🏢 Hays
📍 Sydney