30 Sep
|
Master2Manage® Pty Limited, Australia
|
Sydney
30 Sep
Master2Manage® Pty Limited, Australia
Sydney
This role is strictly for On-Shore Australian Citizens with active AGSVA NV1 clearance - Applicants not meeting criteria may please not to apply.
Company Description
Master2Manage® Pty Limited is an Australian-owned management and technology consulting company that helps government agencies, regulated industries, and private organisations strengthen cyber resilience and deliver complex ICT initiatives. The company focuses on ICT labour hire and specialist workforce augmentation, cybersecurity advisory and assurance, ICT project and program delivery, and corporate and ICT training. Its integrated advisory and delivery capability spans enterprise and solution architecture, business analysis, ICT governance and risk management, privacy and compliance, AI engineering, digital procurement, and solution implementation. Master2Manage consultants support ICT, cybersecurity, and digital transformation programs across Commonwealth and state government, defence, healthcare, critical infrastructure, and commercial organisations. The company is an approved supplier under BuyICT Digital Marketplace 2.0 and BuyNSW ICT Services Scheme, combining senior consulting expertise with practical delivery to achieve secure and compliant outcomes.
Overview
Are you experienced in technology risk, cyber governance, or third-party risk management within highly regulated environments?
An chance is available to contribute to the delivery and continuous improvement of an enterprise Third-Party Risk Management (TPRM) capability, supporting supplier risk assessments across security, privacy, operational resilience, foreign ownership/influence (FOCI), and emerging AI risks.
Rates:
$85-$90 per hour inclusive of super
Role Description
- Conduct supplier and vendor risk assessments for new procurements, renewals, and ongoing engagements.
- Review security, privacy, compliance, resilience, and AI-related controls and evidence.
- Coordinate supplier due diligence activities, questionnaires, risk reviews, and stakeholder engagement.
- Support vendor risk registers, monitoring programs, reporting, and governance activities.
- Work closely with procurement, security, legal, technology, privacy, and risk stakeholders.
- Contribute to continuous improvement of TPRM frameworks, processes, workflows, and tooling.
- Assist with supplier incident response, reassessments, and emerging risk monitoring.
Desired experience:
- 5+ years in Third-Party Risk Management, Cyber Security, Technology Risk, IT Governance, GRC, or related disciplines.
- Experience conducting vendor security assessments and supplier due diligence.
- Knowledge of PSPF, ISM, FOCI, NIST, ISO 27001, AI governance, and privacy frameworks.
- Strong analytical, reporting, stakeholder engagement, and documentation skills.
- Experience with platforms such as UpGuard, SecurityScorecard, Archer, ServiceNow, ProcessUnity, Qualys, or similar.
- Experience in government, banking, insurance, financial services, or other highly regulated sectors is highly regarded.
- Relevant certifications (CISA, CRISC, Security+, ISO 27001, or equivalent) are desirable.
Requirements:
- NV1 Security Clearance
- Ability to work with sensitive information and operate within strict governance and compliance environments.
#J-18808-Ljbffr
📌 Third Party Risk Analyst (Sydney)
🏢 Master2Manage® Pty Limited, Australia
📍 Sydney