Third Party Security Risk Analyst

Talenza · Sydney NSW 2000 · Full time
Posted 10d ago

Third Party Security Risk Analyst

Talenza
Sydney NSW 2000

·

Full time

~$100k - $130k(Estimated)
+ Super
Talenza Logo
KEY POINTS WE FOUND
  • Coordinate and conduct supplier risk assessments for third-party vendors.
  • Review security and compliance documentation to identify risks and control gaps.
  • Support ongoing monitoring of third-party risks across the supplier lifecycle.

Our Federal Government client is seeking an experienced Third Party Risk Analyst to support the ongoing delivery and enhancement of its Third-Party Risk Management (TPRM) capability. This role will be responsible for coordinating and conducting supplier risk assessments, reviewing security and compliance documentation, managing vendor risk activities and supporting the ongoing monitoring of third-party risks across the supplier lifecycle. The successful candidate will work closely with procurement, security, legal, privacy and technology stakeholders to ensure suppliers meet governance, security and risk management requirements. Candidates must be Australian Citizens and be able to obtain a NV1 Clearance.

Role Title: Third Party Risk Analyst

Start Date: November 2026

Contract Role Till: 12 Month Initial Contract

Pay Rate: Market Rates

Location: Sydney CBD (2000), 50/50 split between office and work from home.

Hours of Work: 38 hours per week

Tasks & Responsibilities:

  • Conduct third-party risk assessments across new procurements, contract renewals and existing supplier arrangements.
  • Assess supplier risks relating to information security, privacy, operational resilience, AI and foreign ownership, control or influence (FOCI).
  • Review supplier responses, supporting documentation, certifications, audit reports and security artefacts to identify risks and control gaps.
  • Coordinate assessment activities from initiation through to completion, ensuring appropriate evidence and audit trails are maintained.
  • Prepare risk assessment reports, findings summaries and recommendations for stakeholder review.
  • Liaise directly with suppliers to obtain assessment responses, supporting evidence and clarification of identified risks.
  • Administer vendor assessment questionnaires and support ongoing assessment workflows.
  • Support vendor onboarding, classification and ongoing monitoring activities.
  • Maintain vendor registers, assessment schedules, monitoring requirements and risk documentation.
  • Monitor supplier security ratings, threat intelligence alerts and emerging risks, escalating material concerns where required.
  • Facilitate stakeholder workshops and engagement activities to support risk assessment and governance processes.
  • Support supplier incident investigations, remediation activities and reassessment exercises as required.
  • Contribute to the ongoing improvement of third-party risk frameworks, methodologies, processes and governance artefacts.

Experience & Skills Required:

  • 5+ years' experience within Third Party Risk Management, Technology Risk, IT Governance, Cyber Security, GRC or related disciplines.
  • Experience conducting vendor security assessments, risk assessments or supplier due diligence activities.
  • Strong understanding of Australian Government security requirements including PSPF, ISM, Home Affairs FOCI Guidance, APS AI Plan and DTA AI Policy.
  • Familiarity with NIST Cyber Security Framework, NIST AI Risk Management Framework, ISO 27001 and related standards.
  • Experience reviewing supplier security documentation, audit reports, certifications and assurance artefacts.
  • Knowledge of Australian Government security requirements, including PSPF and ISM frameworks.
  • Strong analytical and investigative skills with a high level of attention to detail.
  • Experience preparing risk assessments, governance reports and executive-level documentation.
  • Strong stakeholder management skills with the ability to work across technology, procurement, legal, privacy and business teams.
  • Proven ability to manage multiple assessments and competing priorities simultaneously.
  • Professional certifications such as CRISC, CISA, CompTIA Security+, ISO 27001 Lead Implementer/Auditor or similar are desirable.

Mandatory Requirements:

  • Current NV1 Security Clearance, or the ability to obtain and maintain an NV1 Security Clearance.
  • Ability to handle sensitive information and apply sound judgement in accordance with security, privacy and governance requirements.

If you feel this opportunity matches your skills and previous experience, please apply with your CV.

Candidates must possess existing Australian working rights (Citizens and be able to obtain NV1 Clearance) and live in the Greater Sydney Area.

Stay Safe While Job Hunting

We vet all employer accounts and do our best to keep job ads safe, but scams can still occur. Be cautious when sharing personal information — never provide financial details or make payments during the application process. For extra security, use the Apply button on our site when proceeding.

Skills

0 of 20 matched
Analytical skillsAssessment coordinationAttention to detailAudit report reviewAustralian government security requirementsCross-functional collaborationIncident investigation and remediationIso 27001Nist cyber security frameworkPolicy and governance developmentRisk assessmentRisk frameworks and standardsRisk reporting and documentationSecurity clearance nv1Security documentation reviewStakeholder managementSupplier due diligenceThreat intelligence monitoringVendor managementWorkplace flexibility

Perks & benefits

0 of 1 matched
Super

Talenza

Talenza Logo