Third Party Security Lead

HESTA Super

City of Melbourne

On-site

AUD 150,000 - 210,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Additional leave
Professional development
Health & wellbeing program
Novated lease options

Job summary

HESTA is seeking a Senior Third Party Security Lead to strengthen the organisation's security posture across its third- and fourth-party ecosystem. You will drive automated and AI-enabled monitoring, own end-to-end assessments and work with multiple teams to identify and remediate risks.

The role reports to the Information Security Risk and Assurance Manager and requires deep expertise in NIST CSF, CIS Controls, ISO 27001 and SOC2, with a strong ability to translate complex risks into actionable

Qualifications

  • Extensive experience in information security and third-party risk management, ideally in financial services.
  • Proven delivery of security assurance, audits and control testing.
  • Understanding of NIST CSF, CIS Controls, ISO 27001 and how they apply to third parties.

Responsibilities

  • Lead third-party security monitoring across third and fourth parties.
  • Own end-to-end third-party security assessments from scoping to remediation.
  • Identify emerging security risks using intelligence and monitoring tools.
  • Shape the roadmap for third-party security assurance and tooling.
  • Advise stakeholders during vendor selection and onboarding.
  • Drive remediation and risk reduction with cross-functional teams.
  • Provide leadership and coaching to the wider team.

Skills

Information security
Third-party risk management
Security frameworks
CCM concepts
Security ratings
SOC2 assessments
Stakeholder engagement
Regulatory awareness
Strategic thinking
Vendor management

Education

Bachelor’s degree in Information Security / IT / Accounting

Tools

CCM platforms
Security ratings platforms
Risk intelligence tools

Job description

Select how often (in days) to receive an alert:

Bring your authentic and passionate self to this exceptional role #careerswithimpact

Shape the future of third-party security at HESTA

At HESTA, protecting our members’ data, investments and trust is at the heart of what we do. We’re looking for an experienced Third Party Security Lead to take a leading role in strengthening how HESTA identifies, monitors and manages information security risk across our third- and fourth-party ecosystem.

This is an opportunity to shape and mature a critical security capability - leveraging automation, continuous monitoring and AI-enabled security intelligence to provide greater visibility of our supply-chain security posture and identify emerging risks before they become issues.

Reporting to the Information Security Risk and Assurance Manager, you’ll be the central SME for third-party security assurance, working across Information Security, Technology, Digital, Risk, Compliance, Procurement, Operational Resilience and business teams.

What You’ll Do

  • Lead HESTA’s third-party security monitoring capability, driving the implementation and ongoing execution of automated and AI-enabled monitoring across third and fourth parties.
  • Own end-to-end third-party security assessments, from scoping and prioritisation through to execution, reporting, remediation and ongoing assurance.
  • Identify emerging security risks and control weaknesses, using security intelligence, ratings, continuous controls monitoring and other technologies to strengthen HESTA’s risk visibility.
  • Shape the technology roadmap for third-party security assurance, identifying and implementing innovative tools that improve detection, insight and response.
  • Act as a trusted security advisor to business and technology stakeholders throughout vendor selection, onboarding and ongoing third-party management.
  • Drive remediation and risk reduction, partnering with stakeholders to ensure identified security issues are appropriately assessed, prioritised and resolved.
  • Provide SME leadership and coaching, supporting resources involved in third-party security assessments and building capability across the broader team.

What You’ll Bring

  • Extensive experience in information security, third-party security or supply-chain security risk management, ideally within superannuation or financial services.
  • Strong experience delivering security assurance, audits, assessments, control reviews and evidence-based assurance.
  • Deep understanding of security control frameworks such as NIST CSF, CIS Controls and ISO 27001 and their application to third-party environments.
  • Experience with Continuous Controls Monitoring (CCM) concepts and platforms, including automated and AI-enabled approaches to identifying control failures and emerging risks.
  • Experience using security ratings and third-party risk intelligence platforms, with the ability to turn data and intelligence into actionable risk insights.
  • Strong knowledge of third-party assessment methodologies, including SIG, CAIQ, control testing and SOC2 assurance.
  • Knowledge of relevant financial services and superannuation regulatory obligations, including APRA CPS 230 and CPS 234 and their implications for third-party and outsourcing risk.
  • The confidence to influence, challenge and constructively while building trusted relationships.
  • Strong strategic thinking, commercial acumen and sound judgement in complex, highly regulated environments.
  • Exceptional communication and stakeholder engagement skills, with the ability to translate complex security risks into clear, concise and actionable insights.
  • A relevant tertiary qualification in Information Security, Information Technology, Accounting or a related discipline or equivalent experience.
  • Professional certifications such as CISSP, CISA, CISM, CRISC, CTPRP/CTPRA, ISO 27001 Lead Auditor or Lead Implementer are desirable.

Bring your third party security expertise | Make an immediate impact at HESTA –

Benefits that matter and make a difference for our employees

  • Leave for those moments that matter, an additional 6 days of leave at the end of year, up to 6 days paid volunteer leave, gender neutral paid parental leave of 20 weeks, Gender Aff­irmation leave, reproductive health and wellbeing leave, Cultural and Ceremonial leave. Access your LSL after 3 years, take AL at half pay, and purchase up to 2 weeks additional leave (just to name a few).
  • Your professional development matters, up to $5,000 per year professional development and up to 8 days professional development leave, HESTA scholarships and free access to a range of premium learning tools.
  • Your health and wellbeing matters, free annual flu shots and skin checks, incredible social events throughout the year and a comprehensive employee assistance program available 24/7.
  • Your financial wellbeing matters, up to 15% super, financial planning support, end of year payment for all Enterprise Agreement-covered employees, incentivised Employee Referral Program and novated lease options.

We celebrate, value and include people of all backgrounds, genders, identities, cultures and abilities. We welcome and support applications from First Nations people, physically, neuro or culturally diverse, LGBTQI+, and people of any age. We are proud to be WGEA accredited as an Employer of Choice for Gender Equity.

We want all candidates to feel safe, included and provided with the best opportunity to thrive, if you require reasonable adjustments during your application or throughout the recruitment process, please reach out to a member of the Talent team careers@hesta.com.au and we’ll call you to discuss.

Please note: Applications via recruitment agencies will not be accepted for this position.

HESTA Superannuation Fund Number (SFN): 129638949. HESTA Australian Business Number (ABN): 64 971 749 321

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Third Party Security Lead
Third Party Security Lead

HESTA • City of Melbourne

On-site
AUD 180,000 - 230,000
Leave and volunteer leave
Professional development allowance
Health and wellbeing programs
+1
Senior Manager - Controls and Assurance
Senior Manager - Controls and Assurance

HESTA Super • City of Melbourne

On-site
AUD 180,000 - 240,000
Extensive leave benefits
Professional development support
Health and wellbeing programs
+1
Senior Manager - Controls and Assurance
Senior Manager - Controls and Assurance

HESTA • City of Melbourne

On-site
AUD 180,000 - 240,000
Leave for moments that matter
Volunteer leave
Parental leave (20 weeks)
+7
Tax Regulatory Lead
Tax Regulatory Lead

HESTA Super • City of Melbourne

On-site
AUD 180,000 - 240,000
Leave benefits
Professional development
Health & wellbeing
+1
Information Security/Cybersecurity Operations Specialist
Information Security/Cybersecurity Operations Specialist

HESTA • City of Melbourne

On-site
AUD 120,000 - 170,000
Additional leave
PD support
Health & wellbeing
+1
Senior Manager - Compliance Framework & Operations
Senior Manager - Compliance Framework & Operations

HESTA • City of Melbourne

On-site
AUD 180,000 - 240,000
Additional leave
Professional development support
Health and wellbeing benefits
+1
Information Security Architect
Information Security Architect

HESTA • City of Melbourne

On-site
AUD 180,000 - 240,000
Additional leave
PD funding
Health programs
+1
Tax Regulatory Lead
Tax Regulatory Lead

HESTA • City of Melbourne

On-site
AUD 180,000 - 240,000
Extended leave provisions
Professional development support
Health and wellbeing programs
+1
Senior Manager - Compliance Framework & Operations
Senior Manager - Compliance Framework & Operations

HESTA Super • City of Melbourne

On-site
AUD 180,000 - 240,000
Extended leave entitlements
Volunteer leave
Parental leave 20 weeks
+5
Legal Counsel - Disputes and Regulatory Matters
Legal Counsel - Disputes and Regulatory Matters

HESTA Super • City of Melbourne

On-site
AUD 140,000 - 180,000
End of year leave and leave options
Professional development allowance
Health and wellbeing initiatives
+2