Third Party Security Risk Analyst

Talenza

Sydney

Hybrid

AUD 166,000 - 221,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Talenza is partnering with a Federal Government client in Sydney to hire an experienced Third Party Risk Analyst on a 12-month contract. The role supports the TPRM capability, coordinating supplier risk assessments and monitoring across the supplier lifecycle.

The successful candidate will work with procurement, security, legal, privacy and technology stakeholders to ensure compliance with governance and risk requirements. Australian Citizens with NV1 eligibility are required.

Qualifications

  • 5+ years in Third-Party Risk Management or related fields.
  • Experience with vendor security assessments and due diligence.
  • Knowledge of PSPF, ISM, and related Australian gov security requirements.
  • Familiarity with NIST/ISO frameworks.

Responsibilities

  • Conduct third-party risk assessments across procurements, renewals and existing supplier arrangements.
  • Review security, privacy, resilience, AI and FOCI documentation for risks.
  • Coordinate assessment activities and maintain audit evidence.
  • Prepare risk reports and recommendations for stakeholders.
  • Engage with suppliers to obtain responses and clarification.
  • Maintain vendor registers and monitoring requirements.
  • Support onboarding and ongoing vendor risk monitoring.
  • Facilitate governance workshops and risk remediation activities.
  • Contribute to ongoing improvement of risk frameworks.

Skills

Third-Party Risk Management
Vendor risk assessments
ISPF/ISM knowledge
GRC frameworks

Job description

Our Federal Government client is seeking an experienced Third Party Risk Analyst to support the ongoing delivery and enhancement of its Third-Party Risk Management (TPRM) capability. This role will be responsible for coordinating and conducting supplier risk assessments, reviewing security and compliance documentation, managing vendor risk activities and supporting the ongoing monitoring of third-party risks across the supplier lifecycle. The successful candidate will work closely with procurement, security, legal, privacy and technology stakeholders to ensure suppliers meet governance, security and risk management requirements. Candidates must be Australian Citizens and be able to obtain a NV1 Clearance.

Role Title: Third Party Risk Analyst

Start Date: November 2026

Contract Role Till: 12 Month Initial Contract

Pay Rate: Market Rates

Location: Sydney CBD (2000), 50/50 split between office and work from home.

Hours of Work: 38 hours per week

Tasks & Responsibilities
  • Conduct third-party risk assessments across new procurements, contract renewals and existing supplier arrangements.
  • Assess supplier risks relating to information security, privacy, operational resilience, AI and foreign ownership, control or influence (FOCI).
  • Review supplier responses, supporting documentation, certifications, audit reports and security artefacts to identify risks and control gaps.
  • Coordinate assessment activities from initiation through to completion, ensuring appropriate evidence and audit trails are maintained.
  • Prepare risk assessment reports, findings summaries and recommendations for stakeholder review.
  • Liaise directly with suppliers to obtain assessment responses, supporting evidence and clarification of identified risks.
  • Administer vendor assessment questionnaires and support ongoing assessment workflows.
  • Support vendor onboarding, classification and ongoing monitoring activities.
  • Maintain vendor registers, assessment schedules, monitoring requirements and risk documentation.
  • Monitor supplier security ratings, threat intelligence alerts and emerging risks, escalating material concerns where required.
  • Facilitate stakeholder workshops and engagement activities to support risk assessment and governance processes.
  • Support supplier incident investigations, remediation activities and reassessment exercises as required.
  • Contribute to the ongoing improvement of third-party risk frameworks, methodologies, processes and governance artefacts.
Experience & Skills Required
  • 5+ years' experience within Third Party Risk Management, Technology Risk, IT Governance, Cyber Security, GRC or related disciplines.
  • Experience conducting vendor security assessments, risk assessments or supplier due diligence activities.
  • Strong understanding of Australian Government security requirements including PSPF, ISM, Home Affairs FOCI Guidance, APS AI Plan and DTA AI Policy.
  • Familiarity with NIST Cyber Security Framework, NIST AI Risk Management Framework, ISO 27001 and related standards.
  • Experience reviewing supplier security documentation, audit reports, certifications and assurance artefacts.
  • Knowledge of Australian Government security requirements, including PSPF and ISM frameworks.
  • Strong analytical and investigative skills with a high level of attention to detail.
  • Experience preparing risk assessments, governance reports and executive-level documentation.
  • Strong stakeholder management skills with the ability to work across technology, procurement, legal, privacy and business teams.
  • Proven ability to manage multiple assessments and competing priorities simultaneously.
  • Professional certifications such as CRISC, CISA, CompTIA Security+, ISO 27001 Lead Implementer/Auditor or similar are desirable.
Mandatory Requirements
  • Current NV1 Security Clearance, or the ability to obtain and maintain an NV1 Security Clearance.
  • Ability to handle sensitive information and apply sound judgement in accordance with security, privacy and governance requirements.

Candidates must possess existing Australian working rights (Citizens and be able to obtain NV1 Clearance) and live in the Greater Sydney Area.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Risk Analyst
Cyber Risk Analyst

Triniti • Sydney

Hybrid
AUD 129,000 - 203,000
IT Risk Analyst
IT Risk Analyst

Michael Page Australia • Sydney

Hybrid
AUD 120,000 - 185,000
Third Party Risk Analyst
Third Party Risk Analyst

Peoplebank • City of Brisbane

On-site
AUD 110,000 - 140,000
Assurance Specialist, Cyber Governance Risk and Compliance
Assurance Specialist, Cyber Governance Risk and Compliance

Balance Recruitment and Balance Consulting • Canberra

On-site
AUD 100,000 - 150,000
Cyber Risk Specialist
Cyber Risk Specialist

Peoplebank • Sydney

Hybrid
AUD 110,000 - 170,000
Hybrid work
5-month contract
Competitive rate
Lead Cyber Analyst
Lead Cyber Analyst

Peoplebank • Canberra

Hybrid
AUD 110,000 - 150,000
Cyber Security SME
Cyber Security SME

Compas PTY • Canberra

On-site
AUD 120,000 - 160,000
Lead Cyber Analyst - Federal Government - NV1 - 12mth contract
Lead Cyber Analyst - Federal Government - NV1 - 12mth contract

Lookahead • City of Melbourne

Hybrid
AUD 95,000 - 120,000
IT Risk Manager
IT Risk Manager

Michael Page Australia • Sydney

Hybrid
AUD 111,000 - 185,000
Cyber Governance, Risk & Compliance Specialist
Cyber Governance, Risk & Compliance Specialist

Bespoke Careers • City of Brisbane

On-site
AUD 91,000 - 152,000