Experience: 5+ years
Location: Sydney, Australia
Eligibility: Candidates must have the right to work in Australia (Citizen, PR, Valid Visa holders).
Job Description
· Evaluate third-party vendors' security practices
· Conduct due diligence assessments and risk analyses for third-party vendors.
· Collaborate with procurement, legal, business pillar and IT teams to ensure security controls are included in vendor contracts.
· Maintain an up-to-date inventory of third-party relationships and associated risks.
· Ensure all security risk management activities align with the requirements of PCI DSS, ISO 27001 and SOC2 Type 2 standards.
· Participate in audits and assessments, providing evidence and documentation as required.
· Develop and maintain policies and procedures for cyber risk management and third party risk management.
· Develop continuous controls monitoring processes and reporting
· Experience:
o 5+ years of experience in identifying and mitigating cyber risks in a corporate environment.
o Expertise in risk assessment methodologies and tools.
o Proven ability to create and implement risk management frameworks.
o Knowledge of PCI DSS and ISO 27001 standards desirable.
o Hands-on experience evaluating and managing vendor risks.
Drop your CV