Cyber Risk Specialist
- 5-month contract commencing around November 2026 – 150 working hours per month
- Sydney or Brisbane – hybrid working
- Baseline security clearance required
- Strong experience in third-party/vendor cyber risk assessments, security controls, risk treatment and stakeholder engagement
Join a cyber security team that is expanding and maturing its Third-Party Risk Management capability across a large and complex technology environment. You will play a hands-on role assessing the security posture of suppliers and service providers, identifying material risks and helping business stakeholders make informed decisions about how those risks should be managed.
Your duties will include:
- Conduct end-to-end third-party security risk assessments, from initial vendor intake and risk tiering through to final assessment outcomes.
- Review security questionnaires, supporting evidence and externally available security information to assess supplier security posture.
- Identify and assess information and cyber security risks, including likelihood, consequence and appropriate risk treatments.
- Prepare clear and structured risk assessment reports for business stakeholders and cyber security leadership.
- Use platforms such as UpGuard to conduct assessments, interpret security ratings and translate findings into meaningful risk information.
- Work with business owners, service owners and suppliers to clarify findings, agree remediation actions and establish appropriate timeframes.
- Contribute to the ongoing improvement of third-party risk processes, assessment methodologies, questionnaires and templates.
Skills and Experience we are looking for:
- Demonstrated experience conducting third-party, supplier or vendor cyber security risk assessments.
- Strong understanding of inherent and residual risk, risk ratings, likelihood and consequence assessment, and treatment planning.
- Experience assessing security controls across areas such as encryption, access management, vulnerability management, backups, penetration testing and incident response.
- Strong written communication skills, with the ability to produce concise and defensible cyber risk assessments.
- Ability to communicate security risks effectively with both technical and non-technical stakeholders.
- Familiarity with Australian Government security frameworks such as the PSPF, ISM and Essential Eight, along with frameworks including ISO 27001 or NIST CSF, will be highly regarded.
- Relevant cyber security qualifications or certifications such as CISSP, CCSP, CISM or ISO 27001 Lead Auditor will also be viewed favourably.
For over 30 years Talent has been redefining the contracting experience with industry leading support, exclusive contractor benefits & a world-class digital platform ENGAGE to access it all. Apply today to see how we can elevate your career