Warning! Be wary of scams. Read our FAQ page for more information.


Third Party Security Risk Analyst

Contract Type

Permanent

Location

New South Wales, Sydney

Industry

IT

Specialisation

Government

Salary

+ Super

Contact Name

Louis Goth

Contact Email

louis@talenza.com.au

Date published

23-09-2026

Job Reference

BBBH22647

Description

Our Federal Government client is seeking an experienced Third Party Risk Analyst to support the ongoing delivery and enhancement of its Third-Party Risk Management (TPRM) capability. This role will be responsible for coordinating and conducting supplier risk assessments, reviewing security and compliance documentation, managing vendor risk activities and supporting the ongoing monitoring of third-party risks across the supplier lifecycle. The successful candidate will work closely with procurement, security, legal, privacy and technology stakeholders to ensure suppliers meet governance, security and risk management requirements. Candidates must be Australian Citizens and be able to obtain a NV1 Clearance.

Role Title: Third Party Risk Analyst

Start Date: November 2026

Contract Role Till: 12 Month Initial Contract

Pay Rate: Market Rates

Location: Sydney CBD (2000), 50/50 split between office and work from home.

Hours of Work: 38 hours per week


Tasks & Responsibilities:

  • Conduct third-party risk assessments across new procurements, contract renewals and existing supplier arrangements.
  • Assess supplier risks relating to information security, privacy, operational resilience, AI and foreign ownership, control or influence (FOCI).
  • Review supplier responses, supporting documentation, certifications, audit reports and security artefacts to identify risks and control gaps.
  • Coordinate assessment activities from initiation through to completion, ensuring appropriate evidence and audit trails are maintained.
  • Prepare risk assessment reports, findings summaries and recommendations for stakeholder review.
  • Liaise directly with suppliers to obtain assessment responses, supporting evidence and clarification of identified risks.
  • Administer vendor assessment questionnaires and support ongoing assessment workflows.
  • Support vendor onboarding, classification and ongoing monitoring activities.
  • Maintain vendor registers, assessment schedules, monitoring requirements and risk documentation.
  • Monitor supplier security ratings, threat intelligence alerts and emerging risks, escalating material concerns where required.
  • Facilitate stakeholder workshops and engagement activities to support risk assessment and governance processes.
  • Support supplier incident investigations, remediation activities and reassessment exercises as required.
  • Contribute to the ongoing improvement of third-party risk frameworks, methodologies, processes and governance artefacts.

Experience & Skills Required:

  • 5+ years' experience within Third Party Risk Management, Technology Risk, IT Governance, Cyber Security, GRC or related disciplines.
  • Experience conducting vendor security assessments, risk assessments or supplier due diligence activities.
  • Strong understanding of Australian Government security requirements including PSPF, ISM, Home Affairs FOCI Guidance, APS AI Plan and DTA AI Policy.
  • Familiarity with NIST Cyber Security Framework, NIST AI Risk Management Framework, ISO 27001 and related standards.
  • Experience reviewing supplier security documentation, audit reports, certifications and assurance artefacts.
  • Knowledge of Australian Government security requirements, including PSPF and ISM frameworks.
  • Strong analytical and investigative skills with a high level of attention to detail.
  • Experience preparing risk assessments, governance reports and executive-level documentation.
  • Strong stakeholder management skills with the ability to work across technology, procurement, legal, privacy and business teams.
  • Proven ability to manage multiple assessments and competing priorities simultaneously.
  • Professional certifications such as CRISC, CISA, CompTIA Security+, ISO 27001 Lead Implementer/Auditor or similar are desirable.

Mandatory Requirements:

  • Current NV1 Security Clearance, or the ability to obtain and maintain an NV1 Security Clearance.
  • Ability to handle sensitive information and apply sound judgement in accordance with security, privacy and governance requirements.

If you feel this opportunity matches your skills and previous experience, please apply with your CV.

Candidates must possess existing Australian working rights (Citizens and be able to obtain NV1 Clearance) and live in the Greater Sydney Area.

Apply Now

File types: PDF, Microsoft Word or text