Warning! Be wary of scams. Read our FAQ page for more information.


Third Party Risk Manager

Contract Type

Contract

Location

New South Wales, Sydney

Industry

Public Sector and Government

Specialisation

Government

Salary

+ Super

Contact Name

Louis Goth

Contact Email

louis@talenza.com.au

Date published

24-09-2026

Job Reference

BBBH22651

Description

Our Federal Government client is seeking an experienced Third Party Risk Manager to lead and mature its Third-Party Risk Management (TPRM) capability within a highly regulated environment. This role will be responsible for overseeing supplier risk assessments, developing governance frameworks, managing third-party security, AI and FOCI risk assessments, and partnering with business stakeholders to ensure supplier risks are effectively identified, assessed and managed throughout the vendor lifecycle. The successful candidate will be a trusted advisor to senior stakeholders, balancing commercial outcomes with security, operational resilience and governance requirements.

Role Title: Third Party Risk Manager

Start Date: November 2026

Contract Role Till: 12 Month Initial Contract

Pay Rate: Market Rates

Location: Sydney CBD (2000), a minimum 50/50 split between office and work from home.

Hours of Work: 38 hours per week

Tasks & Responsibilities:

  • Lead and manage the organisation's Third-Party Risk Management capability across the supplier lifecycle.
  • Conduct and oversee third-party risk assessments covering security, privacy, AI, operational resilience and FOCI risks.
  • Design, implement and enhance third-party risk management frameworks, methodologies and governance processes.
  • Develop and maintain supplier assessment questionnaires, risk assessment methodologies and governance artefacts.
  • Partner with procurement, legal, security, privacy and risk teams to ensure robust supplier risk management practices.
  • Engage with suppliers to review assessment responses, gather supporting evidence and resolve identified risk concerns.
  • Identify, assess and manage security, privacy, concentration, geopolitical, operational resilience and supplier-related risks.
  • Lead the selection, implementation and ongoing management of third-party risk management platforms and monitoring capabilities.
  • Support supplier incident investigations, remediation activities and risk treatment plans.
  • Prepare governance reports, executive briefings and risk papers for senior stakeholders and governance forums.
  • Drive continuous improvement initiatives across third-party risk management processes, controls and reporting.
  • Develop guidance materials, playbooks and awareness initiatives to improve third-party risk capability across the organisation.
  • Monitor emerging regulatory requirements, industry trends and evolving threats impacting supplier risk management.
  • Support the governance and assessment of AI-related supplier risks and third-party technology adoption.

Experience & Skills Required:

  • 15+ years' experience across Third Party Risk Management, Technology Risk, Security Risk, Governance, Risk and Compliance (GRC) or related disciplines.
  • Proven experience designing, implementing or operating enterprise-scale third-party risk management frameworks.
  • Strong understanding of supplier risk management across due diligence, contracting, onboarding, monitoring, incident management, renewal and offboarding activities.
  • Experience conducting supplier security assessments and reviewing evidence relating to privacy, resilience, security controls and data management practices.
  • Strong knowledge of Australian Government security frameworks and industry standards including PSPF, ISM, ISO 27001 and NIST frameworks.
  • Experience facilitating cross-functional risk assessments and engaging with executive-level stakeholders.
  • Strong stakeholder management, negotiation and influencing skills across business, risk, legal and technology functions.
  • Demonstrated ability to develop executive reporting, governance papers, risk assessments and decision records.
  • Strong analytical, problem-solving and risk management capabilities within complex and highly regulated environments.
  • Experience balancing commercial objectives with regulatory, security and operational risk requirements.

Desirable Skills:

  • Experience with Third Party Risk Management platforms such as UpGuard, ServiceNow, ProcessUnity, Qualys or similar tools.
  • Experience assessing AI-related risks and governance considerations.
  • Experience assessing FOCI risks and supplier ownership structures.
  • Background within financial services, banking, insurance, government or other highly regulated sectors.
  • Professional certifications such as CRISC, CISA, CISM, AAISM or equivalent industry-recognised qualifications.

Mandatory Requirements:

  • Current NV1 Security Clearance, or the ability to obtain and maintain an NV1 Security Clearance.
  • Ability to handle sensitive information and exercise sound judgement in accordance with organisational security, privacy and governance requirements.

If you feel this opportunity matches your skills and previous experience, please apply with your CV.

Candidates must possess existing Australian working rights (Citizens and be in possession of an existing NV1 Clearance, active or inactive) and live in the Greater Sydney Area.

Apply Now

File types: PDF, Microsoft Word or text