Vendor Cyber Risk Manager @ Deloitte
7 days ago
- Great opportunity to work with decision makers at the world's most innovative global consulting firm
- Flexible work arrangements – work in a way that suits you best
- Learn from the best in the business
We are seeking a highly skilled and experienced Cybersecurity Manager to lead our Vendor Cyber Risk Management program. The successful candidate will be responsible for overseeing and enhancing our processes for assessing, monitoring, and mitigating cybersecurity risks associated with third-party vendors. This role requires a strategic thinker with strong technical expertise and excellent communication skills to ensure our vendor relationships are secure and compliant with industry standards.
What will your typical day look like?
Key Responsibilities:
- Vendor Risk Assessment – Conduct cybersecurity risk assessments for vendors, develop a risk framework, and evaluate potential security threats in vendor products/services.
- Risk Mitigation – Implement risk mitigation strategies, ensure vendor adherence to security standards, and monitor compliance with contractual and regulatory requirements.
- Vendor Management – Build strong vendor relationships, conduct security audits, and provide guidance to improve vendor cybersecurity practices.
- Policy & Procedures – Develop and maintain vendor cyber risk policies, ensuring clear communication and enforcement across the organization.
- Incident Response – Collaborate with the Incident Response Team to address vendor-related security incidents and provide detailed analysis for prevention.
- Training & Awareness – Lead cybersecurity training for internal teams, promote vendor risk awareness, and foster a culture of cybersecurity vigilance.
- Reporting & Metrics – Develop reporting mechanisms to track vendor risk status, trends, and mitigation efforts, providing insights to senior management.
About the team:
Our CISO team is a diverse and highly skilled group committed to securing Deloitte against evolving cyber threats. We work across multiple security disciplines to govern, design, defend, operate, and enhance our cybersecurity capabilities, ensuring resilience and regulatory compliance.
This role presents an exciting opportunity to lead and shape the VCRM capability, working closely with the broader security teams to strengthen our third-party risk posture. We foster a collaborative and supportive culture, where innovation and knowledge-sharing are encouraged.
If you're looking for a role where you can make a tangible impact, drive vendor security, and contribute to a strong cybersecurity ecosystem, we'd love to hear from you
You are someone with:
Required:
- Bachelor's degree in Cybersecurity, Information Technology, or a related field.
- Minimum of 5-7 years of experience in cybersecurity, with at least 3 years in a vendor risk management role.
- Relevant certifications such as CISSP, CISM, CRISC, or equivalent.
- Strong understanding of cybersecurity frameworks, standards, and regulations (e.g., NIST, ISO 27001, CIS Controls).
- Experience with cybersecurity risk assessment tools and methodologies.
- Excellent analytical, problem-solving, and decision-making skills.
- Strong interpersonal and communication skills, with the ability to work effectively with both technical and non-technical stakeholders.
- Proven ability to manage multiple projects and priorities in a fast-paced environment.
At Deloitte, we focus our energy on interesting and impactful work. We're always learning, innovating and setting the standard; making a positive difference to our clients and our society. We put coaching at the heart of what we do, helping our people grow their careers in any direction – whether it be up, moving into something new, or even moving across the world.
We embrace diversity, equity and inclusion. We have a diverse collection of people from different backgrounds, with different experiences, gender identities, abilities and thinking styles. What binds us together is a shared commitment to value everyone's perspective and to cultivate inclusion; so that our work environment is a safe space we can all belong.
We prioritise flexibility and choice. At Deloitte, you get trust on Day 1. We know our people get their best work done when they're in control of where and how they work, designing their work week around their client, team and personal commitments.
We help you live and work well. To support your personal and professional life, we offer a range of perks and benefits, including retail discounts, wellbeing leave, paid volunteering days, twelve flexible working options, market-leading parental leave and return to work support package.
Next Steps:
Sound like the sort of role for you? Apply now.
By applying for this job, you'll be assessed against the Deloitte Talent Standards. We've designed these standards so that you can grow in your career, and we can provide our clients with a consistent and exceptional Deloitte employee experience globally. The preferred candidate will be subject to background screening by Deloitte or by their external third-party provider.
#J-18808-Ljbffr-
Vendor Cyber Threat Lead
7 days ago
Sydney, New South Wales, Australia Cyber Crime Full timeJob DescriptionCompany OverviewCyber Crime is a leading global consulting firm that specializes in cybersecurity services. Our team of experts helps businesses protect themselves against cyber threats and maintain compliance with industry regulations.We are seeking a highly skilled and experienced Cybersecurity Manager to join our team. The successful...
-
Cybersecurity Risk Management Professional
7 days ago
Sydney, New South Wales, Australia Cyber Crime Full timeOverviewCyber Crime is a global consulting firm that helps businesses navigate the complex world of cybersecurity.We are seeking a highly skilled and experienced Cybersecurity Manager to lead our Vendor Cyber Risk Management program. The successful candidate will be responsible for overseeing and enhancing our processes for assessing, monitoring, and...
-
Cyber Risk Specialist
4 hours ago
Sydney, New South Wales, Australia Optus Full timeJob DescriptionWe are seeking an experienced Cyber Security Specialist to join our National & Cyber Security office. The successful candidate will have strong knowledge of supplier security and risk assessment procedures.This role involves working closely with senior management and cross-functional teams to identify, assess, and mitigate risks associated...
-
Vendor Security Lead
4 hours ago
Sydney, New South Wales, Australia Optus Full timeAbout the RoleWe are currently looking for a highly skilled Cyber Security Specialist to join our team at Optus National & Cyber Security office. As a key member of our team, you will be responsible for managing vendor security and mitigating risks associated with suppliers.You will work closely with our senior management and cross-functional teams to ensure...
-
Cyber Risk Specialist
7 days ago
Sydney, New South Wales, Australia Aon Full timeAon is a global leader in risk management and we are seeking an experienced Cyber Risk Specialist to join our team.This role is responsible for helping to set the strategy in relation to Aon's Cyber Risk endeavours. In this role, you will be executing the provision of Cyber Risk consulting services to a variety of clients within our corporate and global...
-
Cyber Security Risk Management Lead
7 days ago
Sydney, New South Wales, Australia XL CATLIN Full timeAbout the RoleWe are seeking a highly experienced Cyber Security Risk Management professional to join our team as a Senior Cyber Risk Consulting Expert. In this role, you will be responsible for leading the development and implementation of an integrated Cyber Security Risk Management Services Methodology across our business.As a key member of our Cyber Risk...
-
Cyber Defence Risk Manager
7 days ago
Sydney, New South Wales, Australia eFinancialCareers Ltd. Full timeCyber Defence Risk ManagerCommonwealth Bank of Australia, Sydney, AustraliaAre you a Cyber Defence specialist with technical consulting experience relevant to cyber security operations? Are you a Security Engineer, Threat Analyst or Incident Responder who is comfortable reviewing detection logic, incident response playbooks or threat hunting capabilities? Do...
-
Cyber Defence Risk Manager
1 day ago
Sydney, New South Wales, Australia eFinancialCareers Ltd. Full timeCyber Defence Risk Manager Commonwealth Bank of Australia, Sydney, Australia Are you a Cyber Defence specialist with technical consulting experience relevant to cyber security operations? Are you a Security Engineer, Threat Analyst or Incident Responder who is comfortable reviewing detection logic, incident response playbooks or threat hunting...
-
Cyber Risk Consultant
7 days ago
Sydney, New South Wales, Australia Aon Full timeOpportunity for a risk management professional to join our Cyber Consulting teamGreat trajectory to expand and develop as a Cyber subject matter expert consultant under a highly experienced and commendable Cyber leadership teamFull time, permanent opportunity based in SydneyCyber Risk ConsultantThis role is responsible for helping to set the strategy in...
-
Global Cyber Risk Consultant Manager
7 days ago
Sydney, New South Wales, Australia XL CATLIN Full timeAbout Our CompanyAXA XL, the P&C and specialty risk division of AXA, is known for solving complex risks. We provide re/insurance and reinvent it by combining a comprehensive capital platform, data-driven insights, leading technology, and the best talent in an agile and inclusive workspace.We are seeking a highly experienced Cyber Security Risk Management...
-
Technical Cyber Risk Advisor
7 days ago
Sydney, New South Wales, Australia eFinancialCareers Ltd. Full timeCyber Defence Strategic Risk ManagerWe are seeking an experienced Cyber Defence Strategic Risk Manager to join our team. As a senior member of the Cyber Defence Risk team, you will be responsible for providing strategic risk management advice to cybersecurity teams across the Group.Your primary focus will be on identifying, assessing, and mitigating...
-
Cyber Risk Consultant Leader
5 days ago
Sydney, New South Wales, Australia XL CATLIN Full timeKey ResponsibilitiesThe successful candidate will have a strong background in Cyber Risk Consulting and will be responsible for designing and implementing customized risk management frameworks for each client. You will lead the development and implementation of an integrated cyber security risk management services methodology to ensure a consistent approach...
-
Senior Cyber Risk Consultant
7 days ago
Sydney, New South Wales, Australia XL CATLIN Full timeJob DescriptionJob Number:Senior Cyber Risk Consultant (20250031D20240705)DISCOVER your opportunityAustralia, Singapore and Hong KongAt AXA XL, we offer more than 30 lines of business across Property, Casualty and Specialty risk, insuring companies with the most complex risks across different territories. Our desire is to continue growing to ensure we are...
-
Cyber Security Specialist
3 hours ago
Sydney, New South Wales, Australia Optus Full timeWe are seeking a highly skilled and motivated Cyber Security Specialist to join our National & Cyber Security office. This role focuses primarily on Supplier Security and involves a wide range of compliance and security governance functions. You will work closely with senior management and cross-functional teams to identify, assess, and mitigate risks...
-
Cyber Risk and Response Expert
6 days ago
Sydney, New South Wales, Australia Australian Prudential Regulation Authority Full timeCyber Risk and Response ExpertAPRA is seeking a seasoned professional to assess cyber risk and response management practices within regulated entities. As part of this role, you will provide expert advice on current and emerging cyber risk and response issues.This position involves participating in the development of information security standards and...
-
Cyber Defence Strategic Risk Manager
7 days ago
Sydney, New South Wales, Australia eFinancialCareers Ltd. Full timeInformation Security Management LeadWe are seeking an experienced Information Security Management Lead to join our Cyber Defence Risk team. As a lead, you will be responsible for developing and implementing information security management policies, procedures, and controls to protect the Group's assets from cyber threats.Your primary focus will be on...
-
Cyber Security Risk Governance Specialist
7 days ago
Sydney, New South Wales, Australia eFinancialCareers Ltd. Full timeCyber Defence Risk ManagerAs a Cyber Defence Risk Manager, you will play a key role within the Cyber Defence Risk team as part of the Security Operational Risk function that supports Group Security.You will partner with the Executive Manager Cyber Risk to provide independent Line 2 advice and assurance and actively uplift capability across the Cyber Security...
-
Cyber Risk Specialist
1 day ago
Sydney, New South Wales, Australia Aon Hewitt Full timeCyber Insurance Executive RoleCyber Solutions is seeking a high-performing insurance executive or consultative broker to join its team as a Client Executive with a focus on Cyber risk.You will work closely with the Cyber Client Manager, Head of Cyber and other key stakeholders to deliver best-in-class Cyber Insurance risk transfer solutions across a...
-
Vendor Settlement Manager
3 days ago
Sydney, New South Wales, Australia Ofload Full timeVendor Settlement ManagerWe're transforming the freight industry at Ofload, and we need your expertise to make it happen. As a Vendor Settlement Manager, you'll play a vital role in overseeing the vendor settlement process for our suppliers.Our goal is to reduce empty truck miles and improve visibility in the supply chain. We're using technology and data to...
-
Senior Cyber Risk Consultant
4 days ago
Sydney, New South Wales, Australia University of New South Wales Full timeAbout the RoleCyber Security Risk Advisors play a crucial role in ensuring the University's ICT services and IT initiatives are secure and compliant with industry standards.ResponsibilitiesManage and assess information security risks associated with ICT services and IT initiativesProvide cyber security subject matter expertise, risk assessment, assurance,...