Head of Service Providers Risk Management

1 week ago


Sydney Central Business District, Australia HCF Full time

**About HCF**

At HCF, our purpose is to bring our human touch to healthcare. Since 1932 we’ve been putting our members and their health first. As Australia’s largest not-for-profit health fund, we cover over 1.7 million members with health, life, travel and pet insurance and our vision is to make healthcare understandable, affordable, high quality and member centric.

We want to be true health partners to our members, easily guiding the healthcare choices that are right for them. At HCF, our values are the way we do things and create the necessary culture to help us realise our purpose and deliver our 2025 Strategy. Living our values in action we step forward, walk in their shoes, stay human, make it better and get there together.

**About the role**

The Head of Service Providers Risk Management is responsible for ensuring the security and resilience of the services provided to HCF by external service providers that support business operations and objectives. They will oversee and manage the risk processes for the external service providers that support the business operations and objectives. The Head of Service Providers Risk Management will oversee the cyber risk assessment, mitigation, and monitoring of the 3rd party and 4th party service providers, data storage and ensures compliance with the contractual obligations and regulatory requirements. The Head of Service Provider Risk Management must work closely with legal and compliance teams to ensure that all aspects of CPS requirements such as 230 and 234 are met, and that the organisation's outsourcing practices align with the regulatory framework.

**About you**

To be successful in this role, you will demonstrate the following qualifications, experience and skills:

- Must have Bachelor’s degree in Computer Science or an equivalent engineering discipline.
- Minimum of 8 years of experience in vendor/service provider risk management, with a focus on cyber risk management & reporting.
- Proven experience in leading the development and implementation of a vendor cyber risk management program.
- Strong knowledge of cyber security risks, threats and mitigation strategies.
- Excellent leadership, communication, and interpersonal skills.
- Strong verbal and written communication skills.

**Responsibilities**

The responsibilities of this role include but are not limited to the following:

- Conduct a thorough review of the service providers (3rd party and 4th party) risks, security posture, practices, and processes, and use this information to make informed decisions about risk.
- Ensuring that the organization is in full compliance with the upcoming CPS 230 regulations.
- Collaborating & supporting the relevant IT stakeholders and liaising with legal and procurement teams to ensure that contracts with service providers include appropriate risk management provisions, including service level agreements security requirements, data protection clauses, and termination clauses.
- Develop and implement the strategy and framework for managing the cyber security of the 3rd party and 4th party service providers across the organization
- Establish and maintain effective governance, risk management, and performance monitoring processes for the cyber security of the third-party service providers.
- Negotiate, review, and approve contracts, service level agreements, and key performance indicators with the 3rd party & 4th party (if relevant) service providers, ensuring that they include adequate cyber security clauses and controls.
- Communicate and collaborate with internal stakeholders, such as business units, IT service management, security teams, legal, compliance, and audit teams, to ensure alignment and coordination of the cyber security management activities.
- Manage and resolve issues, disputes, and escalations with the third-party service providers related to cyber security incidents or breaches.
- Identify and implement opportunities for cost optimization, service improvement, and innovation with the third-party service providers in terms of cyber security.
- Conduct regular assessments and audits of the third-party service providers (and if required for 4th party) to ensure compliance, quality, and security standards are met.
- Provide regular reports and feedback to senior management on the cyber security performance, risks, and issues of the third-party service providers.
- Regularly assess the security posture of service providers, including regular penetration testing and vulnerability assessments, to identify and remediate any potential security risks.
- Continuously monitoring the performance and compliance of service providers throughout the life of the relationship. This involves tracking key performance indicators (KPIs) and addressing any issues or deviations promptly.
- Developing and implementing strategies to mitigate identified risks associated with service provider relationships. This may include contingency plans, alternative vendor opti



  • Sydney, Australia Compliance and Risk Management Recruitment Full time

    Banking & Finance - Treasury and/or Risk Specialist - Sydney - Permanent / Full Time **26th February, 2024**: We are working with a growing mutual bank who are currently seeking a Risk and Compliance Manager for a newly created role in their Sydney head office. Key Responsibilities: - Developing and supporting compliance and testing frameworks. - Helping...


  • Brisbane Central Business District, Australia Corporate Travel Management Full time

    **About CTM** CTM is an award-winning provider of innovative and cost-effective travel management solutions to the corporate, events, leisure and loyalty travel markets. Its proven business strategy combines personalised service excellence with client-facing technology solutions to deliver a return on investment to clients. CTM was founded in 1994 in...


  • Brisbane central business district, Queensland, Australia Corporate Travel Management Full time

    About CTMCTM is an award-winning provider of innovative and cost-effective travel management solutions to the corporate, events, leisure and loyalty travel markets. Its proven business strategy combines personalised service excellence with client-facing technology solutions to deliver a return on investment to clients. CTM was founded in 1994 in Brisbane,...

  • Risk Manager

    2 weeks ago


    Sydney, Australia Compliance and Risk Management Recruitment Full time

    Banking & Finance - Other - Sydney - Permanent / Full Time **21st February, 2024**: **This is an exciting opportunity join a growing listed Financial Institution in Australia. This role plays a pivotal role in supporting the business deliver to its go to market plan, regulatory obligations, and strategic objectives**. **Key Responsibilities** - Delivering...


  • Sydney Central Business District, Australia HCF Full time

    Reporting to the Chief Information Officer, the Head of IT Risk, Audit and Governance will be responsible for overseeing and managing all aspects of technology-related risks and governance to ensure the effective and secure operation of HCFs information technology systems. The role will play a key role in identifying and mitigating IT-related risks,...


  • Sydney, Australia Risk Leadership Network Full time

    Would you like to be part of an innovative, fast-growing business that drives leading risk practice among CROs and heads of risk management at some of the largest companies in the world? We are looking for a Risk Engagement Manager to join our growing global membership network. Risk Leadership Network supports organisations throughout APAC, UK/Europe and...


  • Sydney, Australia Tyro Full time

    **Why work for us** We're not just like every other bank. Tyro has always been a tech company at heart, but fostering a diverse and inclusive environment, and a passion for continuous learning has always been one of the most important parts of our company's culture. Tyros are a highly collaborative mix of people. You will work closely with our awesome...


  • Sydney, Australia Tyro Full time

    **Why work for us** We're not just like every other bank. Tyro has always been a tech company at heart, but fostering a diverse and inclusive environment, and a passion for continuous learning has always been one of the most important parts of our company's culture. Tyros are a highly collaborative mix of people. You will work closely with our awesome...


  • Sydney Central Business District, Australia Motion Recruitment Full time

    Sydney CBD NSW- Full time- $140,000 - $170,000 Annually- Key Government Vendor - IT Cyber Security team - Hybrid work A key Government Vendor has an opening within its IT Cyber Security team for a ICT Risk and Compliance Lead, reporting directly to the Head of Cyber Security. The Role key responsibilities will include: - Maintain and recertification of...


  • Sydney Central Business District, Australia Guild Group Full time

    Job Number: - 493278 Work type: - Full Time Permanent, Part Time Permanent **Location**: - Sydney (CBD), Brisbane, Melbourne (CBD) Categories: - RIsk, Audit & Compliance **Location**: Can be based in Melbourne, Sydney, or Brisbane **Role type**: Full Time Permanent role but open to those seeking 4 days/week **Way of Working**: 2 days per week in...


  • Sydney, New South Wales, Australia Roman Health Pharmacy LLC Full time

    Why work for usWe're not just like every other bank. Tyro has always been a tech company at heart, but fostering a diverse and inclusive environment, and a passion for continuous learning has always been one of the most important parts of our company's culture.Tyros are a highly collaborative mix of people. Youwill work closely withour awesome teams and...

  • Chief Risk

    1 week ago


    Sydney, New South Wales, Australia Compliance and Risk Management Recruitment Full time

    Government / Local Government Local Government Sydney Permanent / Full Time17th April, 2023:Our client is a leading council that is currently undertaking a large transformation and uplift across the organisation. After a recent restructure that have a newly created Chief Risk & Audit Officer role available for a highly skilled and pragmatic Risk & Audit...

  • Head of Risk

    1 week ago


    Sydney, Australia Mitalent Full time

    **The Company** My client owns and operates one of Australia's largest niche Retail operations and is recognised as a world leader within their industry. They provide an environment that supports competitive trade and effective services across their Retail arm. Their aim is to achieve operational excellence via innovation and business development together...


  • Sydney, New South Wales, Australia Sigma Resourcing Pty Ltd Full time

    Risk Manager- Head of Risk & Compliance.6 months contract Rate: $1,200 to $1600/day + super Sydney CBD- Hybrid PURPOSEThis role is responsible for the second line risk and compliance assurance activities which provide monitoring and evidence-based assurance on the design and operating effectiveness of the enterprise risk, compliance and governance frameworks...

  • Compliance Manager

    2 months ago


    Sydney, Australia Compliance and Risk Management Recruitment Full time

    Insurance - Insurance - Life / Health - Sydney - Contract **08th May, 2023**: **About**: World leading insurance business is currently seeking a Compliance Manager (AVP) to help support the Australian entity. **Your role** - Reporting to the Head Compliance, you will perform a critical role within. - To provide responsive, efficient, practical, commercial,...

  • Head of People

    3 weeks ago


    Brisbane Central Business District, Australia HAYS Full time

    Passionate NFP looking for a Head of P&C to Lead and support the organisation, Brisbane based. **Your new company** We have partnered with a passionate and growing not-for-profit organisation located in inner-city Brisbane who is seeking a Head of People and Culture to join the team on a permanent basis. **Your new role** Reporting to the Director of...

  • Compliance Manager

    1 week ago


    Sydney, New South Wales, Australia Compliance and Risk Management Recruitment Full time

    Insurance Insurance Life / Health Sydney Contract08th May, 2023:About:World leading insurance business is currently seeking a Compliance Manager (AVP) to help support the Australian entity.Your role Reporting to the Head Compliance, you will perform a critical role within. To provide responsive, efficient, practical, commercial, and highquality compliance...

  • Head of Cyber, Risk

    1 week ago


    Hills District, Australia Baptistcare WA Full time

    Head of Cyber, Risk & Compliance | Norwest:Hills District North West Sydney, NSW, Australia, 2153Sydney, NSW, AustraliaPermanent Full-TimeAdd To Favourites- Permanent full-time position | Based in Norwest Flexible/hybrid working:Join an industry leading Business Technology Solutions team:- Well known Not-for-profit who put people at the centre of everything...


  • Sydney Central Business District, Australia u&u Recruitment Partners Full time

    About the Company An excellent opportunity to join a medium sized financial service organisation with a well-respected brand. As the new Head of PMO you will be responsible for managing and providing expert support on complex projects. About the Role Manage and oversee the Program Management Office, ensuring that all projects are delivered on time and...


  • Sydney, Australia Australian Payments Plus Full time

    **The Game Changers**: At AP+ we're changing the game! We're doing big things, and we can't do it alone. We're part of a big ecosystem, and we know teamwork and passion for our purpose is what will make us successful. We value the unique talents, perspectives, of all our employees. This includes people of all gender identities and sexual orientations, First...