Supplier Security Consultant

2 weeks ago


Sydney, Australia Commonwealth Bank Full time

**_You are _**_a problem solver with a strong background in cyber security risk and governance. _
- **_We are _**_one of the best and most advanced Cyber Security teams in Australia. _
- **_Together we can _**_contribute to protecting the group, its customers and community. _

**Your business:
The Technology division delivers the Group’s information technology and banking operation functions to ensure the highest levels of customer service through world-class process excellence and technology innovation. Cyber Security protects the bank and our customers from theft, loss and risk events, through effective and proactive management of cyber security, privacy and operational risk.

We support our people with the flexibility to balance where work is done with at least half your time each month connecting in office. We also have many other flexible working options available including changing start and finish times, part-time arrangements and job share to name a few. Talk to us about how these arrangements might work for you.

**Your new team**:
As a Supplier Security Consultant you will be joining the Third Party Security Team, part of the wider Data Breach and Supplier Security Division. Our Primary role is facilitating the assessment of cyber risks in relations of the Group’s third parties and working with the business to ensure the risk is remediated.

The Third Party Security Team, implements, consults, and drives a variety of complex risk and governance initiatives related to the cyber security of our third parties. The Team maintains robust governance activities and frameworks to ensure the Group’s information security risk and compliance objectives are being met.

**Your impact and contribution**:
This role has a focus on third parties and you can expect to be engaging and working with your peers across the Group’s third party landscape as well as like-minded Cyber Security professionals across the Group.

You will support and provide guidance on complex information security, governance, and risk initiatives that involve the third parties who engage with Commbank. This will include (but not limited to) primarily supporting on third party assessments (utilising various tools, resources, and service providers) and working closely with the Manager and Senior Manager in the team across a variety of project initiatives and uplifts.

**You will also**:

- Undertake security assessments to measure the design and operating effectiveness of the security controls of CommBank’s suppliers and partners.
- Identify and documenting supplier security risks and advising on the management of findings through to issue remediation.
- Contribute to continuous improvement activities associated with the group’s supplier and data governance processes.
- Provide reports and insights into findings arising from security assessments.

**We are interested in people who**:
In this role you will bring your extensive experience across security governance and security risk management.

You have the ability to consult with the business on complex security issues to ensure the organisation’s risk and governance objectives are met.

**You will bring**:

- A **genuine curiosity about cyber security **to the role and be able to demonstrate this as part of the recruitment process.
- Experience across **cyber risk and governance highly regarded **but is **not essential **for success in this role.
- Awareness of information security standards such as APRA CPS 234, **NIST CSF, and the ISO 27000 series **.
- **Process improvement mindset **and someone who is curious and keen to help others and looking to build a future career across cyber.

We're aware of some accessibility issues on this site, particularly for screen reader users. We want to make finding your dream job as easy as possible, so if you require additional support please contact HR Direct on 1800 989 696.

Advertising End Date: 04/09/2023



  • Sydney, Australia Commonwealth Bank Full time

    **A critical function within the Commonwealth Bank Cyber Security.**: - **Contribute to securing and enhancing the financial wellbeing of people, businesses and communities**: - **Fantastic opportunity to work with some of the best security minds in the industry** **Your new team** Cyber Security is part of the Technology business unit at Commonwealth...


  • Sydney, Australia Naviro Pty Ltd Full time

    Join a growing cyber security firm - Work on challenging and interesting projects - Be surrounded by like minded specialists in offensive security Sekuro Operations is seeking a full time ‘Consultant’ to join our Offensive Security Team in Sydney, NSW. The role is suited for professionals with experience in manual penetration testing and a passion for...


  • Sydney, Australia Quorum Security Systems Full time

    **Security Cabling Technician** - Quorum Security Systems is a leading Sydney based Security Company specialising in consulting, design, installation and service of state-of-the-art security, CCTV and monitoring systems for corporate, government and commercial clients throughout Australia and the Asia Pacific region._ - Due to recent expansion, we are...


  • Sydney, Australia Duo Security Full time

    Empowering the world to reach its full potential, securely - that's our vision in Cisco Secure. We do this by providing effective security solutions and becoming our customers most trusted partner. Security is everything in a world of evolving threats. Over the next few years, we’re making big investments for a 10x better customer experience and big...


  • Sydney, Australia J2 Recruitment Full time

    IT & Telecomms - IT Security - Sydney - Permanent / Full Time 2/2/2023 - Cyber Security / Information Security Adviser - Large Scale ICT Applications, Infrastructure & CloudOps - Multi-Project Consulting / Risk Assessments / Threat Testing With a host of new technology and integration initiatives planned over the next 12-36 months, the organisaiton...


  • Sydney, Australia Ambition Group Full time

    Cyber Security Consultant - Vulnerability Management (Fixed-Term Contract) 12 months - Starting ASAP Are you passionate about cybersecurity and committed to ensuring safety and trust within a leading financial institution? Do you possess exceptional skills in identifying vulnerabilities and implementing robust processes to mitigate potential risks? If so,...


  • Sydney, Australia The Decipher Bureau Full time

    This global organisation is a leading provider of cyber security solutions and services. With over 20 years of cyber security intelligence, research and general experience, they provide a suite of cyber products and services that are leading edge. They are looking for a Principal Consultant to be a major part of their technical leadership in the ANZ...


  • Sydney, Australia Tag Group Full time

    **Division**:Procurement **Job type**:Supplier Relations Specialist **Location**:Sydney, Australia At **TAG**, our company values matter. Each member of our staff should exemplify **T**eamwork, an **A**mbitious spirit and a **G**enuine attitude. It is important that you have passion for the job you do, as well as a drive to want to do better. In return,...


  • Sydney, Australia M&T Resources Full time

    **Sydney** **IT & Telecomms** IT Security - Deep knowledge of cybersecurity and protection technologies - Strong Knowledge of ISO27001/2, NIST CSF, CIS standards. - Strong understanding of Cloud Security and IAM The individual must possess a working knowledge of current and developing security threats, strong understanding of risk management in a cloud...


  • Sydney, New South Wales, Australia Robert Walters Full time

    Our client is seeking an Information Security Consultant to join their dynamic team. This role offers a unique opportunity to work in a complex IT environment, where you will play an integral part in shaping the future of banking technology. You will be responsible for performing data-driven security reviews, engaging with stakeholders, and streamlining...


  • Sydney, Australia AECOM Full time

    Company Description At AECOM, we’re delivering a better world. We believe infrastructure creates opportunity for everyone. Whether it’s improving your commute, keeping the lights on, providing access to clean water or transforming skylines, our work helps people and communities thrive. Our clients trust us to bring together the best people, ideas,...


  • Sydney, Australia Atlassian Full time

    **Working at Atlassian** **Atlassian can hire people in any country where we have a legal entity. Assuming you have eligible working rights and a sufficient time zone overlap with your team, you can choose to work remotely or from an office (unless it’s necessary for your role to be performed in the office). Interviews and onboarding are conducted...


  • Sydney, Australia Westpac Group Full time

    **How will I help?** Westpac’s Detection and Response team sits within our Information Security Group and is responsible for monitoring and detecting cyber threats. We analyse and respond to attacks from adversaries targeting the Westpac Group or its customers. We are looking for an Information Security Principal Consultant to join the Security...


  • Sydney, Australia Smart Talent Group Full time

    Information Security Lead Our client is a dedicated professional services business with a passion for protecting businesses from cyber threats. Their core values are around trust, integrity, and excellence in delivering and executing the best cybersecurity services. Currently undergoing massive growth and are looking for Information Security Leads for their...


  • Sydney, Australia Launch Recruitment Full time

    Hybrid Working - 3 days in the office 2 days fromt home - ISO experience is essential certified is a beneficial - Insurance Expereince would be an advantage The Information Security, Risk and Complaince Consultant will collaborate with compliance, security, and general IT risks to ensure that IT supports the business objectives of the group, while enforcing...

  • Solutions Lead

    1 month ago


    Sydney, Australia Security Centric Full time

    **Location**: Sydney **Division**: Service Delivery - Advise and shape client cyber security journeys - Report to a Managing Director that wants to hear and support your ideas Lead a skilled team delivering cyber security solutions across projects and long-term managed services clients. **About us** Not all cybersecurity consultancies are alike. At...


  • Sydney, New South Wales, Australia Federal Government Full time

    To assist on the delivery of Government Department's mandate and strategic priorities, our IT Data Delivery Product team is seeking a highly skilled Cloud Security Consultant who will be responsible for ensuring the security, compliance and data privacy of our Azure platform. This role involves developing and implementing robust security measures, providing...


  • Sydney, Australia FourQuarters Full time

    **The Organisation** FourQuarters Recruitment has been exclusively engaged to recruit a Security Awareness and Training Consultant for a very large business with a number of locations in each state across Australia. The industry that this organisation sits in is very interesting with a large attack surface and mission critical systems that are consistently...


  • Sydney, Australia HCF Australia Full time

    Procurement Sustainability and Supplier Risk Manager The Opportunity Working with Procurement and Sustainability stakeholders, you will be responsible for developing and implementing the required processes, documentation, and program of initiatives within our supply base, to deliver on sustainability objectives. This includes net zero initiatives and...

  • Security Specialist

    4 weeks ago


    Sydney, Australia DNX Solutions Full time

    DNX Solutions is an Australian cloud consulting firm focused on cloud transformation projects. At DNX we help clients to build better software by upgrading how delivery is done, leaving behind manual processes and embracing an automated, cloud-native way of working. Our goal is to streamline the delivery process and infrastructure to clients focusing on...