Cyber Security Risk Manager

2 days ago


Sydney, New South Wales, Australia Tal Services Limited Full time

Established in Australia, TAL Services Limited is a leader in the financial services industry. Our company description reveals our commitment to developing leadership, promoting diversity, and retaining great talent.

Welcome to TAL. We want to grow with you. Achieve with you. And support you to do your best work. That's why we're focused on developing leadership, promoting diversity, rewarding excellence, and retaining great talent.

We're always looking for people who want to go further with us. People who do what's right, aim high, and work smart. Why not see where we can go?

**Job Summary**

The Cyber Security Risk Manager will be part of Third-Party Tech & Cyber Risk, which is part of the Technology & Cyber Risk function within the Technology Business Unit. This role will support the manager in aligning to the strategy and execution of our third-party technology risk management, third party cyber security management, relevant technology and cyber clauses within the contractual management process and overall governance of technology third parties. This role is responsible for adhering to and identifying improvements to relevant frameworks, policies, practices and controls to maintain the risk posture within the appetite.

  • Adhere to the Third-Party Technology & Cyber Risk Management Framework and support the delivery of associated strategy, target state roadmap, and supporting processes and procedures.
  • Conduct in-depth risk assessments and due diligence on potential and existing third-parties to identify risks and compliance gaps.
  • Engage third-parties based on the non-compliance and potential cyber security issues identified via continuous passive security posture management technologies. Conduct risk assessments and develop a plan with the third-parties to remediate non-compliance and/or potential security issues.
  • Establish and maintain the governance structure for ongoing management of third-party relationships, including regular performance and compliance reviews.
  • Collaborate with all technology teams to embed effective vendor management practices aligned to the TAL Procurement Procedure and Vendor Management Model.
  • Identifying potential areas for improvement for vendor governance, enhancement and upgrade by maintaining a good working knowledge of all services provided to TAL business units.
  • Assist with the assurance and compliance activities to demonstrate the effectiveness of Third-Party Technology & Cyber Risk Management function. Address the corrective actions and resolve gaps identified during the assurance and compliance activities.
  • Support and assist with the negotiation, implementation, and management of technology and cyber clauses in the third-party contracts with the Legal. Uplift those technology and cyber clauses in the contractual terms in line with regulatory and threat environment changes, as needed.
  • Monitor and report on third-party compliance with technology and security requirements as well as their performance against contracts, and coordinate the corrective action, as needed
  • Develop and deliver training to internal stakeholders on Third-Party Technology & Cyber Risk Management practices

**Requirements**

  • Bachelor's degree in business, Finance, Information Technology, or a related field. Relevant professional certifications (e.g., CISM, CRISC, CISSP) is a plus.
  • Minimum of 2 years of experience in Third-Party Risk Management, Technology Risk, Cyber Security, or a related field with proven experience of supporting, implementing and managing third party risk management programs.
  • Strong understanding of regulatory compliance standards relevant to third-party risk and security (e.g., APRA CPS234 / CPS230, SOX, ISO 27001, NIST CSF, Privacy Act, SOCI, etc.).
  • Strong communication skills with the ability to translate risk into business impact.
  • Self-starter with strong organisational skills in a highly-adaptive and a fast-paced environment.
  • Customer-oriented mindset and ability to apply collaborative approach to achieving business outcomes.
  • Thinker and doer with a pragmatic approach to make decisions and at the same time focused on outcomes.

Our employees are accountable for their actions, strive to find the best outcomes for customers and partners, and value working together to find the best solutions for problems. As part of the recruitment process, there are a number of checks which may be conducted to demonstrate your eligibility for a role at TAL including Criminal History, Bankruptcy, Entitlement to Work, Regulatory and Reference Checks.

TAL values diversity in all its forms and is committed to fostering an inclusive and equitable culture for all our people. We encourage Aboriginal and Torres Strait Islander people, individuals from all backgrounds, including those with caring responsibilities, people living with disability, and individuals from the CALD and LGBTQI+ communities to apply. Even if you don't check every box in the criteria above, we encourage you to apply today or get in touch with us here. To provide you with the best experience, we can accommodate you at any stage of the recruitment process. Simply inform our Recruitment team at any time.

TAL is recognised by the Workplace Gender Equality Agency as an Employer of Choice. We are proud to be a member of Diversity Council Australia and the Australian Network on Disability. For information on our reconciliation journey, take a look at our Innovate Reconciliation Action Plan. We acknowledge the Traditional Custodians of the Land in which our Head Office is based, the land of the Gadigal people of the Eora Nation, and recognise their deep connections to the land, sea, and culture. We extend this acknowledgment to the many Traditional Lands that we operate across and pay our respects to Elders past, present, and emerging.

**Estimate Salary:** $100,000 - $130,000 per annum



  • Sydney, New South Wales, Australia XM Cyber Full time

    About XM CyberXM Cyber is a cutting-edge threat and exposure management solution that empowers organizations to efficiently remediate security risks. Our innovative technology bridges the gap between security and IT teams, providing a unified approach to threat management.We are a SAAS-based cyber security vendor with a long-term vision for the industry,...


  • Sydney, New South Wales, Australia XM Cyber Full time

    About the RoleXM Cyber is a leading provider of continuous threat and exposure management solutions. We are seeking an experienced Channel Manager to join our team in ANZ.The successful candidate will be responsible for building and managing a channel of enterprise cyber security solutions. This will involve working closely with our sales teams and channel...


  • Sydney, New South Wales, Australia XM Cyber Full time

    About the RoleXM Cyber is a pioneering threat and exposure management solution that empowers organizations to efficiently remediate vulnerabilities. Our innovative approach transforms the traditional cybersecurity model by fostering collaboration between security and IT teams. We are a SAAS-based cybersecurity vendor backed by a leading European retailer,...


  • Sydney, New South Wales, Australia Commonwealth Bank of Australia Full time

    Role SummaryWe are seeking a highly skilled Cyber Security Risk Management Leader to join our team. As a key member of our Operational Risk and Compliance team, you will be responsible for providing expert advice and guidance on cyber security risk management across the organisation.Key Responsibilities:Provide SME risk management advice to crews aligned to...


  • Sydney, New South Wales, Australia CYOS Solutions Full time

    Cyber Security Role OverviewCyOS Solutions is seeking a highly skilled Cyber Security Risk Analyst to join their team. This role will involve conducting security risk analysis of internal systems, assessing cyber threats, and implementing better-practice methodologies and risk management practices.Key ResponsibilitiesConduct security risk analysis of NDIA...


  • Sydney, New South Wales, Australia University of New South Wales Full time

    About the RoleThe University of New South Wales is seeking a highly skilled Cyber Security Risk Advisor to join our team. As a key contributor to the operational delivery of a fit-for-purpose and adaptive Cyber Security Governance framework and Information Security Management System (ISMS), you will be responsible for the management and assessment of...


  • Sydney, New South Wales, Australia HiTech Group Full time

    Job Summary:Cyber Security Risk Analyst required to join a multidisciplinary team in a leading Federal Government department. The successful candidate will be responsible for identifying key security risks in the ICT environment and ensuring the department is able to mitigate and be resilient to cyber threat activity.Key Responsibilities:Conducting security...


  • Sydney, New South Wales, Australia Pyramid Global Technologies Full time

    About the RoleWe are seeking a seasoned Cyber Security Risk Management Lead to join our team at Pyramid Global Technologies.This is a challenging and rewarding role that will play a key part in shaping our Information Security Management System (ISMS). As Cyber Security Risk Management Lead, you will be responsible for delivering and continuously improving...


  • Sydney, New South Wales, Australia CYOS Solutions Full time

    Cyber Security Risk SpecialistThe Cyber Security Risk Specialist will play a critical role in identifying and assessing potential security risks to the NDIA's ICT systems. This includes leading security risk analysis, implementing better-practice methodologies, and developing targeted security risk advice to prevent, detect, and respond to cyber threat...


  • Sydney, New South Wales, Australia Commonwealth Bank of Australia Full time

    About the RoleWe are seeking an experienced Cyber Defence Risk Manager to join our Technology and Operations (Tech & Ops) Risk team.Job DescriptionThis is a key role within the Cyber Defence Risk team, supporting Group Security. You will partner with the Executive Manager Cyber Risk to provide independent Line 2 advice and assurance, actively uplifting...


  • Sydney, New South Wales, Australia University of New South Wales Full time

    Job SummaryThe University of New South Wales is seeking a highly skilled Cyber Security Risk Manager to join our team. The successful candidate will be responsible for providing strategic leadership in developing and continuously improving the University's cyber security risk management practices.Key ResponsibilitiesDevelop and Implement Risk Management...


  • Sydney, New South Wales, Australia Pyramid Global Technologies Full time

    About the rolePyramid Global Technologies is seeking a Cyber Security Specialist - Enterprise Risk Management to join our team in Melbourne/Sydney. The ideal candidate will have a minimum of 10 years of experience in cyber security roles within major organizations, focusing on management of governance, risk, and compliance.Key responsibilities...


  • Sydney, New South Wales, Australia TAL Full time

    At TAL, we are seeking a highly skilled Cyber Security Risk Management Specialist to join our team in Third-Party Tech & Cyber Risk. This role plays a critical part in aligning with our strategy and executing third-party technology risk management, cyber security management, and relevant technology and cyber clauses within the contractual management...


  • Sydney, New South Wales, Australia RSM Full time

    About the RoleWe are seeking an experienced Cyber Security Risk Management Specialist to join our team in Australia. In this role, you will be responsible for performing IT / Cyber / technology risk assessments, technical security related reviews, and assessing the effectiveness of processes/controls and risks related to third party organisations.


  • Sydney, New South Wales, Australia University of New South Wales Full time

    About the RoleWe are seeking an experienced Cyber Security Risk Manager to join our team at the University of New South Wales. In this critical role, you will provide strategic leadership in developing and continuously improving our cyber security risk management practices. Your expertise will ensure that risks are continually identified, assessed,...


  • Sydney, New South Wales, Australia University of New South Wales Full time

    About the RoleWe are seeking a Chief Cyber Security Risk Management Strategist to provide strategic leadership in developing and continuously improving our cyber security risk management practices. As a key member of our team, you will be responsible for ensuring that risks are continually identified, assessed, prioritised, monitored, and mitigated in line...


  • Sydney, New South Wales, Australia RSM Full time

    Job SummaryWe are seeking a skilled Cyber Security Specialist to join our team. As a key member of our security team, you will be responsible for managing client relationships, providing expert advice on IT general controls and application controls, and conducting risk assessments.About RSMRSM is a leading professional services firm that connects clients to...


  • Sydney, New South Wales, Australia Qantas Full time

    Job OverviewWe are seeking an experienced Cyber Security Leader to join our team at Qantas, responsible for leading cultural change across the Group to manage cyber as a business and technology risk.About the RoleThe Senior Business Information Security Officer (SBISO) will serve as a trusted advisor and partner to the business and Technology domains. This...


  • Sydney, New South Wales, Australia University of New South Wales Full time

    About the RoleThis is a key contributor to the operational delivery of a fit-for-purpose and adaptive Cyber Security Governance framework and Information Security Management System (ISMS). The role is responsible for the management and assessment of information security risks associated with ICT services and IT initiatives, and the provision of cyber...


  • Sydney, New South Wales, Australia MARS Recruitment Full time

    Job Title: Cyber & Information Security LeadEstimated Salary: $120,000 - $180,000 per yearAbout the RoleWe are seeking a highly skilled and experienced Cyber and Information Security Lead to join our fast-growing organisation. As a key member of our security team, you will be responsible for managing and improving our information security practices, ensuring...