
Information Security Analyst
3 days ago
Challenger Limited is an ASX-listed investment management firm managing $123.9 billion in assets (as at 30 June 2025). Life with us is fast moving and always exciting. Together we’re driving to deliver our vision to provide our customers with financial security for a better retirement._
- We achieve this goal by providing a work environment where people from diverse backgrounds, with a range of skills and experiences can contribute and succeed._
Information Security Analyst - Third Party Risk & Controls Testing
Location: Sydney CBD (Hybrid)
Team: IT Risk & Security
Reports to: Manager, IT Risk & Compliance- We’re looking for a proactive, curious, and driven Information Security Analyst to join our IT Risk & Security team.- This is a great opportunity for someone with a strong audit or Big 4 background — or someone already in a similar role — who’s ready to move in-house and broaden their skillset in a dynamic, fast-paced environment.- We work flexibly from our Sydney CBD office, typically 3 days in-office and 2 days from home.
About the Role
This role is all about managing and mitigating the information security risks that come with working across a complex third-party ecosystem. You’ll help ensure our external partners meet Challenger’s standards, support regulatory compliance, and contribute to stronger governance and operational resilience across the business.
What you’ll be doing- Third-party risk management: Assess vendor security practices, conduct gap analyses, and drive governance improvements using frameworks like ISO27001, NIST, and CIS.- Controls testing: Help build maturity in our internal controls testing program, linking findings to risks and supporting the rollout of our new GRC system, Archer.- Due diligence & assurance: Respond to inbound and outbound due diligence requests, review certifications and audit reports, and support APRA queries (CPS230, CPS234).- Incident response & compliance: Contribute to incident investigations involving third parties and ensure compliance with internal policies and external regulations.
What’s exciting right now- Archer (our new GRC System) is going live, and you’ll help set up automated third-party risk processes and assessments.- You’ll be involved in major workstreams including the Copilot & agents automation project and the BCP module rollout.- The role offers visibility across the entire security division and the chance to shape how we manage cyber and operational risk.
What we’re looking for
We’re looking for a thoughtful and curious professional with a solid foundation in information security and third-party risk management, who’s ready to take ownership, grow their expertise, and contribute across a broad security and governance landscape.
As well as- Experience in information security and IT risk, ideally within financial services- Understanding of third-party risk management (TPRM) principles and practices- Familiarity with control standards and frameworks such as ISO27001, NIST CSF, SOC 1 & 2, and ASAE3402-
- Experience or interest in conducting due diligence and assurance activities, including reviewing certifications, audit reports, and penetration test results- Ability to support a controls testing program, including assessing design and operating effectiveness, and reporting on control maturity- Good grasp of general IT principles and technologies, and how they intersect with risk and compliance- Strong communication and stakeholder engagement skills — working closely with internal teams and external vendors to ensure alignment and accountability- Initiative to take ownership of tasks and contribute to process improvement- A growth mindset — this role offers exposure across the entire security division and a pathway into broader information security and governance programs
Why this role matters- Manages third-party risk: Ensures our external partners meet Challenger’s security and compliance standards.- Supports regulatory compliance: Helps us meet obligations under CPS230, CPS234, and other relevant frameworks.- Strengthens operational resilience: Minimises disruptions from third-party incidents and improves visibility of risk across the supply chain.- Drives governance and assurance: Contributes to better decision-making through structured controls testing and risk reporting.
Why Challenger?
At Challenger, we’re small enough to be agile, but big enough to accelerate bold ideas. We support your growth and development, offering flexibility and a culture that values your unique contributions.- Discretionary bonus scheme- 18 weeks paid parental leave for all new parents- Challenger Day - one extra day off every year in recognition of the effort our people make.- Additional support leave (fertility, gender affirmation)- Extra superannuation contributions- Employee share plan- Employee Assistance Programme- Subsidised on-site café and central location near Martin Place Metro- Access to free onsite yoga, mindfulness and Pilates classes
-
Information Security Analyst
22 hours ago
Sydney, Australia Anton Murray Consulting Full timeSydney- Ancillary Areas- PermanentOur client is a global financial services company seeking a Senior Information Security Analyst to join their Sydney team located in Rosebery. As a **Senior Cyber Threat Analyst**, you will be given the opportunity to join a team of security analysts about both traditional and unconventional ways to detect, analyze, and...
-
Information Security Analyst
3 days ago
Sydney, Australia Goodman Full timeGlobal Market leading FMCG organisation - iconic brands! - We offer a flexible/hybrid work environment - Work for a company heavily investing in global standard security products The Company Goodman Fielder sits within the Wilmar Group, a global leading Agribusiness Group known for its high quality processed agricultural products. Together, we pride...
-
Information Security Analyst
2 days ago
Sydney, New South Wales, Australia Challenger Limited Full time $80,000 - $120,000 per yearChallenger Limited is an ASX-listed investment management firm managing $123.9 billion in assets (as at 30 June Life with us is fast moving and always exciting. Together we're driving to deliver our vision to provide our customers with financial security for a better retirement.We achieve this goal by providing a work environment where people from diverse...
-
Information Security Analyst
2 days ago
Sydney, New South Wales, Australia CHALLENGER Full time $104,000 - $160,000 per yearChallenger Limited is an ASX-listed investment management firm managing $123.9 billion in assets (as at 30 June Life with us is fast moving and always exciting. Together we're driving to deliver our vision to provide our customers with financial security for a better retirement.We achieve this goal by providing a work environment where people from diverse...
-
Information Security Analyst
3 days ago
Sydney, New South Wales, Australia Challenger Full time $90,000 - $120,000 per yearChallenger Limited is an ASX-listed investment management firm managing $123.9 billion in assets (as at 30 June Life with us is fast moving and always exciting. Together we're driving to deliver our vision to provide our customers with financial security for a better retirement.We achieve this goal by providing a work environment where people from diverse...
-
Information Security Analyst
4 weeks ago
Sydney, Australia The GPT Group Full timeOverview We shape leading experiences across office, retail, logistics and student accommodation. We’re one of Australia’s largest property groups, managing $35 billion worth of assets across the country. Our sustainable returns from investments come from focusing on what matters most to customers — a great experience and doing good. Every day, our...
-
Information Security Analyst
3 days ago
Sydney, Australia Westpac Group Full timeThe Westpac Group has been proudly advancing Australia for two centuries. Our success is built upon both our heritage and our ability to evolve. Our vision is to be one of the world’s great service companies, helping our customers, communities, and people to prosper and grow. We have an exciting opportunity within the Cyber Threat Intelligence team within...
-
Information Security Analyst, Cyber Threat
22 hours ago
Sydney, Australia Westpac Banking Corporation Full timeInformation Security Analyst, Cyber Threat Intelligence **How will I help?** Key responsibilities will include: - Producing clear and concise analytic products on cyber threats, including situation reports and analyst reports. - Identify, analyse and deliver short-turnaround assessments on emerging cyber threat issues. - Providing briefs or presentations...
-
Information Security Analyst
5 days ago
Sydney, Australia Genesis IT&T Pty Ltd Full time**Permanent Full Time**: - **Multinational Corporate Bank**: - **Sydney CBD Office** A prestigious and reputable international bank is currently looking to hire a Information Security Analyst to deliver a highly effective and efficient Security Management (SM) framework for the bank. The responsibilities of this role include daily fulfilment of SM...
-
Senior Information Security Analyst
1 week ago
Sydney, New South Wales, Australia ServiceNow Full time $120,000 - $180,000 per yearCompany Description It all started in sunny San Diego, California in 2004 when a visionary engineer, Fred Luddy, saw the potential to transform how we work. Fast forward to today — ServiceNow stands as a global market leader, bringing innovative AI-enhanced technology to over 8,100 customers, including 85% of the Fortune 500. Our intelligent cloud-based...