Security Grc Consultant

2 days ago


Docklands, Australia Medibank Full time

**Will you actively create a healthier future for tomorrow?**

At Medibank and ahm we’re encouraged to think big. We have a clear purpose to impact better health outcomes for our customers, patients and our community.

We celebrate diversity of thought because we want to make better decisions for our customers. As we work towards our goal of better health for better lives, we value the knowledge and contribution of Aboriginal and Torres Strait Islanders. We are working hard to create an inclusive workplace and develop Indigenous careers.

**Enterprise Digital**

We are building an expert team to deliver best in class solutions for our customers. Our mission is to “_Create delightful experiences that help our customers achieve better health_”.

**The Opportunity**

Reporting to the Head of Security Consulting, the Third Party Security Consultant is responsible for defining and maintaining the compliance of third-party assurance standards and providing assistance to the Information Security department.

**How will you add value?**

This position will work with a diverse range of stakeholders to ensure Medibank is compliant with relevant industry obligations (e.g., APRA, PCI-DSS, CPS234) and to provide pragmatical advice and guidance on the implementation of IT Security Policies, Procedures, and controls. This will include actively reporting on cyber security third party risks and issues to relevant parties.

**Further requirements will include**:

- Support and evaluation of implemented IT Security Policies, Standards and Procedures across the organisation;
- Ensure implemented Third Party Security Governance is in line with business expectations and overall enterprise risk appetite;
- Maintain the end-to-end process for third party security risk assessments, from triage through to reporting;
- Review and assess third parties for security risk posture and provide guidance to third parties to support alignment to security expectations and industry leading standards;
- Maintain IT Security Risk Registers to continuously track and drive mitigation and resolution efforts;
- Define third party risk metrics and collate insights for reporting through to senior executives and the Board;
- Identify and understand global industry and market influences - medical, insurance, security, threats landscapes, threat intelligence, geopolitical, innovative security technologies.

**What are we looking for?**

You will have prior experience working within or leading the Third Party Risk space and be able to work independently across multiple third parties and business units at one time and be comfortable with ambiguity. You will have a strong understanding of business drivers impacting IT systems and security and an in-depth understanding of risk management. As the third party lead you will have strong stakeholder management and leadership skills and be comfortable collaborating and driving team members and stakeholders to achieve security risk management objectives.

Hands on experience with Assessment Frameworks (ISAF) to align IT with ISO, PCI-DSS, APRA, NIST, ASD and other regulatory requirements is important along with a general understanding of other IT Security controls including SIEM, endpoint software, FWs, IPS, WAF, UBA, Malware or GRC products

**A career with us**

We believe work is something we do, not somewhere we go. Our modes of working - Collaboration, Connection and Concentration - help inform how your day is structured and where you choose to work will vary, depending on your role and requirements.

All employees who may attend a worksite or any face-to-face work-related activity will be required to be fully vaccinated for COVID-19 as a condition of employment.

We offer a range of great benefits such as subsidised private health insurance, rewards and discounts, and health and wellbeing initiatives. To find out more, click here.

**To start small and impact bigger.



  • Docklands, Victoria, Australia Information Security Consultants Full time $104,000 - $160,000 per year

    About the role We are seeking an experienced Business Development Manager - Cyber GRC (Consultancy and Certification) to join our dynamic team at Information Security Consultants' in Docklands, VIC 3008. This full-time role will be responsible for generating new business opportunities and driving growth within our Cyber Governance, Risk and Compliance (GRC)...


  • Docklands, Australia Medibank Full time

    **Will you actively create a healthier future for tomorrow?** At Medibank we’re encouraged to think big. We have a clear purpose to impact better health outcomes for our customers, patients and our community. We celebrate diversity of thought because we want to make better decisions for our customers. As we work towards our goal of better health for...


  • Docklands, Australia Medibank Full time

    **Will you actively create a healthier future for tomorrow?** At Medibank we’re encouraged to think big. We have a clear purpose to impact better health outcomes for our customers, patients and our community. We celebrate diversity of thought because we want to make better decisions for our customers. As we work towards our goal of better health for...


  • Docklands, Victoria, Australia Melbourne Water Full time $120,000 - $180,000 per year

    Who We AreIn Melbourne, water is essential to our way of life.As caretakers for Melbourne's water cycle, we care for water, life and land throughout Melbourne: both its people and its biodiversity.Each time you drink from the tap, flush a toilet, run through a backyard sprinkler, or kayak down the Yarra, we're there. Primed and ready, quietly delivering some...

  • Cyber Assurance

    2 weeks ago


    Docklands, Australia Wesfarmers Health Full time

    At Wesfarmers Health we strive to make health, beauty and wellness experiences simpler, more affordable and easier to access for all Australians. Our portfolio includes well-known names like Priceline and Priceline Pharmacy, as well as our medi-aesthetics brands, Clear Skincare Clinics and SILK Laser Clinics. In the digital space, we’re proud to have SISU...


  • Docklands, Australia Medibank Full time

    **Will you actively create a healthier future for tomorrow?** At Medibank we’re encouraged to think big. We have a clear purpose to impact better health outcomes for our customers, patients and our community. We celebrate diversity of thought because we want to make better decisions for our customers. As we work towards our goal of better health for...


  • Docklands, Victoria, Australia BURGEON IT SERVICES Full time $90,000 - $120,000 per year

    Position: IAM Consultant with Telecom and Network domain experienceLocation: Docklands, Victoria.Duration: 6 monthsJob Details:Must Have Skills:Experience inTelecom Network, OSS & BSS space with experience of identity and access management, resilience, and security complianceDetailed Job Description:Job Title: Lead ConsultantJob Summary:We are seeking a...


  • Docklands, Australia Medibank Full time

    **Will you actively create a healthier future for tomorrow?** At Medibank we’re encouraged to think big. We have a clear purpose to impact better health outcomes for our customers, patients and our community. We celebrate diversity of thought because we want to make better decisions for our customers. As we work towards our goal of better health for...

  • Lead Consultant

    5 days ago


    Docklands, Victoria, Australia INNOVATE IT AUSTRALIA Full time $180,000 - $250,000 per year

    Job Description:Must Have Skills:Experience in Telecom Network, OSS & BSS space with experience of identity and access management, resilience, and security complianceDetailed Job Description:Key Responsibilities:• Drive strategy and implementation of Identity and Access Management (IAM) and resilience initiative.• Ensuring data security and secure and...

  • Senior Risk

    1 day ago


    Docklands, Victoria, Australia MUFG Full time $104,000 - $130,878 per year

    OverviewFirst Line Risk works with key stakeholders to identify, assess and mitigate operational and compliance risks within the Board's appetite. From 1 July 2025 , the new Prudential Standard CPS 230 Operational Risk Management will require strengthened controls, business continuity and service provider oversight.The newly created Senior Analyst role will...