Information Security Analyst
1 day ago
Challenger Limited is an ASX-listed investment management firm managing $123.9 billion in assets (as at 30 June Life with us is fast moving and always exciting. Together we're driving to deliver our vision to provide our customers with financial security for a better retirement.
We achieve this goal by providing a work environment where people from diverse backgrounds, with a range of skills and experiences can contribute and succeed.
Information Security Analyst – Third Party Risk & Controls Testing
Location: Sydney CBD (Hybrid)
Team: IT Risk & Security
Reports to: Manager, IT Risk & Compliance
We're looking for a proactive, curious, and driven Information Security Analyst to join our IT Risk & Security team.
This is a great opportunity for someone with a strong audit or Big 4 background — or someone already in a similar role — who's ready to move in-house and broaden their skillset in a dynamic, fast-paced environment.
We work flexibly from our Sydney CBD office, typically 3 days in-office and 2 days from home.
About the Role
This role is all about managing and mitigating the information security risks that come with working across a complex third-party ecosystem. You'll help ensure our external partners meet Challenger's standards, support regulatory compliance, and contribute to stronger governance and operational resilience across the business.
What you'll be doing
Third-party risk management: Assess vendor security practices, conduct gap analyses, and drive governance improvements using frameworks like ISO27001, NIST, and CIS.
Controls testing: Help build maturity in our internal controls testing program, linking findings to risks and supporting the rollout of our new GRC system, Archer.
Due diligence & assurance: Respond to inbound and outbound due diligence requests, review certifications and audit reports, and support APRA queries (CPS230, CPS234).
Incident response & compliance: Contribute to incident investigations involving third parties and ensure compliance with internal policies and external regulations.
What's exciting right now
Archer (our new GRC System) is going live, and you'll help set up automated third-party risk processes and assessments.
You'll be involved in major workstreams including the Copilot & agents automation project and the BCP module rollout.
The role offers visibility across the entire security division and the chance to shape how we manage cyber and operational risk.
What we're looking for
We're looking for a thoughtful and curious professional with a solid foundation in information security and third-party risk management, who's ready to take ownership, grow their expertise, and contribute across a broad security and governance landscape.
As well as
Experience in information security and IT risk, ideally within financial services
Understanding of third-party risk management (TPRM) principles and practices
Familiarity with control standards and frameworks such as ISO27001, NIST CSF, SOC 1 & 2, and ASAE3402
Exposure to APRA regulations, particularly CPS230 and CPS234, and how they apply to third-party risk and cyber resilience
Experience or interest in conducting due diligence and assurance activities, including reviewing certifications, audit reports, and penetration test results
Ability to support a controls testing program, including assessing design and operating effectiveness, and reporting on control maturity
Good grasp of general IT principles and technologies, and how they intersect with risk and compliance
Strong communication and stakeholder engagement skills — working closely with internal teams and external vendors to ensure alignment and accountability
Initiative to take ownership of tasks and contribute to process improvement
A growth mindset — this role offers exposure across the entire security division and a pathway into broader information security and governance programs
Why this role matters
Manages third-party risk: Ensures our external partners meet Challenger's security and compliance standards.
Supports regulatory compliance: Helps us meet obligations under CPS230, CPS234, and other relevant frameworks.
Strengthens operational resilience: Minimises disruptions from third-party incidents and improves visibility of risk across the supply chain.
Drives governance and assurance: Contributes to better decision-making through structured controls testing and risk reporting.
Why Challenger?
At Challenger, we're small enough to be agile, but big enough to accelerate bold ideas. We support your growth and development, offering flexibility and a culture that values your unique contributions.
Discretionary bonus scheme
18 weeks paid parental leave for all new parents
Challenger Day – one extra day off every year in recognition of the effort our people make.
Additional support leave (fertility, gender affirmation)
Extra superannuation contributions
Employee share plan
Employee Assistance Programme
Subsidised on-site café and central location near Martin Place Metro
Access to free onsite yoga, mindfulness and Pilates classes.
Access to annual free flu shots.
Explore our benefits further:
#LI-KM1
#LI-Challenger
#LI-Hybrid
Challenger's employee value proposition guides how we work: Grow and realise your potential, supporting each other, stronger together and making things happen. Our culture encourages curiosity, considered thinking and meaningful contribution, with opportunities to build a broad and rewarding career.
We are committed to fostering a safe, inclusive and respectful workplace where people of all backgrounds, identities and ways of thinking can thrive, and promoting flexible working to support work-life balance.
Challenger is proud to be a Workplace Gender Equality Agency (WGEA) Employer of Choice for Gender Equality, a Family Friendly Workplace and recognised as a Bronze Employer in the Australian Workplace Equality Index (AWEI), the national benchmark for LGBTQ+ workplace inclusion.
Job type:
PermanentPosting Close Date :
07/11/2025-
Information Security Analyst
24 hours ago
Sydney, New South Wales, Australia Challenger Limited Full time $80,000 - $120,000 per yearChallenger Limited is an ASX-listed investment management firm managing $123.9 billion in assets (as at 30 June Life with us is fast moving and always exciting. Together we're driving to deliver our vision to provide our customers with financial security for a better retirement.We achieve this goal by providing a work environment where people from diverse...
-
Information Security Analyst
20 hours ago
Sydney, New South Wales, Australia CHALLENGER Full time $104,000 - $160,000 per yearChallenger Limited is an ASX-listed investment management firm managing $123.9 billion in assets (as at 30 June Life with us is fast moving and always exciting. Together we're driving to deliver our vision to provide our customers with financial security for a better retirement.We achieve this goal by providing a work environment where people from diverse...
-
Senior Information Security Analyst
1 week ago
Sydney, New South Wales, Australia ServiceNow Full time $120,000 - $180,000 per yearCompany Description It all started in sunny San Diego, California in 2004 when a visionary engineer, Fred Luddy, saw the potential to transform how we work. Fast forward to today — ServiceNow stands as a global market leader, bringing innovative AI-enhanced technology to over 8,100 customers, including 85% of the Fortune 500. Our intelligent cloud-based...
-
Senior Information Security Analyst
1 week ago
Sydney, New South Wales, Australia ServiceNow Full time $120,000 - $180,000 per yearCompany Description It all started in sunny San Diego, California in 2004 when a visionary engineer, Fred Luddy, saw the potential to transform how we work. Fast forward to today — ServiceNow stands as a global market leader, bringing innovative AI-enhanced technology to over 8,100 customers, including 85% of the Fortune 500. Our intelligent cloud-based...
-
Security Operations Center Analyst
1 week ago
Sydney, New South Wales, Australia ITbility Full time $60,000 - $120,000 per yearSOC Monitoring & Incident Response AnalystSydneyContract - 3 + MonthsOur client inSydneyis looking for SOC Monitoring & Incident Response Analyst this is aContract for 3 + Monthsrole. Please email me at for more information.Experience: Minimum of 3 years of hands-on experience working in a Security Operations Center (SOC) environment, with a strong focus on...
-
Senior Information Security Analyst
1 week ago
Sydney, New South Wales, Australia ServiceNow Full time $120,000 - $180,000 per yearCompany Description It all started in sunny San Diego, California in 2004 when a visionary engineer, Fred Luddy, saw the potential to transform how we work. Fast forward to today — ServiceNow stands as a global market leader, bringing innovative AI-enhanced technology to over 8,100 customers, including 85% of the Fortune 500. Our intelligent cloud-based...
-
Cyber Security Analyst
7 days ago
Sydney, New South Wales, Australia CareCone Australia Full time $80,000 - $120,000 per yearRole: Cybersecurity AnalystLocation: Sydney, NSWEmployment Type: PermanentMust have:Full working rights. No sponsorship available.Job Summary:We are seeking a skilled Cybersecurity Analyst with a strong focus on Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) to manage Business As Usual (BAU) tasks. The ideal candidate will have a solid...
-
Lead Cyber Security Analyst
2 weeks ago
Sydney, New South Wales, Australia AbiShar Technologies Pty Ltd Full time $120,000 - $180,000 per yearAbout the Role:We are seeking a highly skilled Lead Cyber Security Analyst to head our security operations and guide the analyst team in defending against advanced cyber threats. This role combines hands-on technical expertise with leadership, requiring you to oversee incident response, threat intelligence, and vulnerability management while ensuring...
-
Cyber Security Analyst
3 days ago
Sydney, New South Wales, Australia AI Talent Full time $80,000 - $140,000 per yearJob DescriptionWe are looking for a seasoned and highly capable Senior Cyber Security Analyst to join our team. In this key role, you will be responsible for protecting the organisation's systems, networks, and data against evolving cyber threats. Your deep knowledge of cyber security frameworks, risk management, incident response, and operational security...
-
Cyber Security Analyst
7 days ago
Sydney, New South Wales, Australia N2S Full time $90,000 - $120,000 per yearCybersecurity Analyst Zscaler ZIA and ZPAWe are seeking a skilled Cybersecurity Analyst with a strong focus on Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) to manage Business As Usual (BAU) tasks. The ideal candidate will have a solid background in cybersecurity, specifically in Zscaler Web Security, and will be responsible for handling...