Manager - Third Party Tech & Cyber Risk

4 weeks ago


Sydney, Australia Tal Services Limited Full time

Company Description

Welcome to This Australian Life. 

From the millions of Australians we protect, to those that make it happen every day at TAL, people really are what we’re all about. We want to grow with you. Achieve with you. And support you to do your best work. That's why we're focused on developing leadership, promoting diversity, rewarding excellence and retaining great talent.

We're always looking for people who want to go further with us. People who do what’s right, aim high, and work smart.  Why not see where we can go?

Job Description

The Manager of Third-Party Tech & Cyber Risk will be part of the Technology & Cyber Risk function within the Technology Business Unit and will lead the strategy and execution of our third-party technology risk management, third party cyber security management, relevant technology and cyber clauses within the contractual management process and overall governance of technology third parties. This role is responsible for developing and improving relevant frameworks, policies, practices and controls to maintain the risk posture within the appetite.

Key Accountabilities:

  • Strengthen the Third-Party Technology & Cyber Risk Management Framework and lead the delivery of associated strategy, target state roadmap, and supporting processes and procedures.
  • Conduct in-depth risk assessments and due diligence on potential and existing third-parties to identify risks and compliance gaps.
  • Engage third-parties based on the non-compliance and potential cyber security issues identified via continuous passive security posture management technologies. Conduct risk assessments and develop a plan with the third-parties to remediate non-compliance and/or potential security issues. 
  • Establish and maintain the governance structure for ongoing management of third-party relationships, including regular performance and compliance reviews. 
  • Collaborate with all technology teams to embed effective vendor management practices aligned to the TAL Procurement Procedure and Vendor Management Model.
  • Instituting change in potential areas for improvement for vendor governance, enhancement and upgrade by maintaining a good working knowledge of all services provided to TAL business units.
  • Collaborate with the Cyber Threat Management function and engage material and high risk third-parties to determine their exposure to critical and actively exploited external-facing vulnerabilities, as well as their security posture against emerging attacker tactics and techniques.
  • Assist with the assurance and compliance activities to demonstrate the effectiveness of Third-Party Technology & Cyber Risk Management function. Lead the corrective actions and resolve gaps identified during the assurance and compliance activities.
  • Support and assist with the negotiation, implementation, and management of technology and cyber clauses in the third-party contracts with the Legal. Uplift those technology and cyber clauses in the contractual terms in line with regulatory and threat environment changes, as needed.
  • Monitor and report on third-party compliance with technology and security requirements as well as their performance against contracts, and coordinate the corrective action, as needed.
  • Stay abreast of regulatory changes and industry best practices related to Third-Party Technology and Cyber Risk management to ensure the policies and procedures are up-to-date.
  • Develop and deliver training to internal stakeholders on Third-Party Technology & Cyber Risk Management practices.
  • Collaborate with cross-functional teams, including Technology, Risk (Line 2), Audit, Legal, Compliance, and Procurement, to ensure a cohesive and integrated approach to Third-Party Technology & Cyber Risk Management.
  • Lead, mentor, and develop a team dedicated to Third-Party Technology & Cyber Risk Management function.
  • Deliver the TAL Cyber Security Report to Group Partners to demonstrate TAL’s security posture on an annual basis. Lead the activities required to complete the Report, including but not limited to engaging various parts of Technology and the wider Business Units, collecting supporting evidence, leading interviews/workshops with the independent assessor.
  • Respond to technology risk and cyber security related questions raised by Group Partners through the Business Units on an ongoing basis, and attend periodic governance meetings with the Group Partners as a representative of Technology & Cyber Risk function.
  • Support the RFI/RFP activities led by the Business Units on behalf of Technology & Cyber Risk function.

Qualifications

  • Bachelor's degree in Business, Finance, Information Technology, or a related field. Relevant professional certifications (e.g., CISM, CRISC, CISSP) is a plus.
  • Minimum of 5 years of experience in Third-Party Risk Management, Technology Risk, Cyber Security, or a related field with proven experience of supporting, implementing and managing third party risk management programs.
  • Strong understanding of regulatory compliance standards relevant to third-party risk and security (e.g., APRA CPS234 / CPS230, SOX, ISO 27001, NIST CSF, Privacy Act, SOCI, etc.).
  • Strong communication skills with the ability to translate risk into business impact.
  • Self-starter with strong organisational skills in a highly-adaptive and a fast-paced environment.
  • Customer-oriented mindset and ability to apply collaborative approach to achieving business outcomes.
  • Thinker and doer with a pragmatic approach to make decisions and at the same time focused on outcomes.
  • Ability to lead and motivate both direct and indirect team members, and manage a developing team.

Additional Information

At TAL we value diversity in all its forms and are committed to fostering an inclusive and equitable culture for all our people. We encourage Aboriginal and Torres Strait Islander people, individuals from all backgrounds, including those with caring responsibilities, people living with disability, and individuals from the CALD and LGBTQI+ communities to apply. Even if you don’t check every box in the criteria above, we encourage you to apply today or get in touch with us here.   

To provide you with the best experience, we can accommodate you at any stage of the recruitment process. Simply inform our Recruitment team at any time.  

TAL is recognised by the Workplace Gender Equality Agency as an Employer of Choice.  We are proud to be a member of Diversity Council Australia and the Australian Network on Disability. For information on our reconciliation journey, take a look at our Innovate Reconciliation Action Plan.  

We acknowledge the Traditional Custodians of the Land in which our Head Office is based, the land of the Gadigal people of the Eora Nation, and recognise their deep connections to the land, sea, and culture.  
We extend this acknowledgment to the many Traditional Lands that we operate across and pay our respects to Elders past, present, and emerging.

Everyone at TAL has a responsibility to do the right thing and is accountable for the way they conduct themselves. Our expectations are that you follow the principles set out in our Code of Conduct when you come to work every day. Risk management is everyone’s responsibility.

If you are already a TAL employee please apply via the SmartRecruiters button in Workday and navigate to the Employee Portal. This is important to ensure that your application is recorded accurately.


  • Manager, Risk

    4 weeks ago


    Sydney, Australia Bank of Queensland Full time

    **About the Role** The role of the Manager Risk - Third Parties has the primary accountability for providing risk advice and guidance, and for assisting Management in the analysis, identification, assessment, mitigation, management and reporting across all relevant risk matters, issues, and incidents within the third party stream of the Retail Banking...

  • Cyber Governance

    4 weeks ago


    Sydney, Australia AMP Limited Full time

    The Cyber Governance & Metrics Analyst is responsible for assisting with AMP’s internal processes that provide assurance to our stakeholders that their information assets are appropriately secured. **How you will make an impact** - Lead monthly governance meetings with senior stakeholders, to ensure they are meeting the Cyber metric targets for their...

  • Risk Advisor

    7 days ago


    Sydney, Australia Reserve Bank of Australia Full time

    More change, less staticYou will join a team of Risk Management specialists in the Operational and Strategic Risk team as part of the Risk Management and Compliance Department at the RBA.As a Risk Advisor for Third Party Risk,you will provide Line 2 risk and controls assurance support in Third-Party / Vendor Risk Management. You will engage business leaders...

  • Risk Strategy

    2 weeks ago


    Sydney, Australia KPMGau Full time

    **Job Description **Our Risk Strategy & Technology team is dedicated to helping clients achieve commercial outcomes by viewing risk management as a lever for enhanced innovation, reputation, and sustainable growth. Our areas of expertise include Risk Strategy - understanding risk capacity to inform strategic direction and decision-making, Governance -...

  • Risk Strategy

    4 weeks ago


    Sydney, Australia KPMG Full time

    Our Risk Strategy & Technology team is dedicated to helping clients achieve commercial outcomes by viewing risk management as a lever for enhanced innovation, reputation, and sustainable growth. Our areas of expertise include Risk Strategy - understanding risk capacity to inform strategic direction and decision-making, Governance - looking at Risk Operating...


  • Sydney, Australia Michael Page Full time

    Partner with and evolve our key third party carrier arrangementsBrilliant exposure to key stakeholder helping drive solutions to our 3PL.About Our ClientThis company is a leading food manufacturer and distributor, specialising in the production and supply of quality bakery ingredients and pre-mixes. With a diverse range of products catering to various...


  • Sydney, Australia AMP Limited Full time

    **About the opportunity** Reporting to the Director of Technology Strategy, Architecture and Performance, in this role you will lead the governance model for AMP Technology, to ensure cohesive and engaged management. You will work with stakeholders across our Technology business and prepare relevant materials for interactions with Boards and Executive...


  • Sydney, Australia Michael Page Full time

    About Our Client This company is a leading food manufacturer and distributor, specialising in the production and supply of quality bakery ingredients and pre-mixes. With a diverse range of products catering to various industries, including food service, retail, and industrial customers, Allied Pinnacle focuses on delivering high-quality, innovative...


  • Sydney, Australia J2 Recruitment Full time

    IT & Telecomms - IT Security - Sydney - Permanent / Full Time 2/2/2023 - Cyber Security / Information Security Adviser - Large Scale ICT Applications, Infrastructure & CloudOps - Multi-Project Consulting / Risk Assessments / Threat Testing With a host of new technology and integration initiatives planned over the next 12-36 months, the organisaiton...


  • Sydney, Australia WTW Full time

    Associate - Cyber and Technology - Sydney, AU September 06, 2023 **The Role** - Helping clients understand critical technology risks and their needs across risk consulting, advisory and insurance placement - Supporting the placement of large, complex programs in the financial lines marketplace - Publication of thought leadership, articles and participation...


  • Sydney, Australia LGT Crestone Wealth Management Full time

    Min Experience- 5 yearsYour Role Cyber Security Operations - Collaborate with the outsourced security operations center (SOC) - Ensuring advanced threat technologies are configured to vendor specifications, alerts are reviewed and acted upon, and underlying processes and technologies are continuously refined to keep up with evolving risk. - Be a key contact...

  • Gst Manager

    3 days ago


    Sydney, Australia AMP Limited Full time

    **GST Manager** - Opportunity to be part of a team that achieves together - Your new ideas and ability to change and improve will be appreciated AMP is transforming and we would like you to be part of our journey **Our Division** Tax is accountable for advising on tax impacts on products, pricing and commercial arrangements, managing tax risks, and tax...


  • Sydney, Australia AMP Limited Full time

    **The opportunity** This role will ensure AMP Bank has the optimal mortgage product features and pricing to meet its growth and margin targets and overall strategy. The role includes contributing to the delivery of product strategy, pricing, continuous improvement, and operational execution. **How you will make an impact** - Support the Senior Product...


  • Sydney, Australia AMP Limited Full time

    **The opportunity** Everyday Banking Tribe is responsible for development, distribution and serving of deposit products and payments. The purpose of this role is to manage transactional and savings products end to end including relevant collateral management, pricing and modifications of any existing product features. **How you will make an impact** - Grow...


  • Sydney, Australia AMP Full time

    Be part of a high performing team Location: Sydney Initial 3 Month contract The opportunity The Senior Financial Accountant part of the wider Group Finance Team and is responsible for the provision of statutory reporting, regulatory reporting, and accounting and finance service functions for all areas of AMP and collaborates regularly with other Group...


  • North Sydney, Australia Ventia Pty Limited Full time

    **Cyber Security Operations Manager**: - Date: 1 Nov 2023- Location: North Sydney, NSW, AU, 2060- Company: Ventia- **Use leading edge security tools to work on exciting projects**: - **Flexible start and finish times & work from office/ work from home split**: - **Strong team culture with genuine opportunity for career growth and progression** **About...


  • Sydney, Australia AMP Limited Full time

    **Property Portfolio Manager - **12 Month Fixed Term Contract **The opportunity** Reporting to the Head of Workplace Experience you would be responsible for the strategic management and delivery of leasing transactions in relations to the AMP Workplace lease portfolio. In this role you are going to be overseeing and managing existing portfolio that...


  • Sydney, Australia Whitehaven Coal Full time

    Whitehaven Coal is the dominant player in Australia’s only emerging high quality coal basin. With a culture based on our values of Safety, Teamwork, Respect, Integrity, Value and Excellence, our reputation for excellence in project delivery and safe, efficient and environmentally responsible operations continues to grow. About the Role The Manager Cyber...

  • Risk Manager

    3 days ago


    Sydney, Australia ING Group Full time

    Risk Manager - Business Controls - 12 months fixed term contract ING, Australia's most recommended bank for the 4th consecutive year is on the hunt for an experienced **Risk Manager - Business Controls **to join our high performing **Business Controls Third Party Risk** team. **Please note this is a 12 months fixed term contract role.** As **Risk Manager...


  • Sydney, Australia AMP Limited Full time

    **The opportunity** Everyday Banking Tribe is responsible for development, distribution, and servicing of deposit products, including payments. The purpose of this role is to contribute to the achievement of Everyday Banking Product team growth ambitions and desired customer outcomes. You will be responsible for product development, management and...