← all opportunities

LH-07916

buyict×1

Third-Party Risk Cyber Risk Specialist

1 Third-Party Risk Cyber Risk Specialist

Commonwealth Scientific and Industrial Research OrganisationInvited sellersHybridQLD, NSWcloses in 7 days

1 agency ad is matched to this contract. Sign up free to see which agency is advertising it, why it matched, and the ad itself.

Sign up free

Your CVs matching this role

0

Sign in to see which of your uploaded CVs match this role.

Candidate Search

Find candidates for this role externally, then cache them here.

Sign in to search candidates for this role.

Job description

The Third-Party Risk Analyst will conduct third-party security risk assessments end to end, from vendor intake and tiering through to documented assessment outcomes, identified risks and recommended treatments. The role will work under the direction of the Lead Cyber Risk Specialist and alongside the Cyber Resilience team to support the scale-up of CSIRO’s TPRM Program. Key duties and responsibilities Third-party risk assessments: Conduct third-party security risk assessments across the full lifecycle, including vendor intake, inherent-risk tiering, evidence review, analysis and documented findings. Apply CSIRO’s intake and tiering framework to classify vendors, determine questionnaire requirements and confirm assessment scope. Assess third-party security posture using questionnaires, supporting documentation and externally observable security ratings. Identify, articulate and rate security and information risks to CSIRO, including likelihood, consequence and practical treatment recommendations. Produce clear, structured third-party risk assessment reports suitable for business owners and Cyber Resilience leadership. Use UpGuard to run questionnaire-based assessments, interpret security ratings and translate findings into CSIRO risk language. Platform, tooling & monitoring Use the UpGuard platform to run questionnaire-based assessments, interpret security ratings and category scores, and translate findings into CSIRO risk language. Record and maintain assessment records and medium-or-higher risks in the enterprise risk management platform for ongoing management. Support reassessment scheduling based on vendor risk profile and material changes to a vendor's solution or security posture. Stakeholder engagement & collaboration Engage business owners, service owners, and third-party contacts to gather information, explain findings, and agree remediation owners and due dates. Communicate risk clearly to both technical and non-technical audiences, balancing security assurance with business enablement. Track issues, actions, and stakeholder communications through the team's tooling (for example Jira). Program support Contribute to the continuous improvement of TPRM processes, questionnaires, templates, and assessment methodology. Surface inconsistencies, redundancies, and gaps in process or documentation as they are encountered. Maintain alignment with CSIRO's security classification requirements and relevant Australian Government frameworks throughout all assessment work. Required skills and experience Essential: demonstrated experience conducting third-party, vendor or supplier security risk assessments; sound understanding of inherent and residual risk, likelihood and consequence rating, and treatment planning; ability to assess security controls across encryption, backup and recoverability, access management, vulnerability management, penetration testing and incident response; strong written communication skills; ability to engage technical and non-technical stakeholders; and ability to work independently across multiple concurrent assessments under direction of a lead. Desirable: familiarity with Australian Government security frameworks including PSPF and ISM; working knowledge of ISO/IEC 27001, NIST CSF and Essential Eight; relevant cyber security certification such as CISSP, CCSP, CISM or ISO 27001 Lead Auditor; and awareness of privacy obligations relating to personal information and data breach notification. Criteria The buyer has specified that each candidate must provide a one page pitch to address all criteria specified. This is equal to 5000 characters. Essential criteria 1. a. Suitability of the skills and qualifications for the Role being filled b. Level of applicable experience for the Role being filled c. Team and CSIRO fit for the Role being filled d. Hourly rate and availability Opportunity summary Sellers can submit Up to 3 candidates Number of sellers invited Between 5 and 10 Number of candidates submitted Fewer than 10 Send us feedback About Accessibility Privacy Terms of use Disclaimer and copyright An initiative of the Digital Transformation Agency The Australian Government acknowledges the Traditional Owners of Country throughout Australia and acknowledges their continuing connection to land, waters and community. We pay our respects to the people, the cultures and the Elders past and present. © Commonwealth of Australia

1 match locked

Sign up to see which agency is advertising for this contract, the match evidence, and the ad itself.

Other open contracts for Commonwealth Scientific and Industrial Research Organisation

Related reading