← all opportunities

LH-07945

buyict×1

TPRM Risk Manager

1 TPRM Risk Manager

Australian Prudential Regulation AuthorityInvited sellersHybridNSWcloses in 10 days

3 agency ads are matched to this contract. Sign up free to see which agency is advertising it, why it matched, and the ad itself.

Sign up free

Your CVs matching this role

0

Sign in to see which of your uploaded CVs match this role.

Candidate Search

Find candidates for this role externally, then cache them here.

Sign in to search candidates for this role.

Job description

The Third Party Risk Manager leads the design and assessment of APRA’s third-party risk management capability, with accountability for Foreign Ownership, Control or Influence (FOCI) risk assessments, third-party security assessments and AI risk assessments across new technology procurements and contract renewals. The role provides end-to-end coordination across Procurement, Contract Managers, Legal, Technology, Security, Privacy, Finance, and Line 2 Risk teams, ensuring third-party risks are identified, assessed, endorsed, treated and reported in a consistent, evidence-based and auditable manner. The incumbent is a trusted adviser to senior stakeholders and suppliers, balancing commercial outcomes with APRA’s security, regulatory, operational resilience and risk management requirements. Key duties and responsibilities Own, design and lead cross-functional TPRM workflows spanning Procurement, IT Governance, Enterprise Security, Legal and Contract Manager. Undertake Third-Party Risk Assessments covering Information Security, FOCI and AI risk for new procurements and existing contract renewals, ensuring assessments are complete, risk-based, evidence-supported and progressed to endorsement. Own the development of the third-party risk management governance framework at APRA including questionnaires, assessment methodology and vendor management platform selection and rollout. Periodically review and update questionnaires to reflect the changing threat landscape, government security expectations and relevant DHA directions. Work with Line 2 Risk, IT Governance, Security, Legal and Privacy to obtain appropriate review and endorsement of assessments, while maintaining clear separation of responsibilities and decision records. Engage with suppliers and Procurement to clarify questionnaire responses, request additional evidence and resolve gaps, inconsistencies or unacceptable risk exposures. Partner with Legal, Procurement, Finance, Security, Privacy and Risk teams to identify and negotiate critical security, privacy, resilience, audit, notification, subcontracting, data handling, exit and risk treatment clauses aligned with APRA’s risk strategies. Identify regulatory, security, privacy, operational resilience, concentration, geopolitical and FOCI risks associated with third parties. Develop pragmatic mitigations, record risk decisions and monitor treatments to closure. Lead the selection, implementation and effective use of third-party/vendor management platform to assess supplier security posture, workflow assessments, maintain evidence and support continuous monitoring. Collaborate with incident response teams on supplier-related incidents, supporting impact assessment, supplier engagement, contractual notification, risk escalation, remediation tracking and lessons learned. Maintain accurate records and produce timely reporting on supplier risk status, assessment volumes, ageing, exceptions, treatment, progress, incidents, emerging issues and material risk exposures for operational and executive governance forums. Build effective relationships across APRA and provide clear, actionable advice that supports a seamless contracting experience while embedding proportionate third-party risk management practices. Recommend and implement improvements to third-party risk and contract management processes, controls, templates, guidance, governance, technology and stakeholder experience. Contribute to APRA’s horizon scanning and knowledge management activities, monitoring emerging threats, regulatory developments, government direction, industry practices and technology trends relevant to third-party risk. Develop guidance, playbooks and awareness material for Procurement, Contract Managers, risk owners and technology stakeholders to improve the quality and consistency of third-party risk decisions. Extend governance oversight to address AI-related risks and incidents arising from third-party and vendor arrangements, and drive the automation of third-party risk monitoring to support proactive risk identification, assessment, and reporting Criteria The buyer has specified that each candidate must provide a one page pitch to address all criteria specified. This is equal to 5000 characters. Essential criteria 1. Relevant personnel security capability and delivery approach 2. Quality, experience and suitability of proposed Personnel Security specialist 3. Governance, compliance, privacy and delivery assurance 4. Pricing and Value for money Opportunity summary Sellers can submit Up to 3 candidates Number of sellers invited Fewer than 5 Number of candidates submitted Fewer than 10 Send us feedback About Accessibility Privacy Terms of use Disclaimer and copyright An initiative of the Digital Transformation Agency The Australian Government acknowledges the Traditional Owners of Country throughout Australia and acknowledges their continuing connection to land, waters and community. We pay our respects to the people, the cultures and the Elders past and present. © Commonwealth of Australia

3 matches locked

Sign up to see which agency is advertising for this contract, the match evidence, and the ad itself.

Other open contracts for Australian Prudential Regulation Authority

Related reading