UpGuard is hiring a

Third Party Security Risk Analyst

Sydney, Australia
Full-Time
Why are we hiring this role?

We have successfully implemented third party security managed services for our customers and are looking to scale these efforts therefore need to scale the team!

In this role you will:

  • Translate complex and technical aspects into a report so that the business can understand it.
  • Partner with customers to identify, measure and manage Third Party risks and controls.
  • Assist with standardised reports, templates and scorecards used to inform customers on third party risks.
  • Work closely with various teams including, sales and customer success to understand the changing needs of our customers.
  • Develop and maintain working knowledge of emerging financial, operational, third party and regulatory/compliance related information to contribute to the continuous improvement of the Third Party risk management offering.

What do we need from you:

  • Strong knowledge of relevant security frameworks, standards, US requirements, US laws e.g. ISO 27001, PCI DSS, NIST CSF, HIPAA etc.
  • Thorough understanding of cybersecurity risk management.
  • 2-3+ years of experience in Risk Management, Third Party Risk, Auditing, Consulting or the equivalent.
  • Understanding of Third Party risk management practices, including the lifecycle of risk identification, treatment, mitigation, acceptance, remediation as well as inherent and residual risks.
  • Have a track record of mastering highly technical problem spaces.
  • Possess strong written and verbal communication skills, with a talent for precise articulations of customer problems.
  • Customer Service experience for managing customer relationships.

What would give you an edge:

  • Bachelor Degree in the fields of Information Technology or Systems or related major.
  • Any relevant professional certification, such as Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), Certified in Risk and Information Systems Control (CRISC), Certified Regulatory Vendor Program Manager (CRVPM) or Certified Third Party Risk Professional (CTPRP).
  • Performed data leaks assessments.
  • Experience in managing customer expectations.
  • Experience in performing Third Party Security Risk Assessments.
  • Experience or a keen interest in cybersecurity.

What's in it for you?

  • Hybrid or Remote: you choose.  While we have offices in Sydney & Hobart, we don’t mandate how often you need to be there.  We focus on what you deliver, not where you deliver it from.  
  • Impact: Influence the direction and design of projects that push the boundaries of your field and see the impact of your work daily.
  • Be part of an energetic team: Our team is highly collaborative, fostering a positive work environment that encourages creativity and innovation.
  • We value work-life balance: We recognize the importance of maintaining balance and provide a supportive work environment that allows you to prioritize your personal life and well-being.
  • Generous reward: We offer a competitive salary + equity 
  • Great perks: You won’t find table tennis tables or office mandates - we prefer to offer perks that support your overall well-being - including a lifestyle allowance, well-being program, WFH budget, personal learning & development budget, generous leave benefits, and plenty more!


Apply for this job

Please mention you found this job on AI Jobs. It helps us get more startups to hire on our site. Thanks and good luck!

Get hired quicker

Be the first to apply. Receive an email whenever similar jobs are posted.

Ace your job interview

Understand the required skills and qualifications, anticipate the questions you may be asked, and study well-prepared answers using our sample responses.

Risk Analyst Q&A's
Report this job
Apply for this job