Senior Associate, 4th Party Assessments

Posted:
1/13/2025, 4:50:45 AM

Location(s):
Melbourne, Victoria, Australia ⋅ Victoria, Australia

Experience Level(s):
Senior

Field(s):
IT & Security

Worker Type:

Fixed Term (Fixed Term)


We are looking the Senior Associate, Third Party Assessments is a common point of Subject Matter Expertise providing third party risk assessment support and advice to NAB's Divisions. This role is critical in driving understanding of Supplier controls and ensuring our risk management has the necessary third party rigour to protect the bank.

Role Responsibilities

  • Validation of Initial Assessments to assess Materiality and Outsourcing outcomes as per APRA CPS231 requirements

  • Validation of Inherent Risk Assessments (IRA) and assessment of Third Party Assessments (TPA) for all of NAB’s suppliers.

  • Providing advice and guidance to the business to ensure all outsourcing and third-party arrangements are within the Group Risk Appetite Statement

  • Designing controls with control owners across the enterprise and facilitating documentation in our risk management system for targeted controls; confirming appropriate implementation of controls

  • Supporting the business to build or uplift Supplier controls

  • Performing Assurance over Supplier performance in meeting risk requirements including the CPS 231 and 234 compliance checks

  • Supporting activities/projects with TPRM.

  • Communicating and driving best practice and consistency across the enterprise specific to third-party risk assessment activities

  • Supporting key stakeholders and 2nd line risk partners with the execution of key processes related to third-party risk assessment activities including the review and endorsement of various dashboards

  • An understanding of information security and business continuity/disaster recovery controls along with a working knowledge of following standards/frameworks -

  • APRA CPS 234

  • ISO 27001 and ISO 22301

  • NIST Cyber Security Framework

SKILLS & EXPERIENCE REQUIREMENTS

  • An information security/BCM related certification (CISM/CISSP/Lead auditor for infosec/BCP) would be a plus.

  • 5+ years in operational risk management

  • Knowledge of control design and assurance methodologies

  • Strong stakeholder management skills

  • Inquisitive

  • Analytical, and critical thinker

  • Ability to influence

  • Strong problem solving

  • Knowledge of relevant Prudential Standards (eg CPS 231 Outsourcing, CPS234 Information Security )

  • Proactive attitude


It’s more than a career at NAB. It’s about more opportunity, more moments to make a difference and more focus on you.
Your job is just one part of your life. When you bring your ideas, energy, and hunger for growth to us, you’ll be recognised and rewarded for your contribution in return. You’ll have our support to excel for our customers, deliver positive change for our communities and grow your career. 



It’s a good time to see what more you can find at NAB as a

Senior Associate, 4th Party Assessments

A diverse and inclusive workplace works better for everyone.
At NAB, we’re intent on building a culture we can all be proud of. One based on trust and respect. An uplifting environment where every single one of us feels appreciated and empowered to be our true, authentic selves. A diverse and inclusive workplace where our differences are celebrated, and our contributions are valued. It’s a huge part of what makes NAB such a special place to be.

Please note unsolicited CVs from agencies will not be accepted.