Vendor Risk Consultant at SecurityScorecard
Sydney, New South Wales, Australia -
Full Time


Start Date

Immediate

Expiry Date

03 Dec, 25

Salary

150000.0

Posted On

04 Sep, 25

Experience

5 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Good communication skills

Industry

Financial Services

Description

ABOUT SECURITYSCORECARD:

SecurityScorecard is the global leader in cybersecurity ratings, with over 12 million companies continuously rated, operating in 64 countries. Founded in 2013 by security and risk experts Dr. Alex Yampolskiy and Sam Kassoumeh and funded by world-class investors, SecurityScorecard’s patented rating technology is used by over 25,000 organizations for self-monitoring, third-party risk management, board reporting, and cyber insurance underwriting; making all organizations more resilient by allowing them to easily find and fix cybersecurity risks across their digital footprint.
Headquartered in New York City, our culture has been recognized by Inc Magazine as a “Best Workplace,” by Crain’s NY as a “Best Places to Work in NYC,” and as one of the 10 hottest SaaS startups in New York for two years in a row. Most recently, SecurityScorecard was named to Fast Company’s annual list of the World’s Most Innovative Companies for 2023 and to the Achievers 50 Most Engaged Workplaces in 2023 award recognizing “forward-thinking employers for their unwavering commitment to employee engagement.” SecurityScorecard is proud to be funded by world-class investors including Silver Lake Waterman, Moody’s, Sequoia Capital, GV and Riverwood Capital.

WHAT WE NEED YOU TO HAVE:

  • Experience: 5+ years of demonstrated professional cybersecurity consulting experience or similar.
  • Communications Skills: Outstanding ability to explain complex cybersecurity and vendor risk concepts to a range of technical and non-technical audiences, in both written and verbal form.
  • Cybersecurity Expertise: Strong comprehension and ability to apply cybersecurity concepts, frameworks, technologies, controls, threat knowledge, and best practices to vendor risk.
  • Analytical Skills: Proficiency in common scripting languages (Python preferred) and/or Microsoft Excel (or equivalent) to analyze complex data, build trends, and spot patterns.
  • Client & Program Management: Demonstrated success managing multiple external clients and projects simultaneously, prioritizing competing demands, and meeting deadlines.
  • Solo and Team Excellence: Ability to thrive in fast-paced independent and collaborative settings.
  • Desired Certifications (One or More Completed): CRISC, CISSP, CISM, CISA, GSTRT, GCCC, GSLC, or GSNA. CRVPM, CTPRP, ISO 27001 Lead Auditor or technical certs are also a plus.
  • Languages: English (fluent). Other regional languages are a plus.
  • Other Desired Experience: Experience conducting cybersecurity audits, vendor risk assessments or broader vendor risk management.
Responsibilities

ABOUT THE ROLE:

SecurityScorecard’s MAX team delivers vendor risk management services on behalf of customers. Our MAX team is growing and we are seeking a Vendor Risk Consultant to join our team and help us manage and mitigate cyber risks associated with our customers’ vendors. This is an exciting opportunity to work alongside some of the largest companies in the world and make a significant impact on their business by ensuring that their information is held securely by their vendors.

WHAT YOU’LL DO:

  • Assess and Reduce Risk: Conduct cybersecurity risk assessments on potential and existing vendors within MAX customer portfolios to identify and reduce business risks.
  • Advise Stakeholders: Serve as a trusted advisor to both customers and their vendors, translating technical risk findings into clear business impacts and risk management actions.
  • Apply Threat Intelligence: Leverage SecurityScorecard’s proprietary findings and all-source threat intelligence to assess emerging risks, advise vendors on impacts, and guide remediation.
  • Build and Maintain Relationships: Foster trust with both customers and vendors as you help each understand risks, ensure ongoing compliance with requirements, and prevent incidents.
  • Enhance Customer Risk Programs: Evaluate the maturity of vendor risk management programs and recommend improvements to strengthen governance and operational processes.
  • Monitor & Elevate Vendor Security: Track and report on vendor risk profiles, proactively identifying trends, emerging threats, and opportunities for program improvement.
  • Manage Multiple Engagements: Orchestrate concurrent client programs, ensuring consistent delivery excellence, measurable results, and alignment with regulatory and industry standards.
Loading...