Skip to main content

Important: Be aware of Job Employment Scams.

Read more

Third Party Security Analyst

Melbourne, Australia

Apply
Posted 09/04/2025 Job Number 49193 Work type Permanent - Full Time Posting End Date 30/04/2025

The Cyber team at Bupa is growing and we are on the lookout for a third-party security analyst. 


The Third-Party Security Analyst will partner with project teams that are seeking to engage with new vendors whereby its proposed they manage our regulated entities information assets and work with these vendors to perform an assessment of their information security capability to ensure adequate controls are maintained and the introduction of new security risk is avoided

Responsibilities 

  • Carry out third party security due diligence assessments to inform our business of the third party’s security exposure prior to entering into contractual agreement. 
  • Conduct assessments through triage processes and security questionnaires to understand the supplier’s security maturity and gaps o Evaluating the design of that party’s information security controls
  • Communicate and report these within a risk context and gain agreement with internal Bupa stakeholders and the third-party provider on the remediation plan 
  • Monitor third party’s attack surface observations and raise remediation requests where appropriate 
  • Perform monitoring and oversight over agreed remediations, and validation prior to closure 
  • Providing support to the Cyber Security Incident response team for any Third-Party incident response testing / simulations or real-world cyber incidents (where required) 
  • Working with Security testing teams to coordinate regular controls testing commensurate with the rate at which the vulnerabilities and threats change; and the materiality and frequency of change to information assets managed by our third parties (where required)
  • Prepare scheduled and ad-hoc reports demonstrating the status of third-party security risk profiles, issues, trends, and improvement initiatives 
  • Supporting Security Risk Assessments (where required)
  • Maintain Bupa’s third-party assessments repository

What will I bring?

  • 2-4 years’ experience in Information Security, or a related field
  • Tertiary qualifications in an appropriate Information Technology discipline or equivalent professional experience
  • Knowledge of security and risk frameworks including ISO-27000 series, SABSA, CISSP and NIST
  • Experience operating in an APRA and/or PCI regulated industry sector (preferred)
  • Strong business and commercial acumen with a focus on the customer and business outcome
  • Excellent oral and written communication skills including quality, concise technical documentation, report writing and presentations 
  • Excellent team player working within matrix structures, with demonstrated ability to broker outcomes effectively and collaboratively with colleagues and peers 
  • Vendor and partner management experience, including professional services and technology vendors

What’s in it for you?     

As well as a competitive salary, a range of Bupa benefits and flexible working/ work from home, you’ll be challenged and encouraged to innovate. You will collaborate strongly with colleagues who are committed to delivering exceptional experiences. We trust, respect and consider everyone, knowing your difference will make the difference.     Other benefits include discounts on health insurance, as well as access to our new global wellbeing program, Viva. 

Viva has been designed to help you to live a healthy and happy life. It encompasses a comprehensive health and wellbeing program which includes access to health insurance benefits that will assist with covering the cost of medical treatment, information and education sessions, and preventative healthcare screening such as annual health assessments and skin checks. You will also be eligible to access various discounted products and services through our VIVA wellbeing partnerships.    

Apply

Customer care during COVID

When COVID-19 hit we knew we had a responsibility to care for our customers by putting them at the heart of our decisions.

For this reason, in April 2020 our Health Insurance team invested over $50M and created the hardship team to support our customers when they most needed it.

Celebrate Wear it Purple Day and be the change

Wear it Purple was started to raise awareness of the discrimination faced by LGBTIQ+ youth, and the higher levels of suicide, depression and anxiety they experience as a result.

Read more

Forbes ranks Bupa one of the world’s best employers

Bupa has been ranked one of the world's best employers in Forbes' annual 'World's Best Employers' survey.

Read more

Thank you aged care workers

Today is ‘Aged Care Employee Day’, and there’s never been a more important time to thank aged care workers.

Read more

Ban the asterisk

Our customers have told us that our products can be confusing and complex when we add an asterisk (*) with fine print in our policies. To respond to our customers’ needs, in 2020 the Product Deisgn Squad was created to make our products simpler, more relecant and personalised. Here’s how putting our customers at the heart of everything helped the team ban the *.

Job Alerts

Don’t see a role that’s right for you? You can sign up for our job alerts and we’ll make sure to let you know when the right one comes up.

Job alerts

We're always looking for talented individuals. Make sure you sign up for job alerts so you can bring your difference to make the difference.

Interested InSelect options from the fields below and click “Add” to customise what jobs you would like to be notified about.

Join Our Talent Community

Looking to shape a brighter future for everyone? Sign up to our talent community and be the first to learn about new roles.

Join Now