Third Party Security Lead
Posted Date: 21 Aug 2026
Location: Melbourne, VIC
Company: HESTA Super Fund
Bring your authentic and passionate self to this exceptional role #careerswithimpact
Shape the future of third-party security at HESTA
At HESTA, protecting our members’ data, investments and trust is at the heart of what we do. We’re looking for an experienced Third Party Security Lead to take a leading role in strengthening how HESTA identifies, monitors and manages information security risk across our third- and fourth-party ecosystem.
This is an opportunity to shape and mature a critical security capability - leveraging automation, continuous monitoring and AI-enabled security intelligence to provide greater visibility of our supply-chain security posture and identify emerging risks before they become issues.
Reporting to the Information Security Risk and Assurance Manager, you’ll be the central SME for third-party security assurance, working across Information Security, Technology, Digital, Risk, Compliance, Procurement, Operational Resilience and business teams.
What You’ll Do
- Lead HESTA’s third-party security monitoring capability, driving the implementation and ongoing execution of automated and AI-enabled monitoring across third and fourth parties.
- Own end-to-end third-party security assessments, from scoping and prioritisation through to execution, reporting, remediation and ongoing assurance.
- Identify emerging security risks and control weaknesses, using security intelligence, ratings, continuous controls monitoring and other technologies to strengthen HESTA’s risk visibility.
- Shape the technology roadmap for third-party security assurance, identifying and implementing innovative tools that improve detection, insight and response.
- Act as a trusted security advisor to business and technology stakeholders throughout vendor selection, onboarding and ongoing third-party management.
- Drive remediation and risk reduction, partnering with stakeholders to ensure identified security issues are appropriately assessed, prioritised and resolved.
- Provide SME leadership and coaching, supporting resources involved in third-party security assessments and building capability across the broader team.
What You’ll Bring
- Extensive experience in information security, third-party security or supply-chain security risk management, ideally within superannuation or financial services.
- Strong experience delivering security assurance, audits, assessments, control reviews and evidence-based assurance.
- Deep understanding of security control frameworks such as NIST CSF, CIS Controls and ISO 27001 and their application to third-party environments.
- Experience with Continuous Controls Monitoring (CCM) concepts and platforms, including automated and AI-enabled approaches to identifying control failures and emerging risks.
- Experience using security ratings and third-party risk intelligence platforms, with the ability to turn data and intelligence into actionable risk insights.
- Strong knowledge of third-party assessment methodologies, including SIG, CAIQ, control testing and SOC2 assurance.
- Knowledge of relevant financial services and superannuation regulatory obligations, including APRA CPS 230 and CPS 234 and their implications for third-party and outsourcing risk.
- The confidence to influence, challenge and constructively while building trusted relationships.
- Strong strategic thinking, commercial acumen and sound judgement in complex, highly regulated environments.
- Exceptional communication and stakeholder engagement skills, with the ability to translate complex security risks into clear, concise and actionable insights.
- A relevant tertiary qualification in Information Security, Information Technology, Accounting or a related discipline or equivalent experience.
- Professional certifications such as CISSP, CISA, CISM, CRISC, CTPRP/CTPRA, ISO 27001 Lead Auditor or Lead Implementer are desirable.
Bring your third party security expertise | Make an immediate impact at HESTA – Apply Now
Benefits that matter and make a difference for our employees
- Leave for those moments that matter, an additional 6 days of leave at the end of year, up to 6 days paid volunteer leave, gender neutral paid parental leave of 20 weeks, Gender Affirmation leave, reproductive health and wellbeing leave, Cultural and Ceremonial leave. Access your LSL after 3 years, take AL at half pay, and purchase up to 2 weeks additional leave (just to name a few).
- Your professional development matters, up to $5,000 per year professional development and up to 8 days professional development leave, HESTA scholarships and free access to a range of premium learning tools.
- Your health and wellbeing matters, free annual flu shots and skin checks, incredible social events throughout the year and a comprehensive employee assistance program available 24/7.
- Your financial wellbeing matters, up to 15% super, financial planning support, end of year payment for all Enterprise Agreement-covered employees, incentivised Employee Referral Program and novated lease options.
We celebrate, value and include people of all backgrounds, genders, identities, cultures and abilities. We welcome and support applications from First Nations people, physically, neuro or culturally diverse, LGBTQI+, and people of any age. We are proud to be WGEA accredited as an Employer of Choice for Gender Equity.
We want all candidates to feel safe, included and provided with the best opportunity to thrive, if you require reasonable adjustments during your application or throughout the recruitment process, please reach out to a member of the Talent team careers@hesta.com.au and we’ll call you to discuss.
Please note: Applications via recruitment agencies will not be accepted for this position.