Commonwealth Bank Logo

Commonwealth Bank

Senior Manager - Supplier Risk and Controls

Posted 5 Days Ago
Be an Early Applicant
In-Office
Area, Viveiro, Lugo, Galicia
Senior level
In-Office
Area, Viveiro, Lugo, Galicia
Senior level
Lead a portfolio of critical third‑party suppliers to ensure supplier risk is assessed, controls are tested, deficiencies remediated, and regulatory expectations met across the supplier lifecycle. Provide oversight, stakeholder advisory, governance reporting and drive continuous improvement in supplier risk practices.
The summary above was generated by AI
Senior Manager Supplier Risk

At CommBank, we never lose sight of the role we play in other people’s financial wellbeing. Our focus is to help people and businesses move forward, to progress. To make the right financial decisions and achieve their dreams, targets and aspirations. Regardless of where you work within our organisation, your initiative, talent, ideas and energy all contribute to the impact that we can make with our work. Together we can achieve great things.

Do work that matters

CommBank is recognised as leading the industry in IT and operations with its world-class platforms and processes, agile IT infrastructure, and innovation in everything from payments to internet banking and mobile apps.

See yourself in our team

We are seeking a Senior Manager – Supplier Risk & Controls to lead the delivery of high-quality risk outcomes across a portfolio of critical third-party suppliers.

This role sits within the Supplier Risk & Controls (SR&C) function, a specialist team responsible for ensuring supplier engagements are managed safely, effectively, and in line with regulatory expectations across the full supplier lifecycle

As a portfolio lead, you will combine deep risk expertise, strong stakeholder engagement, and hands-on execution—owning end-to-end supplier risk activity from onboarding through to ongoing assurance and remediation.

This is a permanent role based in Sydney. We also offer remote working and a flexible workplace.

In any given week your responsibilities may include to:

The purpose of the Supplier Risk component of this role is to assess, develop and enhance the management of risk in supplier arrangements used across CBA Group.

You will be responsible for ensuring that the risk management activities and controls relating to suppliers meets the Group’s internal requirements and external regulations (including the Operational Risk Management Framework, Compliance Risk Management Framework and the Group’s Risk Appetite Statements, and CPS230 and equivalent standards).

Specific responsibilities:
 

Portfolio ownership and leadership

  • Lead a defined portfolio of suppliers, accountable for the quality and timeliness of all risk activities delivered

  • Provide oversight and guidance to case managers delivering supplier risk assessments and control testing

  • Manage capacity, prioritisation, and delivery outcomes across your portfolio

Supplier risk assessment and profiling

  • Oversee and review Supplier Risk Profiles and Risk Memos to support business decision-making

  • Ensure risks are identified, assessed, and clearly articulated in line with Group frameworks

  • Drive consistency and quality in risk documentation and approvals

Control assurance and testing

  • Lead oversight of control programs and supplier control testing activities

  • Ensure control are accurately tested and deficiencies are identified, escalated, and addressed

  • Provide insights on systemic control weaknesses and emerging risk themes

Stakeholder engagement and advisory

  • Act as a trusted advisor to Business Owners, Risk, Procurement, and senior stakeholders

  • Facilitate discussions on supplier risks, control gaps, and remediation strategies

  • Lead escalation management for complex or high-risk supplier issues

Governance and regulatory alignment

  • Ensure supplier risk activities align to Group frameworks and regulatory expectations (e.g. supplier lifecycle, operational risk standards)

  • Support governance forums and provide clear, actionable risk reporting

  • Drive improved risk practices and consistency across the organisation

Continuous improvement and transformation

  • Identify opportunities to improve the supplier risk operating model, processes, and tooling

  • Support initiatives that reduce duplication, improve efficiency, and uplift capability

  • Champion a culture of end-to-end ownership and accountability
     

We're interested in hearing from people who:

  • Extensive experience in supplier risk, operational risk, or controls assurance

  • Strong understanding of third-party risk frameworks and control environments

  • >5 years in operational/ technology risk within financial services with proven supplier risk experience

  • Sound understanding of information security management, Privacy legislation, ITIL, IT service continuity, IT disaster recovery, business continuity management, and third party control assurance

  • Experience leading teams or portfolios delivering risk outcomes at scale

  • Experience managing complex stakeholder environments across business and risk functions

  • Familiarity with regulatory expectations for outsourcing and third-party risk (e.g. CPS230)

  • Sound understanding in dealing with regulatory and compliance issues within a major financial institution, audit firm or other major company

  • Ability to analyse trends, identify critical threats and opportunities, diagnose problems and issues and recommend appropriate actions

  • Have a passion for Supplier and technology risk and remain up to date on the latest emerging industry trends and disruptive technologies

  • CA or CPA degree or any relevant tertiary qualifications in finance or risk management preferred

If you're already part of the Commonwealth Bank Group (including Bankwest, x15ventures), you'll need to apply through Sidekick to submit a valid application. We’re keen to support you with the next step in your career.

We're aware of some accessibility issues on this site, particularly for screen reader users. We want to make finding your dream job as easy as possible, so if you require additional support please contact HR Direct on 1800 989 696.

Advertising End Date: 18/06/2026

Similar Jobs

5 Hours Ago
In-Office or Remote
Mid level
Mid level
Big Data • Information Technology • Software • Analytics • Energy
The role involves maintaining CI/CD pipelines, managing infrastructure as code with Terraform, enhancing application resources, and ensuring security best practices in software development.
Top Skills: Ci/CdCloudFormationDockerGrafanaKubernetesMongoDBMs Sql ServerPowershellPythonTerraform
Yesterday
Easy Apply
Remote or Hybrid
Easy Apply
Senior level
Senior level
Artificial Intelligence • Cloud • Security • Software • Cybersecurity
Lead design and development of low-level Linux instrumentation and eBPF-based runtime security features for detection, monitoring, and workload protection. Drive architecture, implement performance-sensitive systems, establish testing methodologies, deliver end-to-end features, and provide technical leadership and cross-team collaboration across Datadog's security products.
Top Skills: Agent DevelopmentCloud SecurityDriver DevelopmentEbpfKernel ApisKernel-Level InstrumentationLarge-Scale Data CollectionLinuxLinux KernelNetworking SystemsPerformance-Sensitive SystemsRuntime SecurityVulnerability Management
2 Days Ago
Remote or Hybrid
Senior level
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Design and build a canonical knowledge graph and ingestion framework: implement connectors, parsers, schema-to-model transforms, code generators, and entity-resolution systems. Lead cross-functional teams, ensure data quality and validation across a multi-backend graph architecture, mentor engineers and taxonomists, and support broader CTO organization with briefings and product demonstrations.
Top Skills: APIsGoGraphRust

What you need to know about the Melbourne Tech Scene

Home to 650 biotech companies, 10 major research institutes and nine universities, Melbourne is among one of the top cities for biotech. In fact, some of the greatest medical advancements were conceptualized and developed here, including Symex Lab's "lab-on-a-chip" solution that monitors hormones to predict ovulation for conception, and Denteric's vaccine for periodontal gum disease. Yet, the thousands of people working in the city's healthtech sector are just getting started, to say nothing of the tech advancements across all other sectors.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account