Onsite
The Information Technology (IT) team plays a key role in providing business enablement throughout ResMed. We are focused on application, infrastructure, and user productivity solutions, with innovation, efficiency and security. Our goal is providing customer oriented agile delivery, effective business partnership and state-of-the-art technology solutions.
Support ResMed in identifying, validating, and assessing applications post-acquisition, onboarding associated vendors into UpGuard, coordinating security documentation, and providing risk insights that strengthen ResMed’s third-party security posture.
Let’s talk about Responsibilities
Identify and validate all applications not previously reviewed through logs, telemetry, and stakeholder interviews.
Capture key details: vendor, use case, data types, hosting model, criticality.
Produce a clean and complete Application Inventory.
Identify vendor contacts and manage communication flow.
Request and collect required security documentation (SOC reports, ISO certs, IR/BCP, etc.).
Maintain complete evidence packages in TPRM platform.
Build vendor profiles with accurate metadata in Resmed TPRM platform.
Upload documentation and ensure alignment with ResMed standards.
Launch security assessments based on risk tier and track vendor progress.
Document findings and escalate high-risk issues as needed.
Coordinate with IT team to review and whitelist validated applications.
Provide weekly status updates.
Prepare reports on application discovery, vendor risk levels, and assessment outcomes.
Let’s talk about Qualifications and Experience
Required:
Minimum 5 years in Vendor Risk Management, Application Security Governance, or GRC.
Strong experience collecting technical requirements for SaaS/cloud applications.
Ability to assess data flows, hosting models, and application criticality.
Hands-on experience with TPRM/GRC platforms such as UpGuard, OneTrust or Archer.
Proven ability to work across multiple stakeholders (Security, M&A, Privacy, Legal, IT).
Strong documentation, reporting, and data quality management skills.
Preferred:
Experience supporting M&A integration activities related to application or vendor risk.
Relevant Security Risk Management certifications such as CRISC, CISM, CISSP etc.
Understanding of regulatory and compliance frameworks (HIPAA, GDPR, ISO, NIST).
Joining us is more than saying “yes” to making the world a healthier place. It’s discovering a career that’s challenging, supportive and inspiring. Where a culture driven by excellence helps you not only meet your goals, but also create new ones. We focus on creating a diverse and inclusive culture, encouraging individual expression in the workplace and thrive on the innovative ideas this generates. If this sounds like the workplace for you, apply now! We commit to respond to every applicant.
Want to know if this job is worth applying to?