Retour à la recherche
Logo de Resonaite
ResonaiteSource d’offres vérifiée

3rd Party Risk and Governance Analyst (Intermediate)

Offre en anglais
  • Toronto, ON
  • Sur place
  • Publié 2 sept. 2026
  • 1 poste

Ouvre un site externe

Connectez-vous pour enregistrer ce poste
Type d’emploi
Contrat
Niveau d’expérience
Intermédiaire · 2+ ans
Formation minimale
Diplôme professionnel
Postuler avant le
2 oct. 2026
Langue de l’offre
anglais
Heures de travail
40 heures par semaine
Niveau d’expérience
Associate
Mode de candidature
La candidature directe est offerte

Résumé du poste

Lead and coordinate third-party risk assessments across the full vendor lifecycle, including onboarding, monitoring, and offboarding. Partner with cross-functional teams to identify, mitigate, and govern third-party risks in accordance with regulatory expectations.

Détails du poste

Our client in the insurance sector is seeking a Third-Party Risk & Governance Specialist with 3–5 years of hands-on experience in Third-Party Risk Management (TPRM), vendor governance, and supplier risk assessments. The successful candidate will support and execute TPRM activities across the full third-party lifecycle for enterprise technology engagements, including vendor onboarding, ongoing monitoring, renewals, risk remediation, and offboarding. Working closely with Business Owners, Cybersecurity, Privacy, Legal, Compliance, Procurement, Finance, and external vendors, this role will help ensure third-party risks are effectively identified, assessed, mitigated, monitored, and governed in accordance with organizational policies and applicable regulatory expectations. Responsibilities Lead and coordinate third-party risk assessments across vendor onboarding, renewals, ongoing monitoring, and off-boarding. Conduct and manage vendor criticality assessments, due diligence reviews, risk assessments, remediation plans, and risk exceptions. Partner with Business Owners, Cybersecurity, Privacy, Legal, Compliance, Procurement, Finance, and vendors to identify and address third-party risks. Monitor vendor performance and risk through scorecards, key metrics, ongoing assessments, and Quarterly Business Reviews (QBRs). Track vendor incidents, identified risks, issues, corrective action plans, concentration risks, and remediation activities through resolution. Develop and maintain vendor Exit Plans and Business Continuity Plans based on criticality and risk tier. Maintain the TPRM inventory and ensure vendor records, assessments, due diligence documentation, and governance activities remain accurate and current. Support third-party risk audits, regulatory reviews, governance reporting, and compliance with organizational TPRM policies. Identify opportunities to strengthen vendor governance, risk monitoring, controls, and overall TPRM processes. Requirements 3–5 years of experience in Third-Party Risk Management (TPRM), Vendor Risk Management, Vendor Governance, Compliance, Procurement, or Operational Risk. Hands-on experience conducting vendor due diligence, supplier risk assessments, criticality assessments, ongoing monitoring, and risk remediation. Experience managing third-party risks throughout the complete vendor lifecycle, from onboarding through renewal and offboarding. Strong understanding of risk identification, assessment, mitigation, issue management, corrective action plans, and risk exceptions. Strong stakeholder management skills with the ability to work effectively across business, technology, risk, procurement, and vendor teams. Strong analytical, organizational, documentation, and communication skills. Experience working with technology vendors, including SaaS, cloud, managed services, and other technology service providers, is preferred. Experience within financial services, insurance, healthcare, or another regulated environment is an asset. Knowledge of OSFI Guideline B-10, third-party risk management principles, operational resilience, or enterprise risk management frameworks is an asset. Experience facilitating QBRs and managing vendor scorecards, KPIs, and supplier performance monitoring programs is an asset. Professional certifications such as CRVPM, CTPRP, CISSP, CISA, CBCP, or equivalent are considered an asset.

Ce que vous ferez

Lead and coordinate third-party risk assessments across the full vendor lifecycle, including onboarding, monitoring, and offboarding. Partner with cross-functional teams to identify, mitigate, and govern third-party risks in accordance with regulatory expectations.

Exigences

Requires 3–5 years of experience in TPRM, vendor governance, or operational risk, preferably within regulated sectors like insurance or finance. Strong analytical skills and experience with technology vendors (SaaS, Cloud) are highly desired.

Compétences indiquées

  • Compliance · Souhaitée
  • Stakeholder Management · Souhaitée

Autres compétences pertinentes

Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.

  • Third-Party Risk Management
  • Vendor Governance
  • Supplier Risk Assessments
  • Due Diligence
  • Risk Remediation
  • Vendor Onboarding
  • Stakeholder Management
  • Risk Identification
  • Compliance
  • Operational Risk
  • Business Continuity Planning
  • Vendor Performance Monitoring
  • Criticality Assessments
  • Issue Management
  • Audit Support
  • Governance Reporting

Domaines d’emploi

  • Security & Safety
  • Consulting
  • Finance & Accounting
  • Technology
  • Legal

D’autres postes auxquels postuler directement

Des possibilités semblables publiées par des employeurs qui recrutent sur Jobs.ca, sans formulaire externe.

Voir tous les postes à candidature simplifiée