3rd Party Risk and Governance Analyst (Intermediate)

Resonaite

Toronto

On-site

CAD 70,000 - 110,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Resonaite is seeking a Third-Party Risk & Governance Specialist with 3–5 years of experience in TPRM, vendor governance, and supplier risk assessments. The role supports a full lifecycle of third-party engagements across onboarding, monitoring, renewals and offboarding, collaborating with Security, Privacy, Legal, Compliance and Procurement to mitigate risks.

The ideal candidate will manage due diligence, criticality assessments, and remediation plans, while tracking performance via scorecards

Qualifications

  • 3–5 years of hands-on experience in Third-Party Risk Management (TPRM), vendor governance, and supplier risk assessments.

Responsibilities

  • Lead and coordinate third-party risk assessments across vendor onboarding, renewals, ongoing monitoring, and off-boarding.
  • Conduct and manage vendor criticality assessments, due diligence reviews, risk assessments, remediation plans, and risk exceptions.
  • Partner with Business Owners, Cybersecurity, Privacy, Legal, Compliance, Procurement, Finance, and vendors to identify and address third-party risks.
  • Monitor vendor performance and risk through scorecards, key metrics, ongoing assessments, and QBRs.
  • Track vendor incidents, identified risks, issues, corrective action plans, concentration risks, and remediation activities through resolution.
  • Develop and maintain vendor Exit Plans and Business Continuity Plans based on criticality and risk tier.
  • Maintain the TPRM inventory and ensure vendor records, assessments, due diligence documentation, and governance activities remain accurate and current.
  • Support third-party risk audits, regulatory reviews, governance reporting, and compliance with organizational TPRM policies.
  • Identify opportunities to strengthen vendor governance, risk monitoring, controls, and overall TPRM processes.

Skills

TPRM
Vendor governance
Due diligence
QBRs
Regulatory knowledge
Stakeholder management
Risk remediation

Job description

Our client in the insurance sector is seeking a Third-Party Risk & Governance Specialist with 3–5 years of hands‑on experience in Third-Party Risk Management (TPRM), vendor governance, and supplier risk assessments.

The successful candidate will support and execute TPRM activities across the full third‑party lifecycle for enterprise technology engagements, including vendor onboarding, ongoing monitoring, renewals, risk remediation, and offboarding. Working closely with Business Owners, Cybersecurity, Privacy, Legal, Compliance, Procurement, Finance, and external vendors, this role will help ensure third‑party risks are effectively identified, assessed, mitigated, monitored, and governed in accordance with organizational policies and applicable regulatory expectations.

Responsibilities
  • Lead and coordinate third‑party risk assessments across vendor onboarding, renewals, ongoing monitoring, and off-boarding.
  • Conduct and manage vendor criticality assessments, due diligence reviews, risk assessments, remediation plans, and risk exceptions.
  • Partner with Business Owners, Cybersecurity, Privacy, Legal, Compliance, Procurement, Finance, and vendors to identify and address third‑party risks.
  • Monitor vendor performance and risk through scorecards, key metrics, ongoing assessments, and Quarterly Business Reviews (QBRs).
  • Track vendor incidents, identified risks, issues, corrective action plans, concentration risks, and remediation activities through resolution.
  • Develop and maintain vendor Exit Plans and Business Continuity Plans based on criticality and risk tier.
  • Maintain the TPRM inventory and ensure vendor records, assessments, due diligence documentation, and governance activities remain accurate and current.
  • Support third‑party risk audits, regulatory reviews, governance reporting, and compliance with organizational TPRM policies.
  • Identify opportunities to strengthen vendor governance, risk monitoring, controls, and overall TPRM processes.
Requirements
  • 3–5 years of experience in Third-Party Risk Management (TPRM), Vendor Risk Management, Vendor Governance, Compliance, Procurement, or Operational Risk.
  • Hands‑on experience conducting vendor due diligence, supplier risk assessments, criticality assessments, ongoing monitoring, and risk remediation.
  • Experience managing third‑party risks throughout the complete vendor lifecycle, from onboarding through renewal and offboarding.
  • Strong understanding of risk identification, assessment, mitigation, issue management, corrective action plans, and risk exceptions.
  • Strong stakeholder management skills with the ability to work effectively across business, technology, risk, procurement, and vendor teams.
  • Strong analytical, organizational, documentation, and communication skills.
  • Experience working with technology vendors, including SaaS, cloud, managed services, and other technology service providers, is preferred.
  • Experience within financial services, insurance, healthcare, or another regulated environment is an asset.
  • Knowledge of OSFI Guideline B-10, third‑party risk management principles, operational resilience, or enterprise risk management frameworks is an asset.
  • Experience facilitating QBRs and managing vendor scorecards, KPIs, and supplier performance monitoring programs is an asset.
  • Professional certifications such as CRVPM, CTPRP, CISSP, CISA, CBCP, or equivalent are considered an asset.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Third-Party Risk & Governance Analyst (Intermediate)
Third-Party Risk & Governance Analyst (Intermediate)

Resonaite • Toronto

On-site
CAD 70,000 - 110,000
Vendor Management Specialist
Vendor Management Specialist

IFG - International Financial Group • Toronto

Hybrid
CAD 70,000 - 110,000
Vendor Management Specialist (3+ years of experience) to support vendor management and contract lifecycle activities using TPRA and procurement processes 106757-1
Vendor Management Specialist (3+ years of experience) to support vendor management and contract lifecycle activities using TPRA and procurement processes 106757-1

S I Systems • Toronto

Hybrid
CAD 70,000 - 90,000
Vendor Manager
Vendor Manager

Insight Global • Toronto

Hybrid
CAD 70,000 - 90,000
Hybrid work model
AVP Third Party Risk Management
AVP Third Party Risk Management

Peoples Group • Vancouver

On-site
CAD 130,000 - 145,000
Hybrid work environment
Competitive salary
Paid time off
+2
Risk Analyst
Risk Analyst

HRbrain Inc. • Toronto

On-site
CAD 75,000 - 95,000
Senior Analyst, Third Party Risk Management - 12 Month Contract
Senior Analyst, Third Party Risk Management - 12 Month Contract

Socket.dev • Vancouver

On-site
CAD 80,000 - 90,000
Flexible workstyles
Competitive compensation & benefits
RRSP Matching Program
+5
Supplier Risk Manager
Supplier Risk Manager

RBC • Toronto

On-site
CAD 90,000 - 120,000
Bonuses and flexible benefits
Career development and coaching
Flexible work arrangements
+1
Senior Analyst, Third Party Risk Management - 12 Month Contract
Senior Analyst, Third Party Risk Management - 12 Month Contract

Raymond James Ltd. • Vancouver

On-site
CAD 80,000 - 90,000
Flexible workstyles
Competitive compensation
Health benefits
+6
Manager, Third Party Risk Management CoE
Manager, Third Party Risk Management CoE

sunlife • Toronto

Hybrid
CAD 110,000 - 140,000