Senior Technical Analyst, Third-Party Risk Management

FCC / FAC

Regina

Hybrid

CAD 95,000 - 128,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work options
Competitive total rewards

Job summary

FCC is seeking a Senior Technical Analyst, Third-Party Risk Management, to assess vendor security and privacy controls across the provider lifecycle in Canada. You will review SOC 2 reports, questionnaires and evidence, and document risk-based recommendations for stakeholders.

In this role you’ll collaborate with procurement, cybersecurity and legal teams, translate complex security findings into actionable guidance, and support remediation activities while maintaining a high-volume assessment

Qualifications

  • Bachelor's degree in computer science, information security, or related field.
  • 4+ years in information security, vendor risk management, or related risk roles.
  • Ability to interpret security documentation and assess vendor controls.

Responsibilities

  • Review vendor security documentation (SOC 2, questionnaires) to assess alignment with FCC requirements.
  • Complete vendor assessments from intake through recommendation.
  • Analyze information security, business continuity and privacy considerations to identify risks.
  • Collaborate with stakeholders to clarify questions and support decision making.
  • Communicate findings and recommendations to vendors and internal teams.
  • Maintain high-volume assessment workload with prioritized tasks and escalation when needed.

Skills

Vendor risk management
Information security
Risk assessment
SOC 2 knowledge
Communication
Independent work

Education

Bachelor's degree in computer science / information security

Job description

Term Duration (in Months)

Salary Range (plus eligible to receive a performance based incentive, applicable to position) :

Closing Date (MM/DD/YYYY)

08/31/2026

Worker Type

Permanent

Language(s) Required

English

Term Duration (in Months)

Salary Range (plus eligible to receive a performance based incentive, applicable to position) :

$94,620 - $128,020

Why FCC?

At FCC, we’re proud to be 100% invested in Canadian agriculture and food. As a federal Crown corporation, we provide financing, knowledge resources and business management software to over 103,000 customers nationwide.

Here’s what you can expect when you join our team:

  • Competitive total rewards packages: market-aligned and performance-based salary and incentive programs, flexible and comprehensive group benefit and savings plans, and well-being support through benefits and wellness programs
  • Purpose-driven work: We build strong relationships, share knowledge and support the people who feed the world
  • Growth: Learning and development opportunities to help you thrive
  • Hybrid work options
How You’ll Make An Impact

As a Senior Technical Analyst, Third-Party Risk Management (TPRM), you’ll assess and monitor technology, cybersecurity, privacy and operational risks associated with third-party service providers. You’ll provide independent analysis and risk-based recommendations to ensure vendor services align with organizational policies, security standards, regulatory requirements and risk appetite.

Working closely with business owners, procurement, cybersecurity, privacy, legal and vendor representatives, you’ll evaluate third-party controls, identify potential risks, facilitate remediation activities and support ongoing vendor oversight throughout the vendor lifecycle.

We’re looking for a strong analytical thinker who can assess vendor security risks, interpret technical documentation and turn findings into practical recommendations. Someone who’s comfortable reviewing security reports, asking thoughtful questions and communicating clearly with both technical teams and business stakeholders.

If you have a foundation in information security or cybersecurity, enjoy independent assessment work and can explain complex technical topics in plain language, this could be the role for you.

What You’ll Do
  • Review vendor security documentation, including SOC 2 reports, security questionnaires and supporting evidence, to assess alignment with FCC requirements
  • Complete vendor assessments from a shared queue, taking ownership of assigned assessments from intake through recommendation
  • Analyze information security, business continuity and privacy considerations to identify vendor risks, control gaps and mitigation needs
  • Collaborate with third-party risk management, cybersecurity, privacy and business stakeholders to clarify assessment questions and support consistent decision-making
  • Communicate assessment findings and recommendations to vendors and internal stakeholders in clear, practical language
  • Contribute to a high-volume assessment environment by managing priorities, documenting rationale and escalating risks or exceptions when needed
Required Qualifications
What you’ll bring to the team
  • A bachelor’s degree in computer science, information systems, cybersecurity, information security or a related discipline
  • At least four years of related experience in information security, cybersecurity, technology risk, vendor risk management, security governance, risk and compliance, or a related technical risk field (or an equivalent combination of education and experience)
  • Strong knowledge of information security concepts, controls and risk assessment practices
  • Experience interpreting technical security documentation and assessing vendor controls against defined requirements
  • Ability to assess risks, identify control gaps and provide practical recommendations that support business and vendor decisions
  • Strong written and verbal communication skills, including the ability to explain technical security topics to non-technical and senior stakeholders
  • Ability to work independently, manage multiple assessments and collaborate with team members when questions or escalations arise
Preferred Qualifications
  • Experience reviewing SOC 2 reports or other third-party assurance reports
  • Experience in third-party risk management, vendor security assessments, security compliance or a regulated environment
  • Professional certification such as CISA, CISM, CISSP, CRISC or a privacy-related designation
  • Knowledge of security, privacy or operational resilience frameworks such as ISO 27001, NIST, SOC 2, OSFI guidance or business continuity practices
You belong here

At FCC, we’re committed to creating an inclusive, equitable and accessible workplace – one that reflects the communities where we live, work and play. Our team is made stronger through diversity, and we’re dedicated to building a workforce that brings together a range of backgrounds, abilities and perspectives.

  • Indigenous Peoples
  • Members of visible minority groups
  • Persons with disabilities
  • Women
Accessibility and accommodations

To support an inclusive and accessible candidate experience, we encourage anyone needing an adjustment or accommodation during any stage of the recruitment process to email us at: TalentSupplyRecherch@fcc-fac.ca. An HR partner will respond and work with applicants who request a reasonable accommodation. Information received in relation to accommodation requests will not impact hiring decisions.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Technical Analyst, Third-Party Risk Management
Senior Technical Analyst, Third-Party Risk Management

Farm Credit Canada • Regina

On-site
CAD 95,000 - 128,000
Hybrid work options
Senior Developer, Data Engineering
Senior Developer, Data Engineering

FCC / FAC • Regina

Hybrid
CAD 95,000 - 128,000
Hybrid work options
Fullstack Developer, Java/Typescript (Marketing and Digital Solutions)
Fullstack Developer, Java/Typescript (Marketing and Digital Solutions)

FCC / FAC • Regina

Hybrid
CAD 83,000 - 112,000
Hybrid work options
Competitive total rewards package
Well-being and benefits programs
Senior Auditor
Senior Auditor

FCC / FAC • Saskatoon

Hybrid
CAD 92,000 - 125,000
Competitive total rewards packages
Learning and development opportunities
Well-being support through benefits
Fullstack Developer, Java/Typescript (Marketing and Digital Solutions)
Fullstack Developer, Java/Typescript (Marketing and Digital Solutions)

fccfac • Regina

Hybrid
CAD 83,000 - 112,000
Hybrid work options
Performance-based incentive
Group benefits and wellness program
Fullstack Developer, Java/Typescript (Marketing and Digital Solutions)
Fullstack Developer, Java/Typescript (Marketing and Digital Solutions)

Socket.dev • Regina

Hybrid
CAD 83,000 - 112,000
Hybrid work options
Product Architect, SaaS Platforms and Third-Party Apps
Product Architect, SaaS Platforms and Third-Party Apps

Farm Credit Canada • Regina

Hybrid
CAD 108,000 - 146,000
Hybrid work options
Competitive total rewards
Senior Developer, Data Engineering
Senior Developer, Data Engineering

Farm Credit Canada • Regina

Hybrid
CAD 95,000 - 128,000
Hybrid work options
Senior Technical Analyst, Data
Senior Technical Analyst, Data

Farm Credit Canada • Regina

Hybrid
CAD 108,000 - 146,000
Hybrid work options
Competitive total rewards package
Growth and development opportunities
Corporate Financing Associate
Corporate Financing Associate

FCC / FAC • Quebec

Hybrid
CAD 72,000 - 99,000
Health benefits
Savings plans
Well-being programs
+1