Third-Party Risk Analyst

Clio

Vancouver, Calgary, Toronto

Hybrid

CAD 84,000 - 113,000

Full time

35 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Hybrid work environment
Flexible time off
$2000 annual counseling benefit
RRSP matching and RESP contribution
Clioversary recognition program

Job summary

Clio is seeking a Third-Party Risk Analyst to review security documentation and assess third-party risk for App Marketplace partners. You will handle SOC 2 reviews, DPIAs, and collaborate with Privacy/Compliance to ensure data remains secure and compliant.

You will triage privacy reviews, escalate risks when needed, and maintain the vendor risk registry while supporting renewals and changes in scope. This is a hybrid Canadian role with a focus on security and privacy across vendor relationships.

Qualifications

  • 2–4 years of hands-on experience in security, compliance, GRC, vendor risk, or procurement review.
  • Experience reading SOC 2 reports and extracting insights.
  • Understanding of access controls, encryption, data classification, data residency, and privacy docs.

Responsibilities

  • Review vendor security documentation (SOC 2, pen tests, whitepapers, DPIA) and assess meeting Clio's security/privacy standards.
  • Evaluate App Marketplace integration submissions for security/privacy risk before listing.
  • Triage for privacy reviews to route to a DPIA with Privacy/Compliance.
  • Escalate risks and document decisions for audit-ready reviews.
  • Maintain the third-party risk registry and support renewals/reassessments.

Skills

SOC 2
Privacy concepts
Documentation review
Vendor risk
GRC

Tools

GRC tooling

Job description

Clio is the global leader in legal AI technology, empowering legal professionals and law firms of every size to work smarter, faster, and more securely.

Third-Party Risk Management (TPRM) is responsible for making sure the outside parties Clio relies on, including software vendors, service providers, and platform integrators it lists in the App Marketplace, meet Clio's bar for security and privacy before they touch Clio or customer data. We sit inside the vendor lifecycle as the security compliance review phase of Procurement, after intake and in parallel with Legal and IT. We work closely with IT, Privacy, Legal, and the App Ecosystem team to deliver strong, documented, defensible assessments of security posture and risk.

About the Role

As a Third-Party Risk Analyst, you are the person who reads the security documentation and advises on the risk of third-party relationships. You own the day-to-day execution of the security review phase, working through vendor submissions, reviewing SOC 2 and penetration test reports, checking data handling against our requirements, and reviewing the security and privacy submissions of partners applying to list in Clio's App Marketplace. When the third party’s criticality is higher, you step up the documentation criteria and adapt. You apply an established set of criteria commensurate with the service provided, surface real risk from paperwork, and keep reviews moving.

You don't need to have seen every framework or every control, but you need to know what a good answer looks like, what questions to ask when something's missing, and when to elevate rather than wave something through.

What You'll Do

  • Review vendor security documentation submitted through the intake process, including SOC 2 reports, penetration test summaries, security whitepapers, AI disclosures, and questionnaire responses, and determine whether the vendor meets Clio's required level of security and privacy
  • Review App Marketplace integration submissions and evaluate the security and privacy documentation of integration partners applying to list on Clio. Flag exceptions that could put customer data or Clio's brand at risk before a partner is added to the marketplace
  • Triage for privacy review by identifying when a vendor or integration will process confidential or sensitive data and route it into a Data Privacy Impact Assessment (DPIA), partnering with Privacy/Compliance
  • Escalate for risk acceptance when a risk is identified in the review process. Document and present it to the appropriate stakeholder for decision making
  • Move reviews through the workflow by tracking submissions, requesting missing artifacts from requesters and vendors, responding to comments, and handing off cleanly to IT, Legal, and executive sign-off
  • Document your findings and decisions. Record what you reviewed, what you found, the risks identified, and your recommendation so the rationale is reusable and audit-ready
  • Maintain the third-party risk registry
  • Support renewals and reassessments by re-reviewing vendors on renewal or change of scope
  • Keep the review criteria and runbooks accurate. Follow the established process and flag when a checklist, threshold, or template is out of date or unclear

What You Bring

Required

  • 2–4 years of hands‑on experience in a security, compliance, GRC, vendor risk, or procurement review role
  • Working familiarity with third‑party audit artifacts. You've read SOC 2 reports and know how to review them and extract a deeper understanding
  • Understanding of core security and privacy concepts, including access controls, encryption, data classification, data residency, and what different tiers of security and privacy documentation look like
  • Demonstrated ability to review documentation critically and separate real risk from noise
  • Comfort working within an established review process and contributing to its improvement
  • Knows when to figure something out independently and when to pull in a subject matter expert
  • Strong organizational skills. You keep multiple reviews moving without losing track of what's waiting on whom

Preferred

  • You are able to see the gaps in documentation and suggest compensating controls where applicable
  • Previous experience with GRC, TPRM, or vendor management tooling
  • Exposure to SOC 2, ISO 27001, PCI DSS, or GDPR/CCPA concepts in an audit context
  • Experience with GDPR, CCPA, DPIAs and/or privacy impact assessments
  • CISA, CIPP/CIPM, CTPRP, CompTIA Security+, or equivalent certification

What Makes You a Great Fit

  • You take full ownership of your review queue, communicate effectively, and are able to balance competing priorities
  • You're curious about why a control matters, not just whether a box is checked
  • You have an intuition for looking beyond the presented facts and noticing emerging patterns across artifacts
  • You have the judgment to hold the line on a real risk and the pragmatism to keep low‑risk reviews moving
  • You communicate clearly when documentation is missing, when a risk needs escalation, or when you need help. Nothing gets quietly approved
  • You're energized by helping build and sharpen a review function rather than inheriting a finished one
  • Your curiosity drives you to learn the why behind the answers, questions, and processes
Summary:

About the Team


Third-Party Risk Management (TPRM) is responsible for making sure the outside parties Clio relies on, including software vendors, service providers, and platform integrators it lists in the App Marketplace, meet Clio's bar for security and privacy before they touch Clio or customer data. We sit inside the vendor lifecycle as the security compliance review phase of Procurement, after intake and in parallel with Legal and IT. We work closely with IT, Privacy, Legal, and the App Ecosystem team to deliver strong, documented, defensible assessments of security posture and risk.


About the Role


As a Third-Party Risk Analyst, you are the person who reads the security documentation and advises on the risk of third‑party relationships. You own the day‑to‑day execution of the security review phase, working through vendor submissions, reviewing SOC 2 and penetration test reports, checking data handling against our requirements, and reviewing the security and privacy submissions of partners applying to list in Clio's App Marketplace. When the third party’s criticality is higher, you step up the documentation criteria and adapt. You apply an established set of criteria commensurate with the service provided, surface real risk from paperwork, and keep reviews moving.

You don't need to have seen every framework or every control, but you need to know what a good answer looks like, what questions to ask when something's missing, and when to elevate rather than wave something through.


What You'll Do


  • Review vendor security documentation submitted through the intake process, including SOC 2 reports, penetration test summaries, security whitepapers, AI disclosures, and questionnaire responses, and determine whether the vendor meets Clio's required level of security and privacy
  • Review App Marketplace integration submissions and evaluate the security and privacy documentation of integration partners applying to list on Clio. Flag exceptions that could put customer data or Clio's brand at risk before a partner is added to the marketplace
  • Triage for privacy review by identifying when a vendor or integration will process confidential or sensitive data and route it into a Data Privacy Impact Assessment (DPIA), partnering with Privacy/Compliance
  • Escalate for risk acceptance when a risk is identified in the review process. Document and present it to the appropriate stakeholder for decision making
  • Move reviews through the workflow by tracking submissions, requesting missing artifacts from requesters and vendors, responding to comments, and handing off cleanly to IT, Legal, and executive sign-off
  • Document your findings and decisions. Record what you reviewed, what you found, the risks identified, and your recommendation so the rationale is reusable and audit-ready
  • Maintain the third‑party risk registry
  • Support renewals and reassessments by re‑reviewing vendors on renewal or change of scope
  • Keep the review criteria and runbooks accurate. Follow the established process and flag when a checklist, threshold, or template is out of date or unclear

What You Bring


Required

  • 2–4 years of hands‑on experience in a security, compliance, GRC, vendor risk, or procurement review role
  • Working familiarity with third‑party audit artifacts. You've read SOC 2 reports and know how to review them and extract a deeper understanding
  • Understanding of core security and privacy concepts, including access controls, encryption, data classification, data residency, and what different tiers of security and privacy documentation look like
  • Demonstrated ability to review documentation critically and separate real risk from noise
  • Comfort working within an established review process and contributing to its improvement
  • Knows when to figure something out independently and when to pull in a subject matter expert
  • Strong organizational skills. You keep multiple reviews moving without losing track of what's waiting on whom

Preferred

  • You are able to see the gaps in documentation and suggest compensating controls where applicable
  • Previous experience with GRC, TPRM, or vendor management tooling
  • Exposure to SOC 2, ISO 27001, PCI DSS, or GDPR/CCPA concepts in an audit context
  • Experience with GDPR, CCPA, DPIAs and/or privacy impact assessments
  • CISA, CIPP/CIPM, CTPRP, CompTIA Security+, or equivalent certification

  • You take full ownership of your review queue, communicate effectively, and are able to balance competing priorities
  • You're curious about why a control matters, not just whether a box is checked
  • You have an intuition for looking beyond the presented facts and noticing emerging patterns across artifacts
  • You have the judgment to hold the line on a real risk and the pragmatism to keep low‑risk reviews moving
  • You communicate clearly when documentation is missing, when a risk needs escalation, or when you need help. Nothing gets quietly approved
  • You're energized by helping build and sharpen a review function rather than inheriting a finished one
  • Your curiosity drives you to learn the why behind the answers, questions, and processes
This is a new role.

What you will find here:

Compensation is one of the main components of Clio’s Total Rewards Program. We have developed a series of programs and processes to ensure we are creating fair and competitive pay practices that form the foundation of our human and high‑performing culture.

Some highlights of our Total Rewards program include:

  • Competitive, equitable salary with top‑tier health benefits, dental, and vision insurance
  • Hybrid work environment, with expectation for local Clions (Vancouver, Calgary, Toronto, Dublin, London, New York City and Sydney) to be in office min. twice per week.
  • Flexible time off policy, with an encouraged 20 days off per year.
  • $2000 annual counseling benefit
  • RRSP matching and RESP contribution
  • Clioversary recognition program with special acknowledgement at 3, 5, 7, and 10 years
The expected salary range for this role is $83,600 to $113,200 CAD. Initial placement within the range is informed by geographic region, experience, and skillset, with room to progress as impact and tenure grow. Final offer amounts will vary based on candidate profile.

Diversity, Inclusion, Belonging and Equity (DIBE) & Accessibility

Our team shows up as their authentic selves, and are united by our mission. We are dedicated to diversity, equity and inclusion. We pride ourselves in building and fostering an environment where our teams feel included, valued, and enabled to do the best work of their careers, wherever they choose to log in from. We believe that different perspectives, skills, backgrounds, and experiences result in higher‑performing teams and better innovation. We are committed to equal employment and we encourage candidates from all backgrounds to apply.

Clio provides accessibility accommodations during the recruitment process. Should you require any accommodation, please let us know and we will work with you to meet your needs.

Learn more about our culture at clio.com/careers

We're a Human and High Performing AI company, meaning we use artificial intelligence to improve all of our operations. In recruitment, AI helps us streamline the process for greater efficiency. However, we've built our systems to ensure that a human always reviews AI-generated output, and we never make automated hiring decisions.

Disclaimer: We only communicate with candidates through official @clio.com email addresses.

In-house performance coach, Katie, helps Clions accelerate their career development.

At Clio, we’re creating a human and high performing culture. That means you’ll be encouraged and supported to do your best work. Find out what keeps us grounded. Learn more.

Hitting record deploys and creating solutions used around the globe.

Every day I am surrounded by a group that keeps me laughing, but also inspires me with their hard work and ingenuity. Everyone here goes out of their way to help each other learn and grow.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Privacy Analyst
Senior Privacy Analyst

Themis Solutions Inc. • Canada

On-site
CAD 106,000 - 144,000
Hybrid work
20 days off
Counseling benefit
+2
Senior Systems Developer, IT.
Senior Systems Developer, IT.

Themis Solutions Inc. • Canada

On-site
CAD 128,000 - 173,000
Hybrid work environment
Health benefits
Dental and vision insurance
+4
Staff People Business Partner, G&A
Staff People Business Partner, G&A

Themis Solutions Inc. • Canada

On-site
CAD 123,000 - 184,000
Health benefits
Hybrid work environment
20 days off per year
+1
Staff Software Developer
Staff Software Developer

Themis Solutions Inc. • Canada

On-site
CAD 176,000 - 264,000
Competitive salary and comprehensive健康
Hybrid work environment
Flexible time off
+3
Staff People Business Partner, G&A
Staff People Business Partner, G&A

Clio • Toronto

On-site
CAD 123,000 - 184,000
Hybrid work environment
Total Rewards program benefits
Health benefits - dental and vision
Senior AI Builder and Analyst, Customer Support
Senior AI Builder and Analyst, Customer Support

Themis Solutions Inc. • Canada

On-site
CAD 108,000 - 146,000
Hybrid work environment
20 days off per year
RRSP matching
+2
Senior Partner Marketing Manager
Senior Partner Marketing Manager

Clio • Vancouver, Calgary, Toronto

Hybrid
CAD 109,000 - 148,000
Health benefits
Dental and vision insurance
Hybrid work environment
+4
Software Development Manager, CBS Monetization
Software Development Manager, CBS Monetization

Clio • Vancouver

Hybrid
CAD 181,000 - 271,000
Hybrid work environment
Total Rewards program
20 days off per year
+1
Accounting Manager (18 Month Contract)
Accounting Manager (18 Month Contract)

Clio • Vancouver

Hybrid
CAD 118,000 - 178,000
Hybrid work environment
Competitive salary
Health benefits
+1
Senior Corporate Security Analyst
Senior Corporate Security Analyst

Clio • Burnaby, Calgary, Toronto

Hybrid
CAD 106,000 - 144,000