3rd Party Risk and Governance Analyst (Intermediate)
- Toronto, ON
- On-site
- Posted Sep 2, 2026
- 1 position
Opens an external site
- Employment type
- Contract
- Experience level
- Mid-level · 2+ years
- Minimum education
- Professional degree
- Apply by
- Oct 2, 2026
- Posting language
- English
- Working hours
- 40 hours per week
- Seniority
- Associate
- Application method
- Direct apply is available
Job summary
Lead and coordinate third-party risk assessments across the full vendor lifecycle, including onboarding, monitoring, and offboarding. Partner with cross-functional teams to identify, mitigate, and govern third-party risks in accordance with regulatory expectations.
Job details
Our client in the insurance sector is seeking a Third-Party Risk & Governance Specialist with 3–5 years of hands-on experience in Third-Party Risk Management (TPRM), vendor governance, and supplier risk assessments. The successful candidate will support and execute TPRM activities across the full third-party lifecycle for enterprise technology engagements, including vendor onboarding, ongoing monitoring, renewals, risk remediation, and offboarding. Working closely with Business Owners, Cybersecurity, Privacy, Legal, Compliance, Procurement, Finance, and external vendors, this role will help ensure third-party risks are effectively identified, assessed, mitigated, monitored, and governed in accordance with organizational policies and applicable regulatory expectations. Responsibilities Lead and coordinate third-party risk assessments across vendor onboarding, renewals, ongoing monitoring, and off-boarding. Conduct and manage vendor criticality assessments, due diligence reviews, risk assessments, remediation plans, and risk exceptions. Partner with Business Owners, Cybersecurity, Privacy, Legal, Compliance, Procurement, Finance, and vendors to identify and address third-party risks. Monitor vendor performance and risk through scorecards, key metrics, ongoing assessments, and Quarterly Business Reviews (QBRs). Track vendor incidents, identified risks, issues, corrective action plans, concentration risks, and remediation activities through resolution. Develop and maintain vendor Exit Plans and Business Continuity Plans based on criticality and risk tier. Maintain the TPRM inventory and ensure vendor records, assessments, due diligence documentation, and governance activities remain accurate and current. Support third-party risk audits, regulatory reviews, governance reporting, and compliance with organizational TPRM policies. Identify opportunities to strengthen vendor governance, risk monitoring, controls, and overall TPRM processes. Requirements 3–5 years of experience in Third-Party Risk Management (TPRM), Vendor Risk Management, Vendor Governance, Compliance, Procurement, or Operational Risk. Hands-on experience conducting vendor due diligence, supplier risk assessments, criticality assessments, ongoing monitoring, and risk remediation. Experience managing third-party risks throughout the complete vendor lifecycle, from onboarding through renewal and offboarding. Strong understanding of risk identification, assessment, mitigation, issue management, corrective action plans, and risk exceptions. Strong stakeholder management skills with the ability to work effectively across business, technology, risk, procurement, and vendor teams. Strong analytical, organizational, documentation, and communication skills. Experience working with technology vendors, including SaaS, cloud, managed services, and other technology service providers, is preferred. Experience within financial services, insurance, healthcare, or another regulated environment is an asset. Knowledge of OSFI Guideline B-10, third-party risk management principles, operational resilience, or enterprise risk management frameworks is an asset. Experience facilitating QBRs and managing vendor scorecards, KPIs, and supplier performance monitoring programs is an asset. Professional certifications such as CRVPM, CTPRP, CISSP, CISA, CBCP, or equivalent are considered an asset.
What you’ll do
Lead and coordinate third-party risk assessments across the full vendor lifecycle, including onboarding, monitoring, and offboarding. Partner with cross-functional teams to identify, mitigate, and govern third-party risks in accordance with regulatory expectations.
Requirements
Requires 3–5 years of experience in TPRM, vendor governance, or operational risk, preferably within regulated sectors like insurance or finance. Strong analytical skills and experience with technology vendors (SaaS, Cloud) are highly desired.
Listed skills
- Compliance · Preferred
- Stakeholder Management · Preferred
Other relevant skills
Identified from the job description. Confirm important requirements above.
- Third-Party Risk Management
- Vendor Governance
- Supplier Risk Assessments
- Due Diligence
- Risk Remediation
- Vendor Onboarding
- Stakeholder Management
- Risk Identification
- Compliance
- Operational Risk
- Business Continuity Planning
- Vendor Performance Monitoring
- Criticality Assessments
- Issue Management
- Audit Support
- Governance Reporting
Job areas
- Security & Safety
- Consulting
- Finance & Accounting
- Technology
- Legal
More jobs you can apply to directly
Similar opportunities posted by employers hiring on Jobs.ca, with no external application form.
Bédard Ressources Humaines
ITAD Services Representative #1265
SponsoredDirect employerEasy Apply- On-site
- Mississauga, ON
- Posted Sep 16, 2026
Bédard Ressources Humaines
Plant Manager - Food Industry #1812
SponsoredDirect employerEasy Apply- On-site
- Posted Sep 9, 2026
Bédard Ressources Humaines
Table Games Trainer #1414
SponsoredDirect employerEasy Apply- On-site
- Posted Sep 8, 2026
