18 Aug
|
Odyssey Global
|
Ontario
18 Aug
Odyssey Global
Ontario
Title: Third-Party Risk & Governance Specialist
Duration: 6-Month Contract (Potential for Extension / Full-time)
Location: 30 Wellington Street West, Toronto, ON M5L 1B1 (2 days in office / 3 days remote)
About the Role We are seeking a Third-Party Risk & Governance Specialist with 3–5 years of hands‑on experience in Third-Party Risk Management (TPRM), vendor governance, and supplier risk assessments. This role will be responsible for supporting and executing TPRM activities across the full third-party lifecycle for enterprise‑wide Technology engagements, including onboarding, ongoing monitoring, renewals, and offboarding/deprecation.
Working closely with Business Owners, Risk Assessors (Cybersecurity, Privacy, Legal, Compliance, Procurement, Finance, and other stakeholders), and external vendors, the Specialist will help ensure that third-party risks are identified, assessed, mitigated, monitored, and governed in accordance with GreenShield's TPRM Policy and regulatory expectations.
The ideal candidate combines robust risk management knowledge with excellent stakeholder management skills and a hands‑on approach to governance, ongoing monitoring, issue management, and vendor risk remediation.
What You'll Do Lead and coordinate TPRM assessments for vendor onboarding, renewals, ongoing monitoring, and offboarding
Partner with Business Owners, Privacy, Security, Legal, Compliance, Procurement, and vendors to identify, assess, and mitigate third-party risks
Manage vendor criticality assessments, due diligence reviews, risk remediation plans, and risk exceptions
Monitor supplier performance through scorecards, metrics, and Quarterly Business Reviews (QBRs) for strategic suppliers
Track and manage incidents, issues, corrective action plans, concentration risk, and ongoing risk mitigation activities
Develop and maintain Exit Plans and Business Continuity Plans based on vendor criticality and risk tier
Maintain the TPRM Inventory and ensure vendor risk records, due diligence documentation, and governance activities remain current
Support audits, regulatory requirements, and adherence to GreenShield's TPRM Policy
What You Bring 3-5 years of experience in Third-Party Risk Management, Vendor Risk Management, Governance, Compliance, Procurement, or Operational Risk
Experience managing vendor due diligence, risk assessments, ongoing monitoring, and remediation activities
Strong stakeholder management skills and the ability to collaborate across business, risk, and vendor teams
Strong analytical, organizational, and communication skills
Experience supporting technology, SaaS, cloud, or managed service providers is an asset
Nice to Have Experience supporting financial services, insurance, healthcare, or other regulated environments.
Understanding of OSFI B-10, third-party risk management principles, operational resilience, or enterprise risk management frameworks.
Experience facilitating QBRs, vendor scorecards, and performance monitoring programs.
Exposure to SaaS, cloud, managed services, and technology supplier ecosystems.
Professional certifications such as CRVPM, CTPRP, CISSP, CISA, CBCP, or equivalent.
#J-18808-Ljbffr
📌 Third Party Risk Management Specialist (Ontario)
🏢 Odyssey Global
📍 Ontario