23 Aug
|
Hampton North
|
Toronto
23 Aug
Hampton North
Toronto
Third Party Risk Management Analyst The Third Party Risk Management Analyst owns third party cyber risk assessments end to end, from scoping and initiation through to following up on the recommendations that come out of them.
The team has a working process and a modern tooling stack already in place and needs the capacity to run it at volume. You will assess supplier security practices, interpret continuous monitoring data, track remediation, and represent the security function directly to vendors. This is an individual contributor seat on a small governance, risk and compliance team, reporting to the Supervisor of Cyber Supply Chain Risk Management.
Logistics: Remote with occasional on-site meetings in Toronto, ON – must be located in the greater Toronto area
Here's what you'll be doing:
- Running supplier cybersecurity risk assessments across the full lifecycle: determining scope, conducting the assessment, documenting findings, and following through on recommendations to closure
- Reviewing supplier security documentation and evidence, including SOC 2 Type 2 reports and ISO 27001 certifications, and judging whether the certification scope actually covers the product being purchased
- Running continuous monitoring through cyber risk rating and IP attribution platforms, interpreting score movements, and separating real posture changes from asset attribution noise
- Leading vendor calls independently on behalf of the security function, escalating to internal technical resources where a control question warrants it
- Documenting assessment results, tracking remediation activities, and communicating risk based recommendations to business and technology stakeholders
- Supporting implementation and enhancement of the GRC platform stack through requirements gathering, user acceptance testing,
workflow development and process documentation, including an active integration between the third party risk platform and ServiceNow
- Partnering across Procurement, Legal, IT, Physical Security, Supply Chain and business units to align supplier risk practices with policy and regulatory requirements
- Contributing to the development and maintenance of cybersecurity policies, standards and procedures supporting supply chain risk
And what you need to have:
- 3+ years in cybersecurity governance, risk and compliance, with hands on third party or supply chain risk assessment experience
- Bachelor's degree or equivalent experience
- Ability to read and interpret SOC 2 Type 2 reports, ISO 27001 certifications, and vendor security documentation with judgment about scope and applicability
- Working experience with cyber risk rating and IP attribution platforms: SAFE TPRM, BitSight, SecurityScorecard or equivalent, including an understanding of how assets get misattributed and how that skews a rating
- Working knowledge of a major GRC platform: Archer, ServiceNow GRC, MetricStream or equivalent, at a process and configuration level rather than as an application developer
- Familiarity with NIST CSF, NIST SP 800-53, NIST SP 800-171, FedRAMP, ISO 27001 and CSA STAR
- A cybersecurity foundation strong enough to recognize a security control when a vendor names one and know when to pull in an engineer
- Comfort operating independently and running vendor facing conversations without supervision
- Relevant certification such as CRISC or Security+
- Nice to have: experience in a regulated utility workplace, including NERC CIP supply chain requirements
- Nice to have: exposure to contract review alongside security assessment
- Nice to have: project side experience implementing GRC or third party risk tooling
No CTC or sponsorship at this time.
📌 Third Party Risk Management Analyst (Toronto)
🏢 Hampton North
📍 Toronto