3rd Party Risk and Governance Analyst (Intermediate) (Toronto)

3rd Party Risk and Governance Analyst (Intermediate) (Toronto)

04 Sep
|
Resonaite
|
Toronto

04 Sep

Resonaite

Toronto

Our client in the insurance sector is seeking a Third-Party Risk & Governance Specialist with 3–5 years of hands-on experience in Third-Party Risk Management (TPRM), vendor governance, and supplier risk assessments.

The successful candidate will support and execute TPRM activities across the full third-party lifecycle for enterprise technology engagements, including vendor onboarding, ongoing monitoring, renewals, risk remediation, and offboarding. Working closely with Business Owners, Cybersecurity, Privacy, Legal, Compliance, Procurement, Finance, and external vendors, this role will help ensure third-party risks are effectively identified, assessed, mitigated, monitored, and governed in accordance with organizational policies and applicable regulatory expectations.

Responsibilities

- Lead and coordinate third-party risk assessments across vendor onboarding, renewals, ongoing monitoring, and off-boarding.
- Conduct and manage vendor criticality assessments, due diligence reviews, risk assessments, remediation plans, and risk exceptions.
- Partner with Business Owners, Cybersecurity, Privacy, Legal, Compliance, Procurement, Finance, and vendors to identify and address third-party risks.
- Monitor vendor performance and risk through scorecards, key metrics, ongoing assessments, and Quarterly Business Reviews (QBRs).
- Track vendor incidents, identified risks, issues, corrective action plans, concentration risks, and remediation activities through resolution.
- Develop and maintain vendor Exit Plans and Business Continuity Plans based on criticality and risk tier.
- Maintain the TPRM inventory and ensure vendor records, assessments, due diligence documentation,



and governance activities remain accurate and current.
- Support third-party risk audits, regulatory reviews, governance reporting, and compliance with organizational TPRM policies.
- Identify opportunities to strengthen vendor governance, risk monitoring, controls, and overall TPRM processes.

Requirements

- 3–5 years of experience in Third-Party Risk Management (TPRM), Vendor Risk Management, Vendor Governance, Compliance, Procurement, or Operational Risk.
- Hands-on experience conducting vendor due diligence, supplier risk assessments, criticality assessments, ongoing monitoring, and risk remediation.
- Experience managing third-party risks throughout the complete vendor lifecycle, from onboarding through renewal and offboarding.
- Strong understanding of risk identification, assessment, mitigation, issue management, corrective action plans, and risk exceptions.
- Strong stakeholder management skills with the ability to work effectively across business, technology, risk, procurement, and vendor teams.
- Strong analytical, organizational, documentation, and communication skills.
- Experience working with technology vendors, including SaaS, cloud, managed services, and other technology service providers, is preferred.
- Experience within financial services, insurance, healthcare, or another regulated environment is an asset.
- Knowledge of OSFI Guideline B-10, third-party risk management principles, operational resilience, or enterprise risk management frameworks is an asset.
- Experience facilitating QBRs and managing vendor scorecards, KPIs, and supplier performance monitoring programs is an asset.
- Skilled certifications such as CRVPM, CTPRP, CISSP, CISA, CBCP, or equivalent are considered an asset.

📌 3rd Party Risk and Governance Analyst (Intermediate) (Toronto)
🏢 Resonaite
📍 Toronto

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: 3rd party risk and governance analyst (intermediate) (toronto) / toronto