06 Sep
|
TMX Group
|
Toronto
Through a rich exchange of ideas, meaningful collaboration, and a nimble operating model, we’re powering some of the nation’s most critical systems, fueling capital formation and innovation, bringing increased opportunity to business visionaries, product ingenuity to consumers, and career exploration to our team. As a Senior Analyst, Enterprise Risk Management , you will support the delivery of the Enterprise Risk Management (ERM) and Operational Resilience programs across the Canadian Depository for Securities (CDS)—Canada’s central securities depository, clearing, and settlement hub—and the Canadian Derivatives Clearing Corporation (CDCC)—the national central counterparty for exchange-traded and over-the-counter derivatives—collectively known as “TMX Post-Trade.” You will play a vital role in safeguarding the organization by proactively identifying, assessing, and mitigating significant non-financial risks across complex vendor and regulatory landscapes. This position carries a primary focus on advancing the Third-Party Risk Management (TPRM) program through comprehensive risk assessments and continuous framework evolution, while driving critical regulatory initiatives and facilitating end-to‑end incident reporting.
This role reports to: Manager, Enterprise Risk Management & Non-Financial Resilience Job Location: Hybrid (2-3 days in office) - we are open to candidates being located in one of our Canadian office locations: Third Party Risk Management (TPRM) Support the Manager, ERM in developing and maintaining the TPRM governance framework, ensuring alignment with CDCC and CDS risk appetite. Support the efficient and effective implementation of the TPRM program across CDCC and CDS, including performing materiality assessment and risk-based due diligence on vendors onboarded as part of recent business initiatives and BAU. Provide guidance and training to Business Units on the requirements and responsibilities included in the TPRM governance.
Contribute to the preparation and delivery of the quarterly reporting process on the third-party risk profile. Assist in the deployment and application of new tools to automate and optimize third-party monitoring and reporting processes. Support the Manager, ERM in driving continuous improvement of Post-Trade’s TPRM program by analyzing industry trends and benchmarking against evolving global regulations (i.e.
DORA),
operational resilience and regulatory compliance.
Regulatory
Initiatives & Reviews Support the Manager, ERM in addressing non-financial risk regulatory inquiries related to regulatory initiatives and reviews. Support the Manager, ERM in developing and implementing emerging best practices that align with both regulatory requirements and broader industry standards. Support the Manager, ERM in monitoring and analyzing internal and external environments to identify emerging risks that may impact TMX Post-Trade’s strategic objectives and risk profile, and report to senior management.
Facilitate the end-to‑end incident reporting process, ensuring risk events are accurately documented, tracked, and escalated in a timely manner. Support root cause analyses of identified incidents and partnering with business units to track the implementation of corrective action plans. Collaborative Opportunities Across Enterprise Risk Management Programs: While the primary focus is on Third Party Risk Management (TPRM) and Regulatory Initiatives & Reviews, there may be opportunities to contribute in a supportive role to initiatives within: Operational Risk Management (ORM): Support risk assessment and oversight for operational activities.
Monitor key risk indicators, and analyze operational risk data to identify trends and inform strategic decisions.
Change Management Risk
Evaluation (CMRE): Support the identification, assessment, and oversight of the overall risk profile associated with significant changes and projects. Monitor adherence to change procedures and facilitate post‑implementation reviews.
Cyber Risk Management: Collaborate with the Information Security Office to track cyber threats, cyber incidents, and remediation efforts. Assist in embedding cyber risk considerations into broader risk programs and contribute to executive cybersecurity reporting. Coordinate and maintain Business Impact Analyses (BIA) and Business Continuity Plans (BCP).
Provide training and oversight for Disaster Recovery (DR) and BCP testing. Bachelor’s degree in Finance, Business Administration, or a related field (Master’s degree preferred).
Experience: Minimum of 3 years of relevant experience in risk management, audit, or compliance functions within financial services or consulting firms.
Core Risk Expertise: Proven track record delivering ERM/ORM projects, including Operational Resilience, Risk Appetite, Third-Party Risk Management, Internal Controls, Business Continuity Management, Crisis Management, and Cybersecurity concepts. Solid understanding of financial institutions, market infrastructures, and financial markets.
Communication Skills: Exceptional written and verbal communication skills, with the ability to articulate complex risk concepts clearly and concisely to diverse audiences.
Certifications: Professional designations in Operational Risk Management, Business Continuity Management, Third-Party Risk Management, and/or Cyber Risk Management (e.g., Regulatory Familiarity: Knowledge of key regulatory frameworks (e.g., Language Skills: Fluency in both French and English (written and spoken) is an asset to support regular interaction with bilingual partners and stakeholders.
Salary Range: 85K/year - 90K/year CAD. Explore emerging technology and innovation, as well as ventures and digital finance that shape the future of global markets! With site hubs in some of the world’s most multicultural cities, we leverage our size and structure to create rich connections and belonging while experiencing powerful global impact through our work.
More than a platform, we use our talents to power mission‑critical systems that drive global economic advancement, innovation, and growth. As well, our employee‑led Team Impact spreads social good via our giving strategy. Plus, with a cloud‑first and hybrid workstyle, as well as generous time‑off and leaves, we support a life well lived!
Please note that our company is not currently sponsoring work permit applications and the applicant must be authorized to work in the country where this position is located. TMX is committed to creating and sustaining a collegial work environment in which all individuals are treated with dignity and respect and one which reflects the diversity of the community in which we operate.
📌 Senior Analyst, Enterprise Risk Management (Third-Party Risk & Regulatory Initiative Focus) (Toronto)
🏢 TMX Group
📍 Toronto