1

Director Third Party Risk Management Jobs in Toronto, ON

Ensure vendor engagements align with FNZ's third-party risk management framework and regulatory ... Independent, self-directing and delivery focused working style. Commercially aware. Excellent ...

Manager, Global Risk Management

Toronto, ON · On-site

$82.43 - $103.04/hr

Provides risk advisory to the business on Third-party risk management Insurance * Manages and sustains the global insurance program, including but not limited to regional insurance underwriting ...

Ensure all supplier activities align with third-party risk management policies, standards, and enterprise frameworks * Promote a customer-focused, collaborative culture that leverages the broader ...

Strong knowledge of Insurance business, operations, procurement processes, sourcing methodologies, contract law, as well as experience with third-party risk management frameworks and regulations ...

Relevant areas include technology and cyber risk management, third-party risk management, operational resilience, incident reporting, data protection, governance, and internal control effectiveness.

... directed by the Manager, ERM * Oversees and provides organizational support, input and system ... Third Party Risk Assessments (TPRAs) * Incident Management * Model Risk Management * Maintains a ...

Showing results 21-40

Director Third Party Risk Management information

See Toronto, ON salary details

$21.5K

$99.9K

$194.7K

How much do director third party risk management jobs pay per year?

As of Sep 3, 2026, the average yearly pay for director third party risk management in Toronto, ON is $99,918.00, according to ZipRecruiter salary data. Most workers in this role earn between $65,849.00 and $130,267.00 per year, depending on experience, location, and employer.

What does a director of third party risk management do?

A Director of Third Party Risk Management is responsible for overseeing an organization's approach to identifying, assessing, and mitigating risks associated with its external partners, vendors, and suppliers. This role involves developing risk assessment frameworks, ensuring compliance with relevant regulations, and collaborating with internal teams to address any third-party issues that may affect the business. The director also leads the creation and execution of policies and procedures to manage third-party risks effectively, balancing operational needs with regulatory requirements.

What are some of the key challenges a director of third party risk management faces when implementing risk assessment frameworks across a large organization?

One of the main challenges is ensuring consistency and thoroughness in risk assessments across diverse business units and geographies, each with varying levels of vendor complexity and regulatory requirements. Directors often need to balance rigorous risk controls with the need for operational efficiency, which requires strong communication and influence skills to gain stakeholder buy-in. Additionally, keeping up with evolving third-party risks, such as cybersecurity threats and supply chain disruptions, demands continuous process improvement and cross-functional collaboration with IT, legal, and procurement teams.

What are the key skills and qualifications needed to thrive as a director of third party risk management, and why are they important?

To thrive as a Director of Third Party Risk Management, you typically need expertise in risk assessment, compliance, vendor management, and a relevant degree in business, finance, or a related field. Familiarity with risk management frameworks, regulatory requirements, and tools like GRC (Governance, Risk, and Compliance) platforms or vendor risk assessment software is essential. Exceptional leadership, strategic thinking, and negotiation skills help manage cross-functional teams and build strong relationships with vendors. These competencies are crucial to effectively mitigate third-party risks, ensure regulatory compliance, and protect the organization’s reputation and operations.

What is the difference between Director Third Party Risk Management vs Vendor Risk Manager?

AspectDirector Third Party Risk ManagementVendor Risk Manager
CredentialsTypically requires advanced degrees and certifications like CTPRP or CRISCOften requires certifications such as CTPRP, CRISC, or vendor-specific training
Work EnvironmentStrategic leadership, overseeing multiple teams and enterprise-wide risk policiesOperational focus, managing vendor assessments and risk mitigation activities
Industry UsageUsed in large organizations across finance, healthcare, and technology sectorsCommon in organizations with extensive vendor networks, especially in finance and IT

The main difference is that the Director Third Party Risk Management holds a strategic, leadership role overseeing enterprise-wide third-party risks, while the Vendor Risk Manager focuses on operational vendor assessments and risk mitigation. Both roles require similar certifications but differ in scope and level of responsibility.

What job categories do people searching Director Third Party Risk Management jobs in Toronto, ON look for?

The top searched job categories for Director Third Party Risk Management jobs in Toronto, ON are:

Infographic showing various Director Third Party Risk Management job openings in Toronto, ON as of August 2026, with employment types broken down into 1% As Needed, 82% Full Time, 14% Part Time, and 3% Contract. Highlights an 88% Physical, 3% Hybrid, and 9% Remote job distribution, with an average salary of $99,918 per year, or $48 per hour.

Director, Governance, Risk and Compliance (GRC)

Momentum Financial Services Group

Toronto, ON • Hybrid

Full-time

Medical, Dental

Re-posted 20 hours ago


Job description

Who We Are

At Momentum Financial Services Group, we help people move forward by reimagining how money works for those who need it most. With more than 40 years of experience, we're the team behind Money Mart-Canada's largest non-bank branch network-and a leader in financial solutions for underserved communities.

From short-term loans to money transfers and prepaid cards, we power the products, technology, and operations that connect over a million customers a year to the money they need, when they need it.

At MFSG, we come together across teams and departments to create something bigger than ourselves: solutions that remove barriers and give people access to money they might not get anywhere else. Whether you're solving problems, building systems, or shaping strategy, your work fuels real support for real people.

We've Got You Covered

Compensation Philosophy: Our strategy is simple-we aim to match the market. We regularly review industry standards to ensure our total rewards package is competitive and fair. This commitment helps us attract and retain talented individuals who share our purpose.

Discretionary Annual Bonus: Enjoy the opportunity for a discretionary bonus based on individual performance and company success.

Comprehensive Benefits: Our benefits include health and dental plans with 100% of the premiums covered. We also offer an Employee Assistance Program to support your mental well-being and provide resources for personal challenges.

Retirement Plans: Plan for your future with our robust retirement savings options, ensuring you're set for the long haul.

Hybrid Work Environment: Experience the best of both worlds with our hybrid work model, allowing you to balance remote work with in-office. When you're at our corporate head office, enjoy a relaxed and collaborative environment featuring breakout rooms for brainstorming and unwinding, plus a variety of snacks to keep you energized throughout the day.

Perks and Rewards: Enjoy reimbursement for tuition assistance and professional development, discounts through Perkopolis and participate in our rewards and recognition programs to celebrate your contributions.

The Job: Director, Governance, Risk and Compliance (GRC)

We're seeking a Director, Governance, Risk and Compliance (GRC) to lead and operate MFSG's cybersecurity governance, cyber risk management, compliance, and data governance functions. This is a highly hands-on senior individual contributor role responsible for strengthening governance frameworks, overseeing cyber risk activities, supporting regulatory compliance, and driving risk-informed decision-making across the organization.

What You'll Do

Cyber Risk Management & Governance:

  • Own and operate the enterprise cyber risk management framework
  • Maintain cybersecurity, technology, and data risk registers
  • Conduct cyber risk assessments across business processes, systems, vendors, and strategic initiatives
  • Define and track key risk indicators (KRIs), metrics, and remediation activities
  • Support post-incident risk reviews and continuous improvement efforts

Compliance, Audit & Regulatory Oversight:

  • Support internal and external audits, regulatory reviews, and customer due diligence requests
  • Validate control effectiveness and coordinate audit evidence collection
  • Manage cybersecurity policy governance and exception management processes
  • Ensure alignment with industry frameworks including NIST, ISO 27001, privacy regulations, and financial sector requirements

Data Governance & Third-Party Risk Management:

  • Partner with data governance, privacy, legal, and compliance teams to manage information risk
  • Oversee data governance activities including classification, retention, protection, access governance, and recovery controls
  • Support vendor and third-party risk assessments and remediation efforts

Reporting, Stakeholder Engagement & Cross-Functional Influence:

  • Prepare executive-level cyber risk reporting and governance updates
  • Present risk trends, control gaps, remediation progress, and emerging risks to leadership
  • Influence business, technology, and control owners to drive risk reduction activities
  • Build strong relationships across cybersecurity, IT, legal, compliance, enterprise risk, and operational teams

Governance Program Development & Operational Leadership:

  • Develop and mature cybersecurity governance programs, policies, standards, and procedures
  • Improve GRC processes, workflows, and governance effectiveness
  • Personally execute critical deliverables in a hands-on leadership capacity
  • Balance business objectives with practical, risk-based governance and security controls
What You'll Bring to the Table
  • 10+ years of experience in information security, cybersecurity, technology risk, or IT controls
  • At least 5 years of direct GRC experience, including 3+ years in a leadership capacity
  • Experience within banking, fintech, insurance, payments, wealth management, or another regulated financial services environment
  • Proven success operating as a senior individual contributor with ownership of risk assessments, governance documentation, executive reporting, and remediation tracking
  • Strong understanding of enterprise cyber risk management, governance, and compliance practices
  • Extensive experience with data governance risk management, privacy controls, and information asset protection
  • Experience managing cyber risk registers, risk reviews, issue management, and remediation programs
  • Strong knowledge of Canadian financial sector regulatory expectations, operational resilience principles, and privacy obligations
  • Excellent communication skills with the ability to translate technical issues into clear business risk language
Education + Experience
  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Risk Management, or a related field, or equivalent practical experience
  • Experience supporting audits, regulatory reviews, customer security assessments, and control testing activities
  • Strong understanding of identity and access management, data protection, cloud security, vulnerability management, incident response, third-party risk, and business continuity
Preferred Qualifications
  • Experience within a Canadian regulated financial institution or fintech organization
  • Professional certifications such as CISSP, CISM, CRISC, CGEIT, or ISO 27001 Lead Implementer/Auditor
  • Experience implementing or enhancing GRC platforms, workflow automation, and reporting dashboards
  • Familiarity with PCI DSS, SOC 2, cloud control frameworks, and privacy control frameworks
  • Experience mapping controls across multiple regulatory and compliance frameworks
Closing

Ready to lead cybersecurity governance and influence enterprise risk decisions across a growing organization? Join us and help strengthen the security, resilience, and compliance foundation of MFSG.

Committed to Equal Opportunity:

MFSG is committed to accommodating applicants up to the point of undue hardship during the recruitment, assessment and selection process. If you are selected for an interview, please notify MFSG if you require accommodation in respect of the materials or procedures used at any time during this process. If you require accommodation, MFSG will work with you to determine how to meet your needs.

Please note: The salary range for this position is between C$175,000 to C$ 190,000.