3

Full Time Remote Third Party Risk Jobs in Ontario

Third Party Cyber Risk Management * Cyber Strategy, Governance, and Delivery * Delivery Excellence: * Oversee multidisciplinary teams delivering cyber programs in areas such as identity and access ...

Security Review Expert - SOC 2

Toronto, ON ยท Remote

CA$90 - CA$110/hr

Remote Role Responsibilities * Review simulated vendor SOC 2 reports , security questionnaires, and ... or third-party risk (TPRM). * Hands-on experience evaluating SOC 2 reports , security ...

Gatekeeper is the ONLY unified contract & third-party-risk management platform that protects ... Note: This is a fully remote position, open to applicants based in Ontario . Role Overview ...

NET backend services - and includes integrations with hardware and third-party vendors (smart locks ... remote environment Clear communication skills and a collaborative mindset Experience using AI ...

Enterprise Security Specialist

Stouffville, ON ยท On-site +1

CA$120K - CA$135K/yr

Lead third-party security risk assessments and vendor security reviews. * Support security ... Flexible working arrangements (hybrid, remote, or in-office) designed to support work-life balance.

next page

Showing results 1-20

Full Time Remote Third Party Risk information

What is a full time remote third party risk professional?

A Full Time Remote Third Party Risk professional is responsible for assessing, monitoring, and managing the risks that arise from an organization's relationships with external vendors or service providers, while working remotely. Their job includes conducting due diligence on third parties, ensuring compliance with relevant regulations, and implementing risk mitigation strategies. They collaborate with internal teams to identify potential threats to data security, operational continuity, or reputation that may arise from third-party engagements. This role is crucial for organizations that rely on external partners and want to minimize potential risks, especially in industries like finance, healthcare, and technology.

How does a full time remote third party risk professional typically collaborate with internal teams and external vendors?

As a Full Time Remote Third Party Risk professional, you will regularly coordinate with internal stakeholders such as procurement, legal, IT security, and compliance teams to assess and manage vendor risks. Communication is often conducted through video meetings, emails, and collaboration platforms, ensuring all parties are aligned on risk assessment processes and remediation actions. Additionally, you may interact directly with third-party vendors to gather necessary documentation, clarify risk-related queries, and support due diligence activities. Strong organizational and communication skills are essential for managing these cross-functional relationships effectively in a remote setting.

What are the key skills and qualifications needed to thrive as a full time remote third party risk professional, and why are they important?

To thrive as a Full Time Remote Third Party Risk professional, you need a solid understanding of risk management principles, vendor assessment procedures, and regulatory compliance, typically supported by a bachelor's degree in business, finance, or a related field. Familiarity with third-party risk management platforms, GRC (governance, risk, and compliance) tools, and relevant certifications such as CTPRP or CISA is highly valuable. Strong analytical thinking, effective communication, and the ability to manage projects independently are crucial soft skills. These competencies are essential for accurately assessing vendor risks, ensuring regulatory compliance, and maintaining the security and integrity of organizational operations in a remote environment.

What is the difference between Full Time Remote Third Party Risk vs Full Time Remote Vendor Risk Analyst?

AspectFull Time Remote Third Party RiskFull Time Remote Vendor Risk Analyst
CredentialsRisk management certifications, such as CRISC or CTPRPRisk management certifications, often CRISC or CTPRP
Work EnvironmentRemote, collaborative with risk teams and vendorsRemote, focused on analyzing vendor risks and compliance
Industry UsageFinancial, healthcare, technology sectorsFinancial, healthcare, technology sectors
Job FocusManaging risks associated with third-party vendors and partnersAssessing and mitigating risks posed by vendors

While both roles involve risk assessment and require similar certifications, the Full Time Remote Third Party Risk role emphasizes managing overall third-party relationships, whereas the Full Time Remote Vendor Risk Analyst focuses specifically on analyzing individual vendors' risks. Both positions are integral to organizational risk management in remote settings.

What cities in Ontario are hiring for Full Time Remote Third Party Risk jobs?

Cities in Ontario with the most Full Time Remote Third Party Risk job openings:

Infographic showing various Full Time Remote Third Party Risk job openings in Ontario as of July 2026, with employment types broken down into 100% Full Time. Highlights an 100% Remote job distribution.

Vendor Risk Specialist - Fully Remote | Upto $110/hr

Mercor

Toronto, ON โ€ข Remote

CA$110/hr

Full-time

This job post hasย expired 2 days ago.ย Applications are no longer accepted.


Job description

About the job

Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark, General Catalyst, Peter Thiel, Adam D'Angelo, Larry Summers, and Jack Dorsey.

Position: Security Expert
Type: Contract
Compensation: $90–$110/hour
Location: Remote

Role Responsibilities

  • Review simulated vendor SOC 2 reports, security questionnaires, and pen-test evidence against a buyer's security standard.
  • Catch scope mismatches and lapsed bridge letters that a surface-level review would miss.
  • Author step-level rubrics and golden responses capturing how an experienced security reviewer would judge a request or renewal.
  • Assess data-handling and sub-processor risk for vendors touching sensitive data.
  • Work independently and asynchronously to meet deadlines while improving AI model performance.

Qualifications

Must-Have

  • 8+ years of professional experience in security review, vendor risk management, or third-party risk (TPRM).
  • Hands-on experience evaluating SOC 2 reports, security questionnaires, and compliance evidence.
  • Strong written communication skills; comfortable producing structured, rubric-style feedback.

Preferred

  • Relevant security certification, such as CISSP or CISA.
  • Prior task-writing, rubric-authoring, or AI-training data experience.

Application Process (Takes 20–30 mins to complete)

  • Upload resume
  • AI interview based on your resume
  • Submit form

Resources & Support

  • For details about the interview process and platform information, please check: https://talent.docs.mercor.com/welcome
  • For any help or support, reach out to: support@mercor.com

PS: Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity.