2

Third Party Risk Analyst Remote Jobs in Ontario (NOW HIRING)

Third Party Cyber Risk Management * Cyber Strategy, Governance, and Delivery * Delivery Excellence: * Oversee multidisciplinary teams delivering cyber programs in areas such as identity and access ...

Remote Role Responsibilities * Review simulated vendor SOC 2 reports , security questionnaires, and ... or third-party risk (TPRM). * Hands-on experience evaluating SOC 2 reports , security ...

Perform NERC-compliance-related technical analyses such as TPL-001-4 Annual Planning Assessments ... Any unsolicited third-party resumes forwarded by recruiters to EPE via our career page or to any of ...

Manager, Compliance & Privacy

Toronto, ON · Remote

CA$95K - CA$105K/yr

This position is remote but may require to be in-office in Toronto for team collaborations. What ... Participate in vendor/third-party risk assessments (DPAs, sub-processor review and audits)

next page

Showing results 1-20

Third Party Risk Analyst Remote information

What does a third party risk analyst do?

A Third Party Risk Analyst is responsible for assessing and managing the risks associated with an organization’s external vendors or partners. They evaluate third parties to ensure they meet security, compliance, and operational standards. This role often involves conducting risk assessments, monitoring vendor performance, and recommending risk mitigation strategies. Working remotely, these analysts use digital tools to collaborate with internal teams and communicate with vendors.

What are the key skills and qualifications needed to thrive as a third party risk analyst?

To thrive as a Third Party Risk Analyst (Remote), you need a solid understanding of risk management frameworks, vendor due diligence, and compliance regulations, typically supported by a bachelor's degree in a related field. Familiarity with risk assessment tools, GRC (governance, risk, and compliance) platforms, and certifications such as CTPRA or CISA are often required. Strong analytical thinking, attention to detail, and effective communication are essential soft skills for evaluating and managing third-party risks collaboratively. These skills ensure organizations can identify, assess, and mitigate risks posed by external partners, maintaining regulatory compliance and protecting business interests.

How does a third party risk analyst collaborate with other departments in a remote work setting?

As a remote Third Party Risk Analyst, collaboration with departments such as procurement, legal, IT security, and compliance is typically achieved through regular virtual meetings and shared documentation platforms. You’ll often coordinate with these teams to assess vendor risks, review contracts, and ensure compliance with company policies. Clear communication and proactive follow-ups are key, as you may be managing multiple projects and stakeholders simultaneously. Building strong remote relationships helps streamline risk assessment processes and ensures effective risk mitigation strategies.

What is the difference between Third Party Risk Analyst Remote vs Vendor Risk Analyst?

AspectThird Party Risk Analyst RemoteVendor Risk Analyst
CredentialsCertifications like CRISC, CISA often preferredSimilar certifications, often including CRISC, CISA
Work EnvironmentRemote, primarily online collaborationRemote or on-site, depending on company policy
Industry UsageFinancial, healthcare, technology sectorsFinancial, retail, manufacturing sectors
Job FocusAssessing third-party risks and complianceEvaluating vendor security and operational risks

The main difference is that a Third Party Risk Analyst Remote focuses on assessing risks posed by third-party entities across various industries, often working remotely. A Vendor Risk Analyst typically concentrates on evaluating specific vendors' security and operational risks, which may involve more direct vendor interactions. Both roles require similar certifications and work environments, but their scope and focus differ slightly.

What are the most commonly searched types of Third Party Risk Analyst jobs in Ontario?

The most popular types of Third Party Risk Analyst jobs in Ontario are:

What are popular job titles related to Third Party Risk Analyst Remote jobs in Ontario?

For Third Party Risk Analyst Remote jobs in Ontario, the most frequently searched job titles are:

What job categories do people searching Third Party Risk Analyst Remote jobs in Ontario look for?

The top searched job categories for Third Party Risk Analyst Remote jobs in Ontario are:

Infographic showing various Third Party Risk Analyst Remote job openings in Ontario as of August 2026, with employment types broken down into 1% As Needed, 81% Full Time, 16% Part Time, and 2% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution.

Vendor Risk Specialist - Fully Remote | Upto $110/hr

Mercor

Toronto, ON • Remote

CA$110/hr

Full-time

Posted 6 days ago


Job description

About the job

Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark, General Catalyst, Peter Thiel, Adam D'Angelo, Larry Summers, and Jack Dorsey.

Position: Security Expert
Type: Contract
Compensation: $90–$110/hour
Location: Remote

Role Responsibilities

  • Review simulated vendor SOC 2 reports, security questionnaires, and pen-test evidence against a buyer's security standard.
  • Catch scope mismatches and lapsed bridge letters that a surface-level review would miss.
  • Author step-level rubrics and golden responses capturing how an experienced security reviewer would judge a request or renewal.
  • Assess data-handling and sub-processor risk for vendors touching sensitive data.
  • Work independently and asynchronously to meet deadlines while improving AI model performance.

Qualifications

Must-Have

  • 8+ years of professional experience in security review, vendor risk management, or third-party risk (TPRM).
  • Hands-on experience evaluating SOC 2 reports, security questionnaires, and compliance evidence.
  • Strong written communication skills; comfortable producing structured, rubric-style feedback.

Preferred

  • Relevant security certification, such as CISSP or CISA.
  • Prior task-writing, rubric-authoring, or AI-training data experience.

Application Process (Takes 20–30 mins to complete)

  • Upload resume
  • AI interview based on your resume
  • Submit form

Resources & Support

  • For details about the interview process and platform information, please check: https://talent.docs.mercor.com/welcome
  • For any help or support, reach out to: support@mercor.com

PS: Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity.