1

Third Party Risk Analyst Jobs in Ontario (NOW HIRING)

We are looking for a Manager to join our growing practice with a specialized focus on Third Party Risk Management (TPRM). The successful candidate will be responsible for being a key contributor in ...

Lead Analyst - Cybersecurity (SITRM) Location: Krakow, Poland (Hybrid) Type: Full-time employment ... Working experience third party security risk assessment methodologies and industry frameworks.

next page

Showing results 1-20

Third Party Risk Analyst information

How does a Third Party Risk Analyst typically collaborate with other departments to manage vendor risks?

A Third Party Risk Analyst works closely with departments such as procurement, legal, IT security, and compliance to assess and mitigate potential risks posed by vendors and service providers. Collaboration often involves reviewing contracts, conducting risk assessments, and ensuring vendors meet the organization's security and compliance requirements. Regular communication and joint meetings are common to align on risk standards and address any emerging concerns. This cross-functional teamwork ensures a comprehensive approach to managing third-party risks and maintaining regulatory compliance.

What is the difference between Third Party Risk Analyst vs Vendor Risk Analyst?

AspectThird Party Risk AnalystVendor Risk Analyst
CertificationsCertifications like CRISC, CISA often preferredSimilar certifications, often the same as Third Party Risk Analyst
Work EnvironmentFinancial institutions, corporations managing third-party relationshipsOrganizations assessing vendor security, compliance, and performance
Industry UsageCommon in finance, healthcare, and tech sectorsPrimarily in procurement, supply chain, and IT sectors

The main difference is that a Third Party Risk Analyst focuses on assessing risks associated with all third-party relationships, including vendors, partners, and service providers. A Vendor Risk Analyst specifically concentrates on evaluating risks posed by vendors and suppliers. While their roles overlap, the Third Party Risk Analyst has a broader scope, often handling multiple types of third-party relationships within various industries.

Is a grc analyst a good entry-level job?

A third-party risk analyst is often considered an entry-level role in risk management and compliance, suitable for individuals with strong analytical skills and knowledge of regulations like GDPR or HIPAA. The position typically involves assessing vendor risks, using tools like GRC software, and may require certifications such as CRISC or CISA. It provides a foundation for career growth in cybersecurity, compliance, or risk management fields.

How much does a third-party risk analyst make?

A third-party risk analyst typically earns between $60,000 and $100,000 annually, depending on experience, location, and industry. Entry-level positions may start lower, while experienced analysts with certifications like CRISC or CISSP can earn higher salaries.

Is third-party risk management a good career?

Third-party risk management is a growing field within risk analysis and compliance, focusing on assessing and mitigating risks from external vendors and partners. It requires skills in risk assessment, regulatory knowledge, and often involves using tools like risk management software. The role offers opportunities for career advancement in industries such as finance, healthcare, and technology.

What does a third-party risk analyst do?

A third-party risk analyst evaluates the risks associated with an organization’s external vendors, suppliers, and partners. They assess third-party security, compliance, and operational risks using tools like risk management software and often require knowledge of industry standards and certifications. Their goal is to ensure that external relationships do not compromise the organization’s security or compliance posture.

What are the key skills and qualifications needed to thrive as a Third Party Risk Analyst, and why are they important?

To thrive as a Third Party Risk Analyst, you need a solid understanding of risk management principles, vendor assessment processes, and compliance regulations, often supported by a degree in business, finance, or information security. Familiarity with risk assessment tools, GRC (Governance, Risk, and Compliance) platforms, and certifications like CTPRA or CRISC is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills set exceptional analysts apart in this field. These competencies are crucial for identifying and mitigating vendor risks, ensuring organizational compliance, and safeguarding sensitive data.
What are the most commonly searched types of Third Party Risk Analyst jobs in Ontario? The most popular types of Third Party Risk Analyst jobs in Ontario are:
What are popular job titles related to Third Party Risk Analyst jobs in Ontario? For Third Party Risk Analyst jobs in Ontario, the most frequently searched job titles are:
What job categories do people searching Third Party Risk Analyst jobs in Ontario look for? The top searched job categories for Third Party Risk Analyst jobs in Ontario are:
Infographic showing various Third Party Risk Analyst job openings in Ontario as of July 2026, with employment types broken down into 87% Full Time, 8% Part Time, 1% Temporary, and 4% Contract. Highlights an 83% Physical, 7% Hybrid, and 10% Remote job distribution.
AVP Third Party Risk Management

AVP Third Party Risk Management

Peoples Group

Toronto, ON

Full-time

PTO

Posted yesterday


Job description

We are hiring for this position out of our Toronto, Calgary, and Vancouver offices. Successful candidates who apply outside of these areas will be expected to relocate and reside in a location that is within a commutable distance.  

Role Overview

The Assistant Vice President, Third Party Risk Management (TPRM) is responsible for leading the implementation and ongoing execution of the Peoples Group TPRM framework, including ownership of the TPRM policy, supporting toolkits, inventory, and compliance tracking. This role leads and develops a team accountable for running the TPRM program, providing effective challenge to thirdparty risk and criticality assessments, and ensuring regulatory requirements are met across the enterprise.

The AVP prepares regular reporting for senior management and Board committees, partners closely with Technology on the development and maintenance of the TPRM system, and works collaboratively with Legal, Procurement, Information Security, and Relationship Owners to manage thirdparty onboarding, contracting, cyber risk, and ongoing monitoring. Success in this role requires strong stakeholder and conflict management skills to balance business objectives, client expectations, and regulatory obligations, as well as the ability to build productive relationships across multiple departments and drive enterprisewide training and compliance with TPRM requirements.

About the day-to-day

  • Lead the implementation of the Peoples Group TPRM framework.
  • Responsible for maintaining the TPRM Policy and Framework as well as the documentation supporting TPRM toolkits (Criticality and Risk Triage, Risk Assessment Template, Due Diligence Questionnaire, Contracting Requirements, Monitoring Plans, Contingency and Exit Planning, Exception Management).
  • Manage a team of analysts and senior managers accountable for running the TPRM Framework. Lead the team in providing constructive challenge to the results of third-party risk and criticality assessments completed by the Relationship Owners.
  • Own and manage the TPRM inventory and compliance tracker.
  • Prepare regular reporting for the Operational Risk Management Committee, Corporate Risk Committee and Board Risk Committee.
  • Work directly with the Technology team on the development and launch of the TPRM system to facilitate completion of the required toolkits and inventory of required Third-Party documentation. This includes accountability for User Acceptance Testing prior to launch and for regular patches and updates from the software provider.
  • Successfully manage friction arising between business objectives, client expectations and regulatory requirements. Account Managers and their clients are important stakeholders in the success of TPRM. The successful candidate will be relied on to diffuse tensions when working with clients and counterparties to meet regulatory requirements for TPRM.
  • Develop and coordinate enterprise-wide training on TPRM requirements.
  • Work directly with Relationship Owners to clarify requirements for the onboarding and management of Third-Parties.
  • Work closely with the Legal and Procurement departments to maintain control processes and compliance requirements when onboarding new Third-Parties and executing contracts.
  • Coordinate with the Information Security Team to assess cyber-security control effectiveness at critical third parties.
  • Working across all departments within PTC, partnering with relationship owners to maintain compliance and update third-party criticality and risk assessment. Collaboratively escalating gaps with requirements and facilitating approval of waivers where appropriate.
  • Establishing productive relationships and working successfully with stakeholders across multiple departments is essential for success in this role.

About the qualifications

  • 10+ years experience working in risk management or operations at a Canadian Financial Institution, with at least 5 years of experience in a management role.
  • Successfully delivered enterprise-wide risk projects requiring significant change management and training across departments.
  • Familiarity with Software Development Life Cycle in the context of enterprise applications and experience developing requirements for risk management solutions and coordinating User Acceptance Testing.
  • Required experience in developing Third Party Risk Management TPRM Frameworks at Small and Medium Sized Banks (SMSBs) in Canada. Alternatively, applicants with intricate knowledge and experience in running an established TPRM framework at an SMSB or DSIB will also be considered.
  • Direct experience in managing OSFI expectation and regulatory findings related to TPRM and Guideline B-10 is a significant asset.
  • Strong communication skills, with experience presenting at senior management committee meetings and interacting directly with C-level executives at SMSBs.
  • Proven conflict management capabilities when working across multiple departments and stakeholders to achieve positive risk and compliance outcomes.

About us

Peoples Group is a trusted financial services company for the innovators at the forefront of Canada’s economic future. With offices in Vancouver, Calgary, and Toronto, we are driving change by working alongside challenger banks, fintechs, brokers, and merchants to foster a dynamic and competitive financial ecosystem.

Our culture is built on four core behaviours: Grit to Grow, Connect to Collaborate, Putting Clients First, and Owning the Outcome. We believe people do not simply choose a company to work for—they choose a company that makes a positive impact in the lives of Canadians. Above all, we value people, build meaningful relationships, focus on individual strengths, and approach our work with passion.

About the work environment

Peoples Group offers a flexible and hybrid work environment. In this role you will work a combination of in-office and remotely from home. Typically, you'll be working regular business hours, Monday to Friday between 8:00am and 4:30pm with flexibility around start/end times.

We offer:

  •  A hybrid work environment, enabling you to balance your personal and professional life seamlessly.
  • Competitive salaries, profit sharing, RRSP matching and benefits from day one.
  • Generous paid time off to help achieve a healthy work-life balance.
  • A strengths-based approach, ensuring we work together more effectively.
  • A commitment to your well-being in five key areas: Financial, Physical, Social, Career, and Community.

Peoples Group is pleased to offer employees a competitive annual salary plus a discretionary profit share opportunity. Salary for this position will vary between $130,000 and $145,000 per year depending on the knowledge, skills, abilities and experience that the chosen candidate possesses.

NOTE:  This job posting is for an existing vacancy. Peoples Group is an Equal Employment Opportunity employer. Please accept our utmost appreciation for your interest; however, only those applicants under consideration will be contacted.

 We value and celebrate individuality while fostering an inclusive workplace for everyone. If there's any way we can support or accommodate you during the selection process, please don't hesitate to let us know.