1

Third Party Risk Analyst Jobs in Quebec (NOW HIRING)

The Analyst independently leads risk assessments and partners closely with IT, OT, audit, andsenior ... Perform cybersecurity risk assessments across IT, OT, cloud, and third-party environments ...

The Analyst independently leads risk assessments and partners closely with IT, OT, audit, andsenior ... Perform cybersecurity risk assessments across IT, OT, cloud, and third-party environments ...

The Analyst independently leads risk assessments and partners closely with IT, OT, audit, andsenior ... Perform cybersecurity risk assessments across IT, OT, cloud, and third-party environments ...

The Analyst independently leads risk assessments and partners closely with IT, OT, audit, andsenior ... Perform cybersecurity risk assessments across IT, OT, cloud, and third-party environments ...

... third party risk, business continuity and key indicators. * Coordinate with other GWAM Risk teams on reporting and analysis on corporate risk programs to support risk governance activities across ...

Analyze portfolio performance and identify the primary drivers behind returns and risk. * Evaluate market fundamentals, system conditions, and portfolio exposures to assess trading risk and portfolio ...

Credit knowledge & Analysis - Knowledge and experience in Credit Analysis and Credit Risk. Expertise of loan/security documentation, compliance, audit and control requirements. Familiarity of ...

Credit knowledge & Analysis - Knowledge and experience in Credit Analysis and Credit Risk. Expertise of loan/security documentation, compliance, audit and control requirements. Familiarity of ...

Ability to apply and challenge risk-based KYC principles, client risk assessment, and products used ... third-party vendor selected by the Financial Industry Regulatory Authority ("FINRA"). LANGUAGE:

General Information Press space or enter keys to toggle section visibility Job Location * Montreal, QC Date Published 05-Dec-2025 Department Qualifications & Proposals Employment Type Permanent ...

Analyze various elements of credit risk during due diligence process primarily related to renewable energy transactions for new and existing counterparties; * Update and maintain information in the ...

Analyze various elements of credit risk during due diligence process primarily related to renewable energy transactions for new and existing counterparties; * Update and maintain information in the ...

We are looking for an Analyst - Risk Management and Insurance who will report to the Senior Analyst - Risk Management, and who'll be tasked with analyzing business risks and supporting the ...

next page

Showing results 1-20

Third Party Risk Analyst information

See Quebec salary details

$10

$45

$71

How much do third party risk analyst jobs pay per hour?

As of Aug 1, 2026, the average hourly pay for third party risk analyst in Quebec is $45.52, according to ZipRecruiter salary data. Most workers in this role earn between $35.82 and $53.61 per hour, depending on experience, location, and employer.

How does a Third Party Risk Analyst typically collaborate with other departments to manage vendor risks?

A Third Party Risk Analyst works closely with departments such as procurement, legal, IT security, and compliance to assess and mitigate potential risks posed by vendors and service providers. Collaboration often involves reviewing contracts, conducting risk assessments, and ensuring vendors meet the organization's security and compliance requirements. Regular communication and joint meetings are common to align on risk standards and address any emerging concerns. This cross-functional teamwork ensures a comprehensive approach to managing third-party risks and maintaining regulatory compliance.

What is the difference between Third Party Risk Analyst vs Vendor Risk Analyst?

AspectThird Party Risk AnalystVendor Risk Analyst
CertificationsCertifications like CRISC, CISA often preferredSimilar certifications, often the same as Third Party Risk Analyst
Work EnvironmentFinancial institutions, corporations managing third-party relationshipsOrganizations assessing vendor security, compliance, and performance
Industry UsageCommon in finance, healthcare, and tech sectorsPrimarily in procurement, supply chain, and IT sectors

The main difference is that a Third Party Risk Analyst focuses on assessing risks associated with all third-party relationships, including vendors, partners, and service providers. A Vendor Risk Analyst specifically concentrates on evaluating risks posed by vendors and suppliers. While their roles overlap, the Third Party Risk Analyst has a broader scope, often handling multiple types of third-party relationships within various industries.

Is a grc analyst a good entry-level job?

A third-party risk analyst is often considered an entry-level role in risk management and compliance, suitable for individuals with strong analytical skills and knowledge of regulations like GDPR or HIPAA. The position typically involves assessing vendor risks, using tools like GRC software, and may require certifications such as CRISC or CISA. It provides a foundation for career growth in cybersecurity, compliance, or risk management fields.

How much does a third-party risk analyst make?

A third-party risk analyst typically earns between $60,000 and $100,000 annually, depending on experience, location, and industry. Entry-level positions may start lower, while experienced analysts with certifications like CRISC or CISSP can earn higher salaries.

Is third-party risk management a good career?

Third-party risk management is a growing field within risk analysis and compliance, focusing on assessing and mitigating risks from external vendors and partners. It requires skills in risk assessment, regulatory knowledge, and often involves using tools like risk management software. The role offers opportunities for career advancement in industries such as finance, healthcare, and technology.

What does a third-party risk analyst do?

A third-party risk analyst evaluates the risks associated with an organization’s external vendors, suppliers, and partners. They assess third-party security, compliance, and operational risks using tools like risk management software and often require knowledge of industry standards and certifications. Their goal is to ensure that external relationships do not compromise the organization’s security or compliance posture.

What are the key skills and qualifications needed to thrive as a Third Party Risk Analyst, and why are they important?

To thrive as a Third Party Risk Analyst, you need a solid understanding of risk management principles, vendor assessment processes, and compliance regulations, often supported by a degree in business, finance, or information security. Familiarity with risk assessment tools, GRC (Governance, Risk, and Compliance) platforms, and certifications like CTPRA or CRISC is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills set exceptional analysts apart in this field. These competencies are crucial for identifying and mitigating vendor risks, ensuring organizational compliance, and safeguarding sensitive data.
What are popular job titles related to Third Party Risk Analyst jobs in Quebec? For Third Party Risk Analyst jobs in Quebec, the most frequently searched job titles are:
What job categories do people searching Third Party Risk Analyst jobs in Quebec look for? The top searched job categories for Third Party Risk Analyst jobs in Quebec are:
Infographic showing various Third Party Risk Analyst job openings in Quebec as of July 2026, with employment types broken down into 89% Full Time, 7% Part Time, 1% Temporary, and 3% Contract. Highlights an 82% Physical, 7% Hybrid, and 11% Remote job distribution, with an average salary of $94,683 per year, or $45.5 per hour.

Cyber Security Risk Analyst

Alcoa

Deschambault, QC • On-site

Full-time

Retirement, PTO

Re-posted 7 days ago


Alcoa rating

8.0

Company rating: 8.0 out of 10

Based on 16 frontline employees who took The Breakroom Quiz


Job description

Shape Your World

At Alcoa, you will become an essential part of our purpose: to turn raw potential into real progress. The way we see it, every Alcoan is a work-shaper, team-shaper, idea-shaper & world-shaper.

Alcoa is seeking a Cyber Security Risk Analyst to serve as a key contributor to the cybersecurity risk management program, providing subject matter expertise in identifying, assessing, and managing risks across both Information Technology (IT) and Operational Technology (OT) environments.This role supports informed business decision-making by translating complex technicalrisksinto business and operational impact.The Analyst independently leads risk assessments and partners closely with IT, OT, audit, andsenior leadersto ensure cybersecurity risks are understood, documented, mitigated, and monitored in accordance with corporate policies and industry standards.

As Alcoa's Cybersecurity Risk Management program continues to mature, the Analyst plays a critical role in shaping and enhancing program capabilities.

About the Role:

  • Contribute to the development, implementation, and continuous improvement of the Cybersecurity Risk Management Program, including frameworks, methodologies, policies, standards, and supporting tools.

  • Perform cybersecurity risk assessments across IT, OT, cloud, and third-party environments, including enterprise systems and manufacturing/process control systems (PCS).

  • Facilitate risk workshops with technical and business stakeholders to evaluate risks associated with new technologies, projects, and operational changes.

  • Serve as a subject matter expert on risk methodology, scoring, and evaluation.

  • Maintain and enhance the cybersecurity risk register, including risk scoring, treatment plans, and residual risk tracking.

  • Support and guide risk treatment strategies (mitigation, acceptance, transfer, avoidance) and partner with compliance teams to design and implement appropriate controls.

  • Translate technical risk findings into clear business and operational impact statements for non-technical audiences and senior leadership.

  • Advise leadership on risk exposure, trends, and residual risks, including impacts to business operations and production.

  • Define, monitor, and report Key Risk Indicators (KRIs) and emerging threat trends.

  • Support audit, regulatory, and compliance activities (e.g., ISO 27001, NIST, SOC) related to cybersecurity risk management.

  • Collaborate with Enterprise Risk Management (ERM) and Operations Risk Management teams to ensure alignment and integration of cybersecurity risks into broader risk reporting.

  • Build and maintain strong relationships with stakeholders across IT, OT, business units, and risk management functions.

  • Continuously monitor evolving cyber threats, emerging technologies, and industry practices to enhance risk management processes and capabilities.

What you can bring to this role:

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, Risk Management, or a related discipline; equivalent professional experience may be considered in lieu of a degree.

  • 6+ years of experience in cybersecurity, IT risk management, information security, governance, compliance, or IT operations within enterprise environments.

  • Demonstrated experience assessing cybersecurity risk across IT and OT environments; experience in manufacturing or industrial organizations preferred.

  • Strong knowledge of cybersecurity frameworks and standards (e.g., ISO 27001, NIST CSF, NIST 800-53, CIS Controls, SOX).

  • Proven experience executing core GRC activities, including risk assessments, policy and standard development, control validation, audit support, and remediation tracking.

  • Expertise in cybersecurity governance, risk assessment, and compliance program implementation.

  • Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards.

  • Solid understanding of security principles, including security controls, threat modeling, vulnerability management, and incident risk analysis.

  • Excellent written, verbal, and facilitation skills, with the ability to translate complex technical risks into clear business impacts.

  • Demonstrated ability to collaborate effectively with cross-functional stakeholders, including technical teams, operations, and senior leadership, while managing multiple priorities in fast-paced environments.

PreferredQualifications

  • Relevant industry certifications such as CISSP, CISM, CRISC, CISA, CGRC, Security+, GRCP, or equivalent.

  • Experience withthird-party/vendor risk management, regulatory compliance assessments, and security awareness programs.

  • Experience supporting global environments and contributing to enterprise-wide security or compliance initiatives.

  • Experience supporting audits and assurance activities, including ISO/IEC 27001 certification and SOC report reviews.

  • Familiarity with security operations capabilities, including SIEM, log analysis, and event monitoring for compliance and incident response.

  • Understanding of enterprise security domains, including cloud security, infrastructure security, and identity and access management (IAM).

  • Working knowledge of project management methodologies and practices.

  • Experience in metals, mining, manufacturing, or other heavy industrial environments.

What we offer:

  • Competitive compensation packages, including pay-for performance variable pay, recognition and rewards programs, and stock-based compensation awards (3-year vesting schedule)

  • Flexible spending accounts and generous employer contribution to the HSA

  • 401(k), employer match up to 6%, additional employer retirement income contribution (no vesting period), and a non-qualified deferred compensation plan

  • 12 paid holidays per year.

  • 15 days of paid vacation (pro-rated from hire date).

  • Employee Assistance Program (EAP)

#LI-TL2

Employees must be legally authorized to work in the United States. Verification of employment eligibility will be required at the time of hire. Visa sponsorship is not available for this position.

About the Location

Alcoa is an international company with multiple locations and joint ventures across six continents. Wherever you choose to join us, you'll be joining a global team committed to advancing sustainability and delivering excellence and innovation. As industry pioneers, we are redefining what it means to be a sustainable aluminum company, bridging the journey from mines to metal.

We are values led, vision driven and united by our purpose of transforming raw potential into real progress. Our commitments to Inclusion, Diversity & Equity include providing trusting workplaces that are safe, respectful and inclusive of all individuals, free from discrimination, bullying and harassment and that our workplaces reflect the diversity of the communities in which we operate.

As a proud equal opportunity workplace and affirmative action employer, Alcoa is dedicated to providing equal opportunities and equal access to all individuals regardless of a person's gender, age, race, ethnicity, sexual orientation, gender identity, religion, nation of origin, disability, veteran status, language spoken or any other characteristic or status protected by the laws or regulations in the places where we operate.

If you have visited our website in search of information on U.S. employment opportunities or to apply for a position, and you require an accommodation, please contact Alcoa Recruiting via email at gssrecruiting@alcoa.com.

This is a place where you are empowered to do your best work, be your authentic self, and feel a true sense of belonging. Come join us and shape your career!

Your work. Your world. Shape them for the better.


What Alcoa employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Alcoa logo

About Alcoa

Sourced by ZipRecruiter

Alcoa is a global industry leader in the production of bauxite, alumina and aluminum, a position enhanced by a portfolio of value-added cast products and select energy assets. Since developing the aluminum industry more than 135 years ago, Alcoa has built a legacy of breakthrough innovations and best practices that have led to efficiency, safety, sustainability and stronger communities wherever we operate.

Industry

Manufacturing

Company size

10,000+ Employees

Headquarters location

Pittsburgh, PA, US

Year founded

1888

Social media