1

Third Party Risk Manager Jobs in Ottawa, ON (NOW HIRING)

IT Third party risk management. * Business continuity and disaster recovery * Cloud security * Data governance assessments and reviews * ERP controls and security * Responsible AI and governance

Support governance, regulatory compliance, and risk management practices across collections operations. * Manage relationships with third-party collections partners and support vendor performance and ...

Support governance, regulatory compliance, and risk management practices across collections operations. * Manage relationships with third-party collections partners and support vendor performance and ...

Support governance, regulatory compliance, and risk management practices across collections operations. * Manage relationships with third-party collections partners and support vendor performance and ...

Support governance, regulatory compliance, and risk management practices across collections operations. * Manage relationships with third-party collections partners and support vendor performance and ...

Support governance, regulatory compliance, and risk management practices across collections operations. * Manage relationships with third-party collections partners and support vendor performance and ...

Support governance, regulatory compliance, and risk management practices across collections operations. * Manage relationships with third-party collections partners and support vendor performance and ...

Support governance, regulatory compliance, and risk management practices across collections operations. * Manage relationships with third-party collections partners and support vendor performance and ...

next page

Showing results 1-20

Third Party Risk Manager information

See Ottawa, ON salary details

$57.6K

$115.8K

$151.9K

How much do third party risk manager jobs pay per year?

As of Sep 7, 2026, the average yearly pay for third party risk manager in Ottawa, ON is $115,839.00, according to ZipRecruiter salary data. Most workers in this role earn between $79,067.00 and $145,274.00 per year, depending on experience, location, and employer.

What is a third party risk manager?

A Third Party Risk Manager is a professional responsible for identifying, assessing, and mitigating risks associated with an organization's external vendors, suppliers, or partners. Their main job is to ensure that third-party relationships do not expose the company to undue financial, operational, regulatory, or reputational risk. This includes evaluating vendor security practices, monitoring compliance with contracts and regulations, and developing risk management policies. Third Party Risk Managers often collaborate with legal, procurement, and IT teams to safeguard the organization's interests. Their work is crucial in today's interconnected business environment, where companies increasingly rely on third-party services and products.

What are the key skills and qualifications needed to thrive as a third party risk manager?

To thrive as a Third Party Risk Manager, you need a strong background in risk assessment, vendor management, and regulatory compliance, often supported by a degree in business, finance, or a related field. Familiarity with risk management frameworks, tools like GRC (Governance, Risk, and Compliance) platforms, and relevant certifications such as CTPRP (Certified Third Party Risk Professional) are highly beneficial. Excellent communication, analytical thinking, and stakeholder management skills set top performers apart in this role. These competencies are crucial for effectively identifying, mitigating, and communicating third-party risks to protect organizational assets and ensure regulatory compliance.

How does a third party risk manager typically collaborate with other departments to manage vendor risks?

A Third Party Risk Manager works closely with teams such as procurement, legal, IT security, and compliance to assess and monitor the risks associated with external vendors. They coordinate with these departments to perform due diligence, review contracts, and establish ongoing monitoring processes. Regular cross-functional meetings and clear communication channels are essential, as the role often requires aligning risk management strategies with organizational objectives and ensuring that vendor-related risks are identified and mitigated promptly.

What is the difference between Third Party Risk Manager vs Vendor Risk Analyst?

AspectThird Party Risk ManagerVendor Risk Analyst
CredentialsCertifications like CRISC, CTPRP often preferredCertifications such as CRISC, CTPRP common
Work EnvironmentOversees multiple vendors and third-party relationships at strategic levelFocuses on assessing specific vendor risks and compliance
Employer & Industry UsageUsed in finance, healthcare, and large corporations managing third-party risksCommon in IT, finance, and procurement departments
Search & Comparison IntentOften compared for broader risk management rolesCompared for detailed vendor risk assessments

The Third Party Risk Manager oversees the overall risk associated with third-party vendors, focusing on strategic risk mitigation. The Vendor Risk Analyst concentrates on evaluating individual vendors' risks and compliance. While both roles require similar certifications and work in related environments, the Risk Manager has a broader scope, whereas the Analyst specializes in detailed assessments.

Is third party risk manager a good career?

A third party risk manager plays a key role in assessing and mitigating risks associated with external vendors and partners, often requiring knowledge of compliance standards and risk management tools. The role offers opportunities for advancement in industries such as finance, healthcare, and technology, with a growing demand for professionals skilled in risk assessment and regulatory requirements. It can be a stable and rewarding career for those with strong analytical skills and attention to detail.

What cities near Ottawa, ON are hiring for Third Party Risk Manager jobs?

Cities near Ottawa, ON with the most Third Party Risk Manager job openings:

Infographic showing various Third Party Risk Manager job openings in Ottawa, ON as of August 2026, with employment types broken down into 86% Full Time, 13% Part Time, and 1% Contract. Highlights an 82% Physical, 3% Hybrid, and 15% Remote job distribution, with an average salary of $115,839 per year, or $55.7 per hour.

Executive Advisor - Governance, Risk & Compliance

Malleum

Ottawa, ON โ€ข Remote

Full-time

Posted 9 days ago


Job description

About MalleumMalleum is at the forefront of next-generation cyber defense, partnering with marquee clients across space, aerospace, defense, government, financial services, and critical infrastructure. We're experiencing exceptional growth as demand accelerates for trusted advisors capable of delivering at the intersection of national security, allied intelligence cooperation, and enterprise resilience. Our advisors shape the governance, risk, and compliance programs that underpin cutting-edge defensive technologies, sovereign space capabilities, and allied programs with national security impact – from satellite and launch operations to next-generation defense platforms.
If you take pride in shaping how the most consequential organizations govern cyber risk and want your counsel to influence sovereign and allied missions, Malleum is where your leadership meets purpose.The OpportunityWe're seeking a very senior governance, risk and compliance specialist to lead our most strategic GRC engagements and to help scale our advisory practice across the space, aerospace, and defense sectors.
In this role you'll serve as a trusted counsel to CISOs, CIOs, CROs, and boards – translating regulatory complexity into pragmatic, mission-aligned programs. This is a remote position, with travel to client sites – typically Ontario-based – as required.
This is a senior leadership role for a recognized GRC practitioner who has stood up enterprise-grade cyber resilience programs, navigated the most demanding compliance regimes, and can mentor the next generation of Malleum advisors.What You'll Do
  • Lead executive-level GRC advisory engagements for clients across space, aerospace, defense, government, and critical infrastructure
  • Stand up and mature Cyber Resilience Programs at large enterprises, integrating governance, risk management, business continuity, third-party risk, and incident readiness into a cohesive operating model
  • Advise C-suite and board stakeholders on cyber risk posture, regulatory exposure, and strategic investment priorities
  • Lead client journeys to CMMC (Cybersecurity Maturity Model Certification) readiness and certification, including scoping, gap assessments, SSP/POAM development, and assessor coordination
  • Lead client adoption of the Canadian Program for Cyber Security Certification (CPCSC) for organizations supporting the Government of Canada defense supply chain
  • Develop, operationalize, and audit programs aligned with NIST CSF 2.0, NIST 800-53/171, ISO 27001/27005, ITSG-33, SOC 2, and sector-specific frameworks
  • Advise space-sector clients on emerging requirements such as Space ISAC guidance, NIST IR 8401 (Satellite Ground Segment), and allied space defense expectations
  • Define and implement enterprise risk management frameworks, KRIs/KPIs, risk appetite statements, and board reporting cadences
  • Lead third-party / supply-chain risk programs aligned with defense industrial base (DIB) and allied requirements
  • Shape Malleum's GRC service offerings, methodologies, accelerators, and intellectual property
  • Mentor and develop senior managers, managers, and consultants — building bench strength and a strong delivery culture
  • Drive business development: trusted-advisor relationships, account growth, proposals, and thought leadership across the space, aerospace, and defense ecosystem
  • Represent Malleum in industry forums, regulator engagements, client briefings, and executive roundtables
What You Bring
  • 15+ years of progressive cybersecurity and GRC experience, including senior leadership roles in consulting, industry, or government
  • Demonstrated track record standing up and scaling Cyber Resilience Programs for large, complex enterprises — including governance structures, risk frameworks, control libraries, metrics, and operating cadences
  • Deep expertise across CMMC (Levels 1–3) and emerging CPCSC requirements, including how each maps to NIST 800-171 / 800-172 and supplier obligations
  • Hands-on experience advising clients in space, aerospace, and defense — familiarity with ITAR, CGP, controlled goods, export controls, and allied compliance regimes
  • Strong command of NIST CSF 2.0, NIST 800-53/171/172, ISO 27001/27005, ITSG-33, SOC 2, PCI DSS, and relevant privacy regimes (PIPEDA, Quebec Law 25, GDPR)
  • Executive presence — proven ability to advise CISOs, CIOs, CFOs, GCs, audit committees, and boards
  • Strong commercial acumen — practice building, account growth, proposal leadership, and revenue accountability
  • Demonstrated leadership in mentoring, coaching, and developing high-performing GRC teams
  • Certifications such as CISSP, CISM, CRISC, CGEIT, CISA, ISO 27001 Lead Auditor/Implementer, or CMMC Registered Practitioner (RP) strongly preferred
  • Eligibility for Government of Canada security clearance (Secret or higher); existing clearance highly valued
  • French fluency is an asset
  • Bachelor's degree required; advanced degree (MBA, MS in Cybersecurity) preferred
 Why Malleum
  • Lead GRC programs with genuine national and allied security impact across space, aerospace, and defense
  • Shape the strategy and growth of a rapidly scaling advisory practice with direct partner-level visibility
  • Work alongside seasoned IR, offensive security, engineering, and program leaders on the most consequential client missions
  • Highly competitive executive compensation, performance incentives, and equity-style participation in practice growth
  • Continuous learning budget, certification sponsorship, and a platform to publish, speak, and shape industry dialogue
  • A flat, high-trust culture that rewards judgment, ownership, and mission focus

Malleum is an equal opportunity employer. We welcome applications from all qualified candidates and are committed to building a team that reflects the communities and missions we serve.
We are committed to providing accommodations for individuals with disabilities throughout the recruitment process. Please let us know if you require accommodation at any stage.
 

Powered by JazzHR

Gm1VJfwdua