... risk management framework * Maintain cybersecurity, technology, and data risk registers * Conduct cyber risk assessments across business processes, systems, vendors, and strategic initiatives
... risk management framework * Maintain cybersecurity, technology, and data risk registers * Conduct cyber risk assessments across business processes, systems, vendors, and strategic initiatives
Assess and manage third-party and vendor security risk including vendor assessments and ongoing monitoring. * Collaborate with and advise internal departments to improve security-related risks and ...
Assess and manage third-party and vendor security risk including vendor assessments and ongoing monitoring. * Collaborate with and advise internal departments to improve security-related risks and ...
Global Risk Analytics (GRA) is the center of expertise for models used in risk management, covering ... Collaborate with vendors including external data providers to integrate and validate their outputs ...
Global Risk Analytics (GRA) is the center of expertise for models used in risk management, covering ... Collaborate with vendors including external data providers to integrate and validate their outputs ...
Perform vendor risk assessments and enhanced the Third-Party Risk Management (TPRM) program by Gathering and preparing data for reporting security service performance metrics that includes status of ...
Quick apply
Perform vendor risk assessments and enhanced the Third-Party Risk Management (TPRM) program by Gathering and preparing data for reporting security service performance metrics that includes status of ...
... risk management * Risk Knowledge: Deep knowledge of supplier risk assessment frameworks, risk taxonomy, and vendor due diligence methodologies * Business Partnering: Demonstrated ability to build ...
... risk management * Risk Knowledge: Deep knowledge of supplier risk assessment frameworks, risk taxonomy, and vendor due diligence methodologies * Business Partnering: Demonstrated ability to build ...
Risk Management * Conduct risk assessments of IT infrastructure, applications, third parties, and ... Support vendor risk assessments, including reviewing response to questionnaire GRC Tools * Maintain ...
Risk Management * Conduct risk assessments of IT infrastructure, applications, third parties, and ... Support vendor risk assessments, including reviewing response to questionnaire GRC Tools * Maintain ...
Security GRC Specialist
Toronto, ON · On-site
Risk Management * Conduct risk assessments of IT infrastructure, applications, third parties, and ... Support vendor risk assessments, including reviewing response to questionnaire GRC Tools ·
Quick apply
Security GRC Specialist
Toronto, ON · On-site
Risk Management * Conduct risk assessments of IT infrastructure, applications, third parties, and ... Support vendor risk assessments, including reviewing response to questionnaire GRC Tools ·
Direct experience in vendor management or third-party risk management is required; broader general risk management experience may be considered. Experience overseeing complex third-party portfolios ...
Direct experience in vendor management or third-party risk management is required; broader general risk management experience may be considered. Experience overseeing complex third-party portfolios ...
VP & General Counsel
Toronto, ON · On-site
Lead review, drafting, and negotiation of key commercial agreements, including vendor contracts ... Risk Management & Process Development: Build practical legal processes, templates, playbooks ...
VP & General Counsel
Toronto, ON · On-site
Lead review, drafting, and negotiation of key commercial agreements, including vendor contracts ... Risk Management & Process Development: Build practical legal processes, templates, playbooks ...
VP & General Counsel
Toronto, ON · On-site
Lead review, drafting, and negotiation of key commercial agreements, including vendor contracts ... Risk Management & Process Development: Build practical legal processes, templates, playbooks ...
Quick apply
VP & General Counsel
Toronto, ON · On-site
Lead review, drafting, and negotiation of key commercial agreements, including vendor contracts ... Risk Management & Process Development: Build practical legal processes, templates, playbooks ...
Information Systems Security Manager
Waterloo, ON · On-site
CA$120K - CA$150K/yr
Overseeing the deployment of security technologies, including encryption tools, antivirus software, and access controls Vendor Risk Management: * Assessing the security protocols of third-party ...
Information Systems Security Manager
Waterloo, ON · On-site
CA$120K - CA$150K/yr
Overseeing the deployment of security technologies, including encryption tools, antivirus software, and access controls Vendor Risk Management: * Assessing the security protocols of third-party ...
The Director will also be responsible for managing a portion of the ORC project portfolio, which ... Demonstrated ability to lead large, high-visibility initiatives involving third-party vendors and ...
The Director will also be responsible for managing a portion of the ORC project portfolio, which ... Demonstrated ability to lead large, high-visibility initiatives involving third-party vendors and ...
Supports an efficient and effective risk management function which uses common information sources ... and external vendors (e.g. lending system, payment system, external credit rating system) to ...
Supports an efficient and effective risk management function which uses common information sources ... and external vendors (e.g. lending system, payment system, external credit rating system) to ...
Head of Risk
Toronto, ON · On-site
$125 - $150/hr
Manage day‑to‑day relationships with our risk vendors and ensure we extract full value from each. Team & Regulatory Leadership * Lead, coach, and develop the risk operations team, raising the ...
Head of Risk
Toronto, ON · On-site
$125 - $150/hr
Manage day‑to‑day relationships with our risk vendors and ensure we extract full value from each. Team & Regulatory Leadership * Lead, coach, and develop the risk operations team, raising the ...
Senior/Lead Risk Analyst, Payment fraud
Toronto, ON · On-site
$150K - $200K/yr
... manage vendor relationships, and ensure effective alignment on fraud and risk management ... Qualifications * The ideal candidate is an accountable and resilient team-player who brings a ...
Senior/Lead Risk Analyst, Payment fraud
Toronto, ON · On-site
$150K - $200K/yr
... manage vendor relationships, and ensure effective alignment on fraud and risk management ... Qualifications * The ideal candidate is an accountable and resilient team-player who brings a ...
Senior Analyst, Card Forecasting, Inventory & Vendor Management
CA$56K - CA$103K/yr
Oversee and manage inventory for card plastics, chip modules, chip milling/embedding, and ... Maintain vendor documentation, risk registers, issue logs, audit evidence, control records ...
Senior Analyst, Card Forecasting, Inventory & Vendor Management
CA$56K - CA$103K/yr
Oversee and manage inventory for card plastics, chip modules, chip milling/embedding, and ... Maintain vendor documentation, risk registers, issue logs, audit evidence, control records ...
... Risk Management, Standard Operating Procedure (SOP), Supervision, Teamwork, Troubleshooting, Vendor Management, Waterfall Model Additional Job Details Address: BAY WELLINGTON TOWER, 181 BAY ST:
... Risk Management, Standard Operating Procedure (SOP), Supervision, Teamwork, Troubleshooting, Vendor Management, Waterfall Model Additional Job Details Address: BAY WELLINGTON TOWER, 181 BAY ST:
Senior Operational Risk Analyst , Business Continuity & Operational Resilience DUCA is looking for ... This role manages all elements of DUCA's Business and Vendor Continuity Planning and Resiliency ...
Quick apply
Senior Operational Risk Analyst , Business Continuity & Operational Resilience DUCA is looking for ... This role manages all elements of DUCA's Business and Vendor Continuity Planning and Resiliency ...
Technology Risk & Compliance Manager, Deloitte Global Audit and Assurance
Toronto, ON · On-site +1
CA$85K - CA$156K/yr
Performing risk assessments, information management reviews, and control evaluations for audit ... Leading coordination across product, technology, vendor, privacy, regulatory, and risk stakeholders ...
Technology Risk & Compliance Manager, Deloitte Global Audit and Assurance
Toronto, ON · On-site +1
CA$85K - CA$156K/yr
Performing risk assessments, information management reviews, and control evaluations for audit ... Leading coordination across product, technology, vendor, privacy, regulatory, and risk stakeholders ...
Senior Operational Risk Analyst , Business Continuity & Operational Resilience DUCA is looking for ... This role manages all elements of DUCA's Business and Vendor Continuity Planning and Resiliency ...
Senior Operational Risk Analyst , Business Continuity & Operational Resilience DUCA is looking for ... This role manages all elements of DUCA's Business and Vendor Continuity Planning and Resiliency ...
Vendor Risk Management information
See Ontario salary details
$13.70 - $20.67
7% of jobs
$20.67 - $27.64
12% of jobs
$30.51 is the 25th percentile. Wages below this are outliers.
$27.64 - $34.62
15% of jobs
The median wage is $40.97 / hr.
$34.62 - $41.59
18% of jobs
$41.59 - $48.56
7% of jobs
$48.56 - $55.53
9% of jobs
$59.49 is the 75th percentile. Wages above this are outliers.
$55.53 - $62.50
12% of jobs
$62.50 - $69.47
8% of jobs
$69.47 - $76.44
4% of jobs
$76.44 - $83.41
4% of jobs
$83.41 - $90.38
3% of jobs
$13
$48
$90
How much do vendor risk management jobs pay per hour?
What is vendor risk management?
A Vendor Risk Management (VRM) job involves assessing, monitoring, and mitigating risks associated with third-party vendors and suppliers. Professionals in this role evaluate vendor security, compliance, and operational risks to protect their organization from potential disruptions, data breaches, or regulatory violations. They work closely with procurement, legal, and IT teams to establish risk management frameworks and ensure vendors meet contractual and security standards. Their responsibilities often include conducting risk assessments, reviewing vendor contracts, and developing risk mitigation strategies. Effective VRM helps organizations reduce exposure to risks while maintaining productive vendor relationships.
What are some common challenges faced in vendor risk management?
Professionals in Vendor Risk Management often encounter the challenge of assessing and monitoring a wide range of vendors, each with unique risk profiles and compliance requirements. Balancing multiple projects, managing deadlines, and ensuring clear communication between internal stakeholders and vendors can also be demanding. Staying updated on evolving regulatory standards and quickly adapting to new risks is essential in this role. Overcoming these challenges requires strong organizational skills, continual learning, and proactive relationship management.
What are the key skills and qualifications needed to thrive in vendor risk management?
To thrive in Vendor Risk Management, you need a solid background in risk assessment, contract analysis, and supply chain management, often supported by a degree in business, finance, or a related field. Familiarity with risk management software, vendor management systems, and relevant certifications such as Certified Third Party Risk Professional (CTPRP) are highly valued. Strong attention to detail, excellent communication, and negotiation skills help build effective vendor relationships and navigate complex scenarios. These capabilities are crucial for ensuring organizational compliance, minimizing third-party risks, and maintaining strong supplier performance.
How to do vendor risk management?
What does a vendor risk management do?
What are popular job titles related to Vendor Risk Management jobs in Ontario?
For Vendor Risk Management jobs in Ontario, the most frequently searched job titles are:
What job categories do people searching Vendor Risk Management jobs in Ontario look for?
The top searched job categories for Vendor Risk Management jobs in Ontario are:

Director, Governance, Risk and Compliance (GRC)
Toronto, ON • Hybrid
Full-time
Medical, Dental
Re-posted 5 days ago
Job description
At Momentum Financial Services Group, we help people move forward by reimagining how money works for those who need it most. With more than 40 years of experience, we're the team behind Money Mart-Canada's largest non-bank branch network-and a leader in financial solutions for underserved communities.
From short-term loans to money transfers and prepaid cards, we power the products, technology, and operations that connect over a million customers a year to the money they need, when they need it.
At MFSG, we come together across teams and departments to create something bigger than ourselves: solutions that remove barriers and give people access to money they might not get anywhere else. Whether you're solving problems, building systems, or shaping strategy, your work fuels real support for real people.
We've Got You CoveredCompensation Philosophy: Our strategy is simple-we aim to match the market. We regularly review industry standards to ensure our total rewards package is competitive and fair. This commitment helps us attract and retain talented individuals who share our purpose.
Discretionary Annual Bonus: Enjoy the opportunity for a discretionary bonus based on individual performance and company success.
Comprehensive Benefits: Our benefits include health and dental plans with 100% of the premiums covered. We also offer an Employee Assistance Program to support your mental well-being and provide resources for personal challenges.
Retirement Plans: Plan for your future with our robust retirement savings options, ensuring you're set for the long haul.
Hybrid Work Environment: Experience the best of both worlds with our hybrid work model, allowing you to balance remote work with in-office. When you're at our corporate head office, enjoy a relaxed and collaborative environment featuring breakout rooms for brainstorming and unwinding, plus a variety of snacks to keep you energized throughout the day.
Perks and Rewards: Enjoy reimbursement for tuition assistance and professional development, discounts through Perkopolis and participate in our rewards and recognition programs to celebrate your contributions.
The Job: Director, Governance, Risk and Compliance (GRC)We're seeking a Director, Governance, Risk and Compliance (GRC) to lead and operate MFSG's cybersecurity governance, cyber risk management, compliance, and data governance functions. This is a highly hands-on senior individual contributor role responsible for strengthening governance frameworks, overseeing cyber risk activities, supporting regulatory compliance, and driving risk-informed decision-making across the organization.
What You'll DoCyber Risk Management & Governance:
- Own and operate the enterprise cyber risk management framework
- Maintain cybersecurity, technology, and data risk registers
- Conduct cyber risk assessments across business processes, systems, vendors, and strategic initiatives
- Define and track key risk indicators (KRIs), metrics, and remediation activities
- Support post-incident risk reviews and continuous improvement efforts
Compliance, Audit & Regulatory Oversight:
- Support internal and external audits, regulatory reviews, and customer due diligence requests
- Validate control effectiveness and coordinate audit evidence collection
- Manage cybersecurity policy governance and exception management processes
- Ensure alignment with industry frameworks including NIST, ISO 27001, privacy regulations, and financial sector requirements
Data Governance & Third-Party Risk Management:
- Partner with data governance, privacy, legal, and compliance teams to manage information risk
- Oversee data governance activities including classification, retention, protection, access governance, and recovery controls
- Support vendor and third-party risk assessments and remediation efforts
Reporting, Stakeholder Engagement & Cross-Functional Influence:
- Prepare executive-level cyber risk reporting and governance updates
- Present risk trends, control gaps, remediation progress, and emerging risks to leadership
- Influence business, technology, and control owners to drive risk reduction activities
- Build strong relationships across cybersecurity, IT, legal, compliance, enterprise risk, and operational teams
Governance Program Development & Operational Leadership:
- Develop and mature cybersecurity governance programs, policies, standards, and procedures
- Improve GRC processes, workflows, and governance effectiveness
- Personally execute critical deliverables in a hands-on leadership capacity
- Balance business objectives with practical, risk-based governance and security controls
- 10+ years of experience in information security, cybersecurity, technology risk, or IT controls
- At least 5 years of direct GRC experience, including 3+ years in a leadership capacity
- Experience within banking, fintech, insurance, payments, wealth management, or another regulated financial services environment
- Proven success operating as a senior individual contributor with ownership of risk assessments, governance documentation, executive reporting, and remediation tracking
- Strong understanding of enterprise cyber risk management, governance, and compliance practices
- Extensive experience with data governance risk management, privacy controls, and information asset protection
- Experience managing cyber risk registers, risk reviews, issue management, and remediation programs
- Strong knowledge of Canadian financial sector regulatory expectations, operational resilience principles, and privacy obligations
- Excellent communication skills with the ability to translate technical issues into clear business risk language
- Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Risk Management, or a related field, or equivalent practical experience
- Experience supporting audits, regulatory reviews, customer security assessments, and control testing activities
- Strong understanding of identity and access management, data protection, cloud security, vulnerability management, incident response, third-party risk, and business continuity
- Experience within a Canadian regulated financial institution or fintech organization
- Professional certifications such as CISSP, CISM, CRISC, CGEIT, or ISO 27001 Lead Implementer/Auditor
- Experience implementing or enhancing GRC platforms, workflow automation, and reporting dashboards
- Familiarity with PCI DSS, SOC 2, cloud control frameworks, and privacy control frameworks
- Experience mapping controls across multiple regulatory and compliance frameworks
Ready to lead cybersecurity governance and influence enterprise risk decisions across a growing organization? Join us and help strengthen the security, resilience, and compliance foundation of MFSG.
Committed to Equal Opportunity:MFSG is committed to accommodating applicants up to the point of undue hardship during the recruitment, assessment and selection process. If you are selected for an interview, please notify MFSG if you require accommodation in respect of the materials or procedures used at any time during this process. If you require accommodation, MFSG will work with you to determine how to meet your needs.
Please note: The salary range for this position is between C$175,000 to C$ 190,000.
About Momentum Financial Services Group
Sourced by ZipRecruiter
Company size
1,001 - 5,000 Employees
Headquarters location
Malvern, PA, US
Year founded
1979