About the Role
Support critical third-party risk and vendor governance activities in an insurance environment, gaining exposure to compliance, audit, supplier monitoring, and emerging risk initiatives. This hybrid role involves collaboration with cross-functional teams and offers a flexible work model with on-site days in Toronto.
Responsibilities
- Conduct inherent risk assessments to evaluate third-party risk based on service criticality, data sensitivity, and regulatory impact.
- Perform financial due diligence, including analysis of supplier financial health and credit ratings.
- Conduct adverse and negative media reviews to identify reputational, legal, or operational risks.
- Assess supplier risk posture and identify areas requiring additional due diligence or mitigation.
- Support contract owners and business stakeholders through training and guidance on third-party risk management practices.
- Support ongoing supplier monitoring and governance activities across the vendor lifecycle.
- Conduct ongoing monitoring activities to ensure suppliers maintain effective control environments.
- Support governance activities, including periodic supplier reviews and documentation of risk posture.
- Track and manage issues, risk findings, and policy exceptions while ensuring timely resolution.
- Monitor supplier risk indicators, including financial performance, adverse media, and emerging global risks.
- Ensure adherence to internal third-party risk management policies and standards.
- Support regulatory compliance activities, including alignment with OSFI B-10 or equivalent guidelines.
- Assist with internal and external audits, including documentation and remediation tracking.
- Maintain accurate and complete risk assessment documentation and audit trails.
- Partner with business units, procurement teams, and risk functions to support vendor oversight activities.
- Communicate risk assessment outcomes and recommendations clearly to stakeholders.
- Contribute to the enhancement of third-party risk management processes, tools, frameworks, dashboards, and metrics.
- Stay informed on emerging risks, regulatory changes, and industry best practices.
Requirements
- Degree in a related field or equivalent combination of education and experience.
- 2–5 years of experience in Third-Party Risk Management, Vendor Risk, Compliance, Audit, or Operational Risk.
- Experience conducting inherent risk assessments and due diligence activities.
- Experience performing financial reviews and adverse media reviews.
- Strong understanding of the vendor risk lifecycle, including onboarding, monitoring, and governance activities.
- Knowledge of risk-based assessment methodologies.
- Familiarity with regulatory guidelines such as OSFI B-10 is considered an asset.
- Experience reviewing SOC reports, ISO certifications, or equivalent control documentation is preferred.
- Experience using TPRM tools or platforms such such as Archer, Ivalua, or ProcessUnity is considered an asset.
- Understanding of cybersecurity and information security risk concepts.
- Exposure to emerging technology risks such as AI, cloud, and global risk landscape considerations.
Skills
- Analytical skills
- Audit skills
- Compliance skills
- Risk assessment skills
- Stakeholder communication
- Relationship management
- Attention to detail
- Ability to assess control environments
- Training skills
- Facilitation skills
- Cybersecurity and information security risk concepts
- Emerging technology risks (AI, cloud, global risk landscape)
- Risk-based assessment methodologies
- Regulatory guidelines (OSFI B-10)
- Reviewing SOC reports, ISO certifications, or equivalent control documentation
- Using TPRM tools or platforms (Archer, Ivalua, ProcessUnity)
Location
- Toronto
- Hybrid
Work Type
- 6-month contract
- Potential for permanent employment
- Full-time
- 37.50 hours per week
- Hybrid
Experience Level
- 2–5 years of experience
Education Level
- Degree in a related field or equivalent combination of education and experience
Salary/Compensations
- Salaried: $40-46 per hour
- Incorporated Business Rate: $46-53 per hour
About the Company
- Recruit Action (agency permit: AP-2504511) provides recruitment services through quality support and a personalized approach.
- As part of the screening process, some applications may be reviewed using artificial intelligence tools.
- Only candidates who meet the hiring criteria will be contacted.
