Third Party Security Risk Manager

2 weeks ago


Toronto, Canada EQ Bank | Equitable Bank Full time

**Join a Challenger**

Being a traditional bank just isn’t our thing. We are big believers in innovating the banking experience because we believe Canadians deserve better options, and we challenge ourselves and our teams to creatively transform what’s possible in banking. Our team is made up of inquisitive and agile minds that find smarter ways of doing things. If you’re not afraid of taking on big challenges and redefining the future, you belong with us. You’ll get to work with people who will encourage you to reach new heights. We like to keep things fun, ask questions and learn together.

We are a big (and growing) family. Overall we serve more than 670,000 people across Canada through Equitable Bank, Canada's Challenger Bank, and have been around for more than 50 years. Equitable Bank's wholly-owned subsidiary, Concentra Bank, supports credit unions across Canada that serve more than six million members. Together we have over $125 billion in combined assets under management and administration, with a clear mandate to drive change in Canadian banking to enrich people's lives. Our customers have named our EQ Bank digital platform (eqbank.ca) one of the top banks in Canada on the Forbes World's Best Banks list since 2021.

**Purpose of Job**

The Third-Party Security Risk manager will work closely with the technology teams and line of business teams to mitigate the risk of security attacks emanating from partners, vendors and other related third-parties while enabling the business to grow the bank and serve our customers efficiently and securely.

**Main Activities**:

- Perform Third-Party security risk assessments.
- Monitor and report on third-party security risk action plans, engaging with third-party contacts as well as business stakeholders.
- Maintain third-party security risk management framework ensuring alignment with Risk management framework (2nd Line of defense) and Privacy requirements
- Provide security input to third-party contracts by ensuring alignment with cyber security regulatory requirements and Company cyber security policies
- Identify supplier related cyber risk threat scenarios and evaluate risk rating based on a thorough review of the third party’s security program and technical architecture.
- Monitor third-party compliance program, ensuring continuous compliance and evidence collection, validation, and recording.

**Knowledge/Skill Requirements**:

- A college diploma or university degree is required. Higher accreditation (e.g. Bachelor of Computer Science) is preferred.
- At least five (5) years of information security and information risk experience.
- At least three (3) years of third-party risk management experience (including hands-on experience conducting third party risk assessments)
- Understanding of Cloud Shared responsibility models and risk mitigation approach/techniques.
- Experience in performing organization-wide/entity security risk assessments or audits is required.
- Understanding and experience with security compliance frameworks such as PCI DSS, BSIMM, Cloud Security Alliance, NIST, ISO 27K series is required.
- Understanding of Canadian Financial industry regulations relevant to third-party security and privacy expectations E.g. OSFI, OPC
- The following certifications are preferred: CCSP, CCSK, CISM, CISSP, CISA, or CRISC.
- Experience working in a banking or financial services environment is an asset.

**Accountability**
- The incumbent works under direct management of the Senior Manager, Information Security Risk Management. They will be expected to lead and provide guidance to others in the department.
- The incumbent is accountable for formulating, developing and drafting security policies, procedures, and other relevant documents while liaising with the concerned stakeholders to ensure that the Information Security concerns are amicably addressed and their buy-in is obtained. Hence paving the way for easy acceptance at the time of implementation.
- The incumbent is accountable for the managing of security risk throughout the lifecycle, right from identifying the security risk to explaining it to the relevant stakeholders and getting their buy-in in remediating to tracking the closure of the weaknesses/risks to the organization.
- The incumbent is accountable for ensuring the completeness and accuracy of the periodic compliance reports submitted by the IT functions. Failure to it may result in the IT organization being non-compliant with external and internal regulators.
- The incumbent is also responsible for performing penetration testing as per the agreed upon plan by the Senior Manager, IT Security & Compliance and, compiling the report and working with the concerned stakeholder for getting the weaknesses remediated/fixed or risk accepted. Similarly, the incumbent will maintain register for penetration testing results and vulnerabilities and liaise with action owners for fixing the gaps.
- The incumbent is also responsible for administering and m



  • Toronto, Canada CIBC Full time

    We’re building a relationship-oriented bank for the modern world. We need talented, passionate professionals who are dedicated to doing what’s right for our clients. At CIBC, we embrace your strengths and your ambitions, so you are empowered at work. Our team members have what they need to make a meaningful impact and are truly valued for who they are...


  • Toronto, Canada Manulife Full time

    As Manulife increases reliance on third-parties for products and services, the more exposed the company is to greater risk relating to the delivery, disruption, and risks of the products and services they provide. It is crucial for us to understand the risk factors we have with third-parties and identify any systemic weaknesses with our internal third-party...


  • Toronto, Canada Scotiabank Full time

    Requisition ID: 176393 Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture. **Purpose of Job**: **Responsibilities**: - Champions a customer focused culture to deliver best in class service and support for the TPRM program global stakeholders. Delivers support and assistance to Global contract owners and key...


  • Toronto, Canada Scotiabank Full time

    Manager, Third Party Risk Management Requisition ID: 239137 Join a purpose-driven, high-performing team that is committed to results in an inclusive culture. The Manager, Global Third Party Risk Management contributes to the overall success of the Global Third Party Risk Management Program across all markets. The incumbent ensures risk assessments are...


  • Toronto, Canada Scotiabank Full time

    Manager, Third Party Risk Management Requisition ID: 239137 Join a purpose-driven, high-performing team that is committed to results in an inclusive culture. The Manager, Global Third Party Risk Management contributes to the overall success of the Global Third Party Risk Management Program across all markets. The incumbent ensures risk assessments are...


  • Toronto, Canada Scotiabank Full time

    Manager, Third Party Risk Management Requisition ID: Join a purpose-driven, high-performing team that is committed to results in an inclusive culture. The Manager, Global Third Party Risk Management contributes to the overall success of the Global Third Party Risk Management Program across all markets. The incumbent ensures risk assessments are accurate,...


  • Toronto, Canada Affirm Full time

    Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest. Affirm's Enterprise Risk Management (ERM) team is focused on enabling informed risk based decisions by establishing enterprise standards, governance practices and independent risk...


  • Toronto, Ontario, Canada Canada Life Full time $63,500 - $117,400 per year

    Permanent Full TimeWe are looking for a Senior Analyst, to Support our Third-Party Risk 1B function Team.Reporting to the Manager in Third Party Risk, the Senior Analyst plays a crucial role in assessing and managing the risks associated with an organization's external vendors, suppliers, and partners. This role will focus on the Quality, Monitoring, and...


  • Toronto, Canada Scotiabank Full time

    Requisition ID: 239137 Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture. The Manager, Global Third Party Risk Management contributes to the overall success of the Global Third Party Risk Management Program across all markets where the Bank operates. This position is responsible for accurately applying the...


  • Toronto, Canada KPMG Full time

    Overview: At KPMG, you’ll join a team of diverse and dedicated problem solvers, connected by a common cause: turning insight into opportunity for clients and communities around the world. The Opportunity As part of the **Governance Risk and Compliance **(GRCS) practice, **our risk management professionals provide a broad range of risk advisory services...