Talent.com
Third-Party Risk Management (TPRM) Analyst
Third-Party Risk Management (TPRM) AnalystVancity • Vancouver, BC, CA
Third-Party Risk Management (TPRM) Analyst

Third-Party Risk Management (TPRM) Analyst

Vancity • Vancouver, BC, CA
30+ days ago
Job type
  • Full-time
  • Permanent
Job description

Our Story & Purpose :

We’re Vancity, a member-owned credit union built on the principles of inclusion and social justice. Since 1946, our relentless commitment to these values has helped us challenge the status quo and break down barriers. We’ve made bold commitments to become net-zero by 2040 across all mortgages and loans, and we’re actively pursuing strategies in Indigenous banking and financial resilience for our members.

As the largest private sector Living Wage Employer in Canada, we’re proud to be consistently recognized as one of the country’s Top Employers. If you’re ready to join our team of 2,700 diverse individuals, access competitive rewards and benefits, and be part of a greater movement – apply today!

Your Role in Supporting Our Members :

Join our IT Governance, Risk, and Compliance (IT-GRC) team as a Third-Party Risk Management (TPRM) Analyst. In this role, you shall perform TPRM and vendor risk assessments, and will work closely with internal stakeholders and vendors to ensure that security and compliance risks are identified, assessed, and managed effectively in line with internal policies, regulatory requirements, and industry best practices.

This is a Full-time, Permanent role based at Vancity head office. This role will enjoy hybrid working arrangements which can be fulfilled primarily from the Vancity head office location and your Lower Mainland based home office. Periodically, you’ll be required to attend in-person activities or events. This role reports to the Senior Manager of IT GRC.

How You’ll Make an Impact :

  • Conducting third-party risk assessments to evaluate vendor security and compliance controls by reviewing vendor documentation, engaging with internal stakeholders to understand business requirements, and identifying security and compliance gaps
  • Reviewing vendor security documentation, including SOC reports, web application penetration test results, and security risk assessments
  • Reviewing and providing opinion on vendor provided SoWs, contracts, and MSAs
  • Maintaining and improving third-party risk management processes, tools, and workflows to streamline risk assessments, audit procedures, and reporting
  • Working with procurement, vendor management, legal, and other business teams to perform due diligence on new vendors and ensure security and compliance requirements are met before onboarding
  • Evaluating third-party security incidents or breaches, or vulnerabilities, and coordinating investigation efforts with internal teams and vendors
  • Performing other tasks and responsibilities as assigned

What You’ll Bring to the Team :

  • Bachelor’s in Information Technology, Risk Management, Business, or a related field
  • 2–5 years of related experience in IT Governance, Risk, and Compliance (GRC), Third-Party Risk Management, or Information Security
  • A solid understanding of relevant cyber security standards and frameworks such as NIST, ISO 27001, AICPA SOC reports, PCI-DSS, OSFI, PIPEDA
  • Prior working knowledge in reviewing SOC1, SOC2, PCI (AoC), and ISO 27001 reports and attestations
  • Experience reviewing vendor security controls, evaluating compliance artifacts, and analyzing security risks
  • Strong attention to detail and analytical thinking to identify vendor security risks and assist in remediation tracking
  • Excellent communication and stakeholder management skills to engage with vendors and internal teams
  • A proactive mindset with the ability to work independently and manage multiple priorities in a fast-paced environment
  • Extra Skills That Set You Apart :

  • Experience in IT, Audit, Risk Management, Information Security, or a combination of these
  • Information Security related certifications and training such as CISA, CRISC, and CISM
  • An undergraduate degree (preferably in Cyber Security, Computer Science, Engineering, or highly related field)
  • You’ll Thrive Here If You Are :

  • Detail-Oriented : You have a sharp eye for identifying security gaps and areas of improvement in vendor security practices
  • Analytical : You can balance business needs with risk considerations and provide pragmatic recommendations
  • Proactive & Adaptable : You anticipate challenges and take action to address them before they escalate
  • Collaborative : You work effectively with cross-functional teams, including Procurement, Legal, and IT Security
  • A Clear Communicator : You can translate technical risk concepts into business-friendly language for stakeholders
  • Driven by Continuous Improvement : You are always looking for ways to refine processes and enhance risk management effectiveness
  • We value lived experience, so if you are interested in this role, we encourage you to apply even if you feel your skills don't perfectly align with those listed.

    What You’ll Earn :

    This role offers a salary range of $71,500 to $107,300 per annum . The base pay offered may vary depending on factors such as relevant qualifications, skills, previous experience, and internal equity. As part of our total rewards package, employees may also be eligible for our annual incentive program, subject to program eligibility requirements.

    Why You’ll Love Working Here :

    A career at Vancity is more than just a job, you’re joining a tradition of change-makers who are creating lasting change for our communities. Beyond base pay, we offer a comprehensive total rewards package to ensure our employees are empowered to thrive :

  • Living Wage Employer : We’re the largest private-sector Living Wage Employer in Canada and consistently ranked among Canada’s Top Employers
  • Customizable Benefits : Permanent employees receive flexible benefit packages that can be tailored annually to meet evolving needs
  • Generous Vacation : New employees start with 3–4 weeks of vacation per year, with additional days earned over time
  • Extra Stat Holidays : In addition to BC’s 11 statutory holidays, we offer 2 extra days, plus care days for personal or family illness
  • Immediate Health Coverage : Health and dental benefits begin on your hire date, with three levels of coverage to choose from
  • Defined Benefit Pension : Our retirement plan provides a guaranteed income for life, recognizing that retirement looks different for everyone
  • Vancity Talent Programs :

    Vancity supports an inclusive hiring process for candidates who self-identify as Indigenous, Black, or Trans. With special permission from the BC Human Rights Commissioner, this initiative provides access to career development opportunities, prioritized job screening, and feedback. Any information you choose to share will be stored securely and used only for recruitment and career development connected to this initiative, in line with the BC Personal Information Protection Act (PIPA). For details, please see our dedicated Talent Programs job posting.

    At Vancity we’re committed to creating a welcoming and inclusive workplace to help our people and communities thrive and prosper. Diversity in our workforce is integral so that we can truly represent, understand and respond to our community needs and deliver on our member experience.

    We are also committed to an inclusive, barrier-free and accessible recruitment experience for all candidates.

    Create a job alert for this search

    Risk Analyst • Vancouver, BC, CA

    Similar jobs
    FinTech AML Analyst – On-Site Risk & Compliance

    FinTech AML Analyst – On-Site Risk & Compliance

    VoPay International Inc. • Vancouver
    Full-time
    A FinTech company in Vancouver is looking for an AML Analyst to support compliance efforts.The successful candidate will assist with client onboarding, KYC due diligence, and transaction monitoring...Show more
    Last updated: 9 days ago • Promoted
    Digital Risk and Resilience Analyst Co-op

    Digital Risk and Resilience Analyst Co-op

    Teck Resources • Vancouver
    Full-time +1
    Located in the heart of downtown Vancouver, between the Pacific Ocean and the Coast Mountains, Teck's Corporate Office sits in one of Canada's most culturally diverse cities.Surrounded by world‑ren...Show more
    Last updated: 17 hours ago • Promoted • New!
    Senior PMO Lead, Transformation Risk & Advisory

    Senior PMO Lead, Transformation Risk & Advisory

    PwC - Global • Vancouver
    Full-time
    A leading global consulting firm is seeking a Senior Manager for its Transformation Risk & Advisory practice in Vancouver. The role involves designing governance strategies, leading program manageme...Show more
    Last updated: 1 day ago • Promoted
    AML Compliance Analyst

    AML Compliance Analyst

    Peoples Group • Vancouver
    Full-time
    We are hiring for this position out of our Vancouver office.Successful candidates who apply outside of these areas will be expected to relocate and reside in a location that is within a commutable ...Show more
    Last updated: 13 days ago • Promoted
    Senior Third-Party Security & Risk Analyst

    Senior Third-Party Security & Risk Analyst

    Insight Global • Vancouver
    Full-time
    A leading cybersecurity firm in Canada is seeking an experienced cybersecurity professional to join their Governance Risk & Compliance team. Responsibilities include conducting IT risk assessments, ...Show more
    Last updated: 1 day ago • Promoted
    Threat and Vulnerability Management Analyst

    Threat and Vulnerability Management Analyst

    Raise • Vancouver
    Full-time
    Threat and Vulnerability Management Analyst.Threat and Vulnerability Management Analyst.They’re expanding their team to meet growing needs, making this a unique opportunity to work with an industry...Show more
    Last updated: 13 days ago • Promoted
    Senior Portfolio Compliance Analyst — Elevate Risk & Automation

    Senior Portfolio Compliance Analyst — Elevate Risk & Automation

    Connor, Clark & Lunn Financial Group (CC&L) • Vancouver
    Full-time
    A leading asset management firm in Vancouver is seeking a Senior Portfolio Compliance Analyst to join their Portfolio Compliance Team. The ideal candidate will have over 5 years of experience in Ass...Show more
    Last updated: 13 days ago • Promoted
    Manager, Enterprise Risk Services

    Manager, Enterprise Risk Services

    MNP • Vancouver
    Full-time
    Manager, Enterprise Risk Services.Join to apply for the Manager, Enterprise Risk Services role at MNP.Inspirational, innovative and entrepreneurial - this is how we describe our empowered teams.Com...Show more
    Last updated: 13 days ago • Promoted
    Senior Mid-Market Credit Risk Leader

    Senior Mid-Market Credit Risk Leader

    Banque Nationale du Canada • Vancouver
    Full-time
    A leading Canadian bank is seeking a Senior Commercial Credit Manager to join its Credit Risk Management team in Vancouver. This role involves approving Mid‑Market commercial credit and managing por...Show more
    Last updated: 1 day ago • Promoted
    Senior Data Analyst, Risk

    Senior Data Analyst, Risk

    Spring Financial Inc. • Vancouver, BC, Canada
    Full-time +1
    Salary : $81,500-$107,500 yearly salary + benefits (See below for more details).Spring Financial is revolutionizing financial access for Canadians, providing smart credit-building, mortgage, and len...Show more
    Last updated: 23 days ago • Promoted
    Analyst, Enterprise Risk

    Analyst, Enterprise Risk

    Mnp Llp • Vancouver
    Full-time
    Inspirational, innovative and entrepreneurial - this is how we describe our empowered teams.Combine your passion with purpose and join a culture that is thriving in the face of change.Make an impac...Show more
    Last updated: 13 days ago • Promoted
    Manager, Compliance & Risk Management

    Manager, Compliance & Risk Management

    KPMG Canada • Vancouver
    Full-time
    At KPMG, you’ll join a team of diverse and dedicated problem solvers, connected by a common cause turning insight into opportunity for clients and communities around the world.KPMG’s Compliance Gro...Show more
    Last updated: 2 days ago • Promoted
    Risk Control Consultant

    Risk Control Consultant

    Intact Financial Corporation • Vancouver
    Full-time +1
    Our employees are at the heart of everything we do.Together, we help people, businesses, and society prosper in good times and be resilient in bad times. Our employee promise represents Intact’s com...Show more
    Last updated: 13 days ago • Promoted
    Senior Murex BA : Front-to-Back Trading & Risk

    Senior Murex BA : Front-to-Back Trading & Risk

    Themesoft Inc. • Vancouver
    Full-time +1
    A global IT solutions provider is seeking a Murex Business Analyst in Vancouver.This role is focused on leading trade lifecycle processes within the Murex environment, requiring expertise in Capita...Show more
    Last updated: 7 days ago • Promoted
    Senior LMS Analyst

    Senior LMS Analyst

    BC.Net • Vancouver
    Full-time
    The Senior LMS Analyst is primarily responsible for maintaining BCNET’s hosted Moodle cloud service offering, including configuration, Tier 2 support for institutional contacts, and maintenance of ...Show more
    Last updated: 30+ days ago • Promoted
    Director, Treasury Risk Management

    Director, Treasury Risk Management

    Vancity Group • Vancouver
    Full-time +1
    We’reVancity, a member-owned credit union built on the principles of inclusion and social justice.Since 1946, our relentless commitment to these values has helped us challenge the status quo and br...Show more
    Last updated: 30+ days ago • Promoted
    Senior Finance Portfolio Lead : Complex Loans & Risk Management

    Senior Finance Portfolio Lead : Complex Loans & Risk Management

    YaaLk Technologies • Vancouver
    Full-time
    A financial technology firm located in Metro Vancouver is seeking a Senior Finance / Funding Portfolio Manager.This role requires managing post-closing funding, including risk assessment and monitori...Show more
    Last updated: 6 days ago • Promoted
    Drive Commercial Loan Risk & Portfolio Impact

    Drive Commercial Loan Risk & Portfolio Impact

    Domain Funding • Vancouver
    Full-time
    A private mortgage brokerage in Vancouver is looking for an experienced Commercial Loan Risk Officer to support and implement loan risk policies. This full-time role involves working in a fast-paced...Show more
    Last updated: 11 days ago • Promoted