Talent.com
Royal Bank of Canada>
Senior Director, Vendor IT Risk Management (Global Security)Royal Bank of Canada> • TORONTO, Canada
Senior Director, Vendor IT Risk Management (Global Security)

Senior Director, Vendor IT Risk Management (Global Security)

Royal Bank of Canada> • TORONTO, Canada
18 days ago
Job type
  • Full-time
Job description

Job Description

What is the opportunity?


The Senior Director, Vendor IT Risk Management (Global Security) is a strategic leadership position responsible for driving the management and evolution of core third party IT risk practices at RBC. This role sits within the Global Cyber Security (GCS) Global IT Risk team and focuses on identifying, assessing, and advising on risks resulting from RBC’s third-party supply chain management engagements, considering safety, soundness, resiliency, risk, and compliance to RBC practices, policies, and guidelines.


As Senior Director, you will lead a team of direct reports and indirect reports and manage the enterprise-wide third-party supply chain management assessment program that covers all technology-related supplier engagements across RBC. You will serve as a subject matter expert in third party supply chain management risk and partner with other RBC risk teams, senior leadership, and staff to drive change and effectively manage risks in an open, collaborative environment to further mature the business risk culture.


The is responsible for transforming third party IT Risk practices to be more proactive, leveraging new technologies including Artificial Intelligence to enhance third party IT risk due diligence capabilities and increase coverage of suppliers while gaining insights to ensure risks are effectively identified.

What will you do?

  • Core Third Party Supply Chain Management & IT Risk Management- Contract Reviews: Participate in contract reviews to ensure appropriate IT risk-related clauses exist that support the organization’s right to review/audit the security practices of its third parties

  • SOC Reviews: Participate in SOC (Qualified Opinion) reviews as required and provide appropriate guidance to risk owners on control effectiveness and risk implications

  • M&A IT Risk Assessments: Complete comprehensive IT risk assessments for mergers and acquisitions, evaluating technology risks, integration challenges, and control environments

  • Define and advance third-party risk management maturity across the enterprise, establishing centralized standards while adapting to emerging risks and evolving organizational capabilities

  • Third Party Reporting and Analytics: Assist with the creation of third-party presentations, KRIs, KPIs and associated materials, and risk summaries for senior management and Board committees

  • Third Party Control Assessments & Continuous Monitoring- Lead the enterprise-wide third-party control assessment program for all technology-related supplier engagements across RBC

  • Establish and maintain standardized assessment frameworks covering cybersecurity, data protection, operational resilience, and technology governance domains

  • Advisory Services to Supplier Management Offices (SMOs)- Provide strategic third-party supply chain management advisory support to internal Supplier Management Offices across all business units and functions

  • Develop risk guidance, best practices, and decision-making frameworks that enable SMOs to make informed supplier selection and management decisions

  • Partner with SMOs on contract negotiations to ensure appropriate risk management clauses and control requirements are incorporated

  • Process Development & Tools Enhancement- Leverage Artificial Intelligence and advanced analytics to increase supplier coverage, automate risk scoring, and generate predictive insights

  • Design and deploy data-driven risk identification capabilities that enable proactive risk management and early warning systems

  • Manage complex stakeholder relationships across business units, including Procurement, GCS Teams, GRM Cyber and Technology Risk, Compliance, Legal, Privacy, BCM, Third Party Risk, SMO, and Lines of Business

  • Provide support, expertise, feedback, coaching, and development to build the capability of more junior staff, and promote a mindset for sustained success, growth, and diversity within the team

What do you need to succeed?

Must have:

  • 10+ years of experience in cyber security/third party IT risk with demonstrated progression to senior management roles, highly skilled at managing vendor/supplier relationships and service delivery partnerships

  • Highly skilled at navigating complex risk trade-offs—including vendor criticality assessment, data availability challenges, model risk, and control adequacy determinations—while balancing risk protection with business enablement

  • 10+ years of cyber security, data protection, operational resilience, and technology governance

  • 10+ years executing transformation initiatives that evolve third-party supply chain management practices from reactive to proactive models. With experience implementing AI and advanced analytics in risk management, to enable teams through technological and process innovation while sustaining operational excellence

  • SOC Reviews & Risk Assessments: 10+ years of experience conducting SOC reviews and comprehensive IT risk assessments for mergers and acquisitions, with demonstrated ability to evaluate technology risks, integration challenges, and control environments while providing strategic guidance to risk owners on control effectiveness and risk implications

  • Third-Party Risk Reporting & Executive Communication: 10+ years of experience developing third-party risk presentations, KRIs, KPIs, and risk summaries for senior management and Board committees, with proven ability to translate complex risk data into actionable intelligence for executive stakeholders

  • Deep experience with Cyber Security Frameworks - NIST, ISO 27001, with comprehensive knowledge of third-party risk assessment methodologies, control frameworks, and industry standards

  • Exceptional ability to influence and collaborate with senior leaders, business partners, and external stakeholders

Nice to have:

  • ISACA approved certifications together with other cyber security bodies or technical qualifications (CISSP preferred)

  • Experience with AI implementation in risk management domains

  • Advanced education in business, risk management, technology, or related field

What’s in it for you?

We thrive on the challenge to be our best, progressive thinking to keep growing, and working together to deliver trusted advice to help our clients thrive and communities prosper. We care about each other, reaching our potential, making a difference to our communities, and achieving success that is mutual.

  • A comprehensive Total Rewards Program including bonuses and flexible benefits, competitive compensation, commissions, and stock where applicable

  • Leaders who support your development through coaching and managing opportunities

  • Ability to make a difference and lasting impact

  • Work in a dynamic, collaborative, progressive, and high-performing team

  • Opportunities to do challenging work

  • Opportunities to take on progressively greater accountabilities

  • Access to a variety of job opportunities across business

#LI-POST
#TechPJ

Job Skills

Business Analytics, Decision Making, Financial Risk Management (FRM), Operational Delivery, Quality Management, Results-Oriented, Risk Management, Strategic Thinking

Additional Job Details

Address:

16 YORK ST:TORONTO

City:

Toronto

Country:

Canada

Work hours/week:

37.5

Employment Type:

Full time

Platform:

TECHNOLOGY AND OPERATIONS

Job Type:

Regular

Pay Type:

Salaried

Posted Date:

2026-07-13

Application Deadline:

2026-08-26

Note: Applications will be accepted until 11:59 PM on the day prior to the application deadline date above

Our Employment Opportunities

At RBC, we are guided by living shared values of Client First, Integrity, Collaboration, Respect and Excellence and winning together as One RBC. We believe an inclusive workplace that has diverse perspectives is core to our continued growth as one of the largest and most successful banks in the world. Maintaining a workplace where our employees feel supported to perform at their best, effectively collaborate, drive innovation, and grow professionally helps to bring our Purpose to life and create value for our clients and communities. RBC strives to deliver this through policies and programs intended to foster a workplace based on respect, belonging and opportunity for all.

Join our Talent Community

Stay in-the-know about great career opportunities at RBC. Sign up and get customized info on our latest jobs, career tips and Recruitment events that matter to you.

Expand your limits and create a new future together at RBC. Find out how we use our passion and drive to enhance the well-being of our clients and communities at jobs.rbc.com.

RBC is presently inviting candidates to apply for this existing vacancy. Applying to this posting allows you to express your interest in this current career opportunity at RBC. Qualified applicants may be contacted to review their resume in more detail.

Create a job alert for this search

Senior Director, Vendor IT Risk Management (Global Security) • TORONTO, Canada

Similar jobs

Remote Director of IT Security Role

DirectiveToronto, ON, CA
Remote
Full-time

Shape Directive Consulting's cybersecurity landscape as the Director of IT Security.This fully remote position emphasizes strategic oversight of information security across multiple regions.As the ... Show more

 • Promoted

Senior Manager - IT Governance Risk and Control

Enercare Inc.Markham, ON, CA
Full-time

Canada’s largest home and commercial services companies servicing over one million customers across Ontario, Manitoba, Saskatchewan, Alberta, British Columbia, Quebec and New Brunswick.Enercare is ... Show more

 • Promoted

Senior Leader, Cyber Risk Management

CapcoToronto
Full-time

As a Senior Leader within Capco’s Cyber Risk Management practice, you will be driving the growth, delivery, and innovation of our cybersecurity and technology risk services across the financial ser... Show more

 • Promoted

Senior AVP, Global Professional Services

ROSSRichmond Hill, York Region, CA
Full-time

A leading software company located in Richmond Hill is seeking an Assistant Vice President, Professional Services.The role entails overseeing professional service proposals, managing client satisfa... Show more

 • Promoted

Senior Risk Analyst

Stantec Consulting International Ltd.Markham
Full-time +1

Stantec is currently looking for a Senior Risk Analyst to be part of our team on a permanent full‑time position.Reporting to the Program Risk Lead, the Senior Risk Analyst will support one of the k... Show more

 • Promoted

Senior Director, CMHC Securitization

Cameron Stephens Mortgage Capital Ltd.toronto, on, Canada
Full-time

We are seeking an experienced and entrepreneurial.Senior Director, CMHC Securitization.Cameron Stephens’ CMHC-insured securitization function.This individual will be responsible for managing relati... Show more

 • Promoted

Director of IT Security for Directive Consulting

DirectiveToronto, ON, CA
Full-time

Enhance IT security as Director at Directive Consulting.Protect client data and manage risks within a fully remote framework.In this leadership role, you'll report to the Head of Finance and define... Show more

 • Promoted

Senior Actuary Director

VIP Universal Medical Insurance Group (VUMI)Markham, York Region, CA
Full-time

The Senior Actuary Director for the Life & Investment Division is a key member of the actuarial team, responsible for ensuring the financial soundness, risk management, and profitability of the com... Show more

 • Promoted

Senior Specialist, Vendor Management

Mazda Canada IncRichmond Hill, York Region, CA
Full-time

Work Arrangement: Hybrid (Home Office/Richmond Hill Office).At Mazda, we love sharing the beautiful machines we craft with the world.But even more, we love building relationships with the people wh... Show more

 • Promoted

Senior Director, Vendor IT Risk Management (Global Security)

RBCToronto, Ontario, Canada
Full-time

The Senior Director, Vendor IT Risk Management (Global Security) is a strategic leadership position responsible for driving the management and evolution of core third party IT risk practices at RBC... Show more

 • Promoted

Director, Risk & Total Fund Management Technology

CPP Investments | Investissements RPCtoronto, on, Canada
Full-time

Drive risk management and technology strategy as the Director at CPP Investments, focusing on the SimCorp platform.This position requires leadership in delivering accountability in investment perfo... Show more

 • Promoted

Senior Director, Pharmacovigilance and Drug Safety

Everest Clinical ResearchMarkham, Ontario, Canada
Full-time

Everest Clinical Research (“Everest”) is a full-service contract research organization (CRO) providing a broad range of expertise-based clinical research services to worldwide pharmaceutical, biote... Show more

 • Promoted

Senior Director, Vendor It Risk Management (Global Security)

RBCToronto, Canada
Full-time

Job Description The Senior Director, Vendor IT Risk Management (Global Security) is a strategic leadership position responsible for driving the management and evolution of core third party IT risk ... Show more

 • Promoted

IT Program & Delivery Director

ExtendicareMarkham, York Region, CA
Full-time

A leading care provider in Canada seeks an IT Project Director to oversee complex IT projects within their corporate operating divisions.This role, based in Markham, offers a hybrid working environ... Show more

 • Promoted

Senior Credit Risk Leader — Team Management & Compliance

Industrial and Commercial Bank of China (Canada)Richmond Hill, York Region, CA
Full-time

A prominent banking institution is seeking a Credit Risk Manager to lead their credit analysis team.This role involves overseeing underwriting, ensuring compliance with policies, and managing a cre... Show more

 • Promoted

Director of Infrastructure Operations at API

Accommodations Plus InternationalMarkham, ON, CA
Full-time

Shape the future of travel technology at Accommodations Plus International as the Director of Infrastructure Operations.This position in Markham, Ontario, focuses on AWS cloud strategy and team man... Show more

 • Promoted

Senior Manager of IT Audit and Risk

ScotiabankToronto
Full-time

Lead IT audit initiatives focused on cyber security as a Senior Audit Manager.Ensure compliance and risk management for cloud and technology infrastructures with a robust audit approach.In this rol... Show more

 • Promoted

Director, M&A

Perseus Group, Constellation SoftwareMarkham, ON, CA
Full-time

Director of M&A, Homebuilder Solutions Portfolio.Perseus Group, Constellation Software is looking for a Director of M&A for its homebuilding and construction portfolio.This role will work closely w... Show more

 • Promoted

Risk Director

MaceToronto
Full-time

At Mace, our purpose is to redefine the boundaries of ambition.We believe in creating places that are responsible, bringing transformative impact to our people, communities, and societies across th... Show more

 • Promoted

Senior IT Auditor

Amphenol ICCMarkham, York Region, CA
Full-time

Amphenol Communications Solutions (ACS), a division of Amphenol Corporation, is a world leader in interconnect solutions for Communications, Mobile, RF, Optics, and Commercial electronics markets.A... Show more