Third Party Security Risk Management Specialist
Wealthsimple
In this role, you'll have the opportunity to:
- Lead the development and implementation of a scalable third-party risk management program that aligns with business objectives and regulatory requirements
- Conduct comprehensive security risk assessments of vendors, suppliers, and business partners
- Collaborate with cross-functional teams to establish vendor onboarding/offboarding processes, security questionnaires, and risk rating methodologies
- Develop policies and procedures for vendor lifecycle management, from initial due diligence through ongoing monitoring and contract renewal
- Drive continuous monitoring initiatives through risk-based assessments, vendor audits, and remediation tracking
- Support procurement and legal teams with contract reviews, ensuring appropriate security and compliance clauses are included
- Contribute to incident response procedures related to third-party security events and vendor-related risks
- Build and maintain a centralized vendor risk registry and reporting dashboard for executive reporting
What you'll bring:
- 4-6 years of experience in third-party risk management, vendor risk assessment, or supply chain security (preferably in financial services or fintech)
- Working knowledge of Canadian regulatory requirements (PIPEDA, OSFI guidelines) and international frameworks (SOC 2, ISO 27001) with experience evaluating vendor compliance
- Proven ability to design and implement vendor risk management programs in complex, regulated environments
- Strong analytical and communication skills with ability to present risk findings and recommendations to stakeholders at all levels
- Experience with risk assessment methodologies, vendor questionnaires, and due diligence processes
- Familiarity with security frameworks and controls assessment (experience with GRC tools is a plus but not required)
- Self-directed professional who can manage multiple vendor assessments simultaneously and influence cross-functional stakeholders
- Relevant certifications preferred (CTPRP, CISA, CISSP, CRISC, or equivalent risk management credentials)
