Senior Analyst, ORM & Third-Party Risk

Posted 5 Days Ago
Be an Early Applicant
Oakville, ON, CAN
In-Office
64K-85K Annually
Senior level
Retail
The Role
Supports the organization’s third-party and operational risk programs by coordinating risk assessments, evaluating control environments, monitoring remediation, preparing dashboards and governance reporting, and providing oversight throughout third-party lifecycles. The role collaborates with procurement, legal, cybersecurity, compliance, technology, and enterprise risk teams; supports regulatory reviews and audits; and assesses operational resilience, concentration risk, fourth-party dependencies, and supply-chain risks.
Summary Generated by Built In

The Senior Analyst, ORM & Third-Party Risk will report to Manager, Third-Party Risk and primarily support the organization's Third-Party Risk Management program while also contributing to broader Operational Risk Management objectives as needed. This role is responsible for assessing, monitoring, and reporting risks arising from third-party relationships, ensuring suppliers and service providers operate in accordance with the organization's risk appetite, regulatory requirements, and governance standards.

Working closely with business owners, procurement, legal, technology, cybersecurity, compliance, and risk stakeholders, the Senior Analyst provides effective challenge and oversight throughout the third-party lifecycle while supporting operational risk assessments, issue management, resilience considerations, and risk reporting activities.


Key Responsibilities

Third-Party Risk Management

  • Support the execution and continuous improvement of the Third-Party Risk Management framework, policies, standards, and procedures.
  • Co-ordinate third-party risk assessments across various risk domains, including operational, cyber, information security, privacy, compliance, financial, and resiliency risk.
  • Review inherent and residual risks associated with third-party relationships and recommend appropriate mitigation strategies.
  • Monitor third-party risk profiles and track remediation activities to ensure identified risks are effectively managed.
  • Support ongoing monitoring activities and periodic reassessments of critical and high-risk third parties.
  • Partner with procurement, legal, and business stakeholders throughout the onboarding, renewal, and termination processes.
  • Prepare third-party risk reporting, metrics, dashboards, and committee materials for management and governance forums.
  • Support regulatory examinations, audits, and reviews related to third-party risk management activities.

Operational Risk Management

  • Support Operational Risk Management activities, including risk and control assessments, issue management, and risk reporting.
  • Assist in identifying, assessing, and monitoring operational risks associated with critical business processes and third-party dependencies.
  • Collaborate with Operational Resilience, Business Continuity, Cybersecurity, and Enterprise Risk teams to assess risks associated with critical service providers.
  • Participate in the evaluation of concentration risk, fourth-party dependencies, and supply chain resiliency considerations.

Qualifications Required

  • Bachelor's degree in Business, Risk Management, Supply Chain Management, or a related field.
  • 3-5 years of experience in Third-Party Risk Management, Operational Risk Management, Enterprise Risk, Compliance, Audit, Procurement Risk, or a related discipline.
  • Strong understanding of third-party risk management principles and lifecycle activities.
  • Experience conducting risk assessments and analyzing control environments.
  • Strong analytical, critical thinking, and problem-solving capabilities.
  • Excellent written and verbal communication skills.
  • Ability to effectively challenge stakeholders and influence risk-informed decision-making.
  • Advanced proficiency in Microsoft Excel, PowerPoint, and reporting tools.

Preferred

  • Experience within financial services, insurance, healthcare, or other regulated industries.
  • Familiarity with operational resilience, business continuity, vendor management, or cybersecurity risk management practices.
  • Experience with Governance, Risk, and Compliance (GRC) platforms and third-party risk management tools.
  • Working knowledge of industry frameworks and standards related to risk management and third-party oversight.
  • Professional certifications such as CRISC, CISA, CISSP, CBCP, MBCI, CTPRP, or equivalent are considered an asset.

Success Measures

  • Effective execution of third-party due diligence, risk assessments, and ongoing monitoring activities.
  • Timely identification, escalation, and management of third-party risks and control concerns.
  • High-quality risk reporting and governance support for leadership and risk committees.
  • Strong stakeholder engagement across business, procurement, legal, technology, and risk functions.
  • Contribution to a mature and effective risk management program through continuous improvement initiatives and proactive risk oversight.

Broadband Salary Range:  $64,000 – 106,000
Our typical hiring range is between $80,000 and $85,000. Salary decisions are also dependent on other factors such as your experience, industry benchmarks, internal equity and other role-specific requirements. For critical roles, the compensation offering will be reviewed to ensure alignment with market rate and conditions and the unique value you bring to the role.  #LI-NZ2

This posting represents an existing vacancy within our organization.

We may use artificial intelligence tools as part of our recruitment process to assist in the initial screening of resumes. All hiring decisions, including candidate evaluation, selection, and disposition, are made by human recruiters.

About Us

At Canadian Tire Services Limited/Canadian Tire Bank, it is our mandate to continue to create innovative and rewarding financial solutions for our customers. Our growing suite of products and services showcase the dynamic contributions from our employees and our success is driven by a strong vision, loyal customers, and our ability to build teams that reflect the diverse customers and communities in which we live and work. Join us, where there's a place for you here.

Our Commitment to Diversity, Inclusion and Belonging 

We are committed to fostering an environment where belonging thrives, and diversity, inclusion and equity are infused into everything we do. We believe in building an organizational culture where people are consistently treated with dignity while respecting individual religion, nationality, gender, race, age, perceived ability, spoken language, sexual orientation, and identification. We are united in our purpose of being here to help make life in Canada better. .

Accommodations  

We stand firm in our Core Value that inclusion is a must. We welcome and encourage candidates from equity-seeking groups such as people who identify as racialized, Indigenous, 2SLGBTQIA+, women, people with disabilities, and beyond. Should you require any accommodation in applying for this role, or throughout the interview process, please make them known when contacted and we will work with you to help meet your needs.

Skills Required

  • Bachelor’s degree in Business, Risk Management, Supply Chain Management, or a related field
  • 3–5 years of experience in Third-Party Risk Management, Operational Risk Management, Enterprise Risk, Compliance, Audit, Procurement Risk, or a related discipline
  • Strong understanding of third-party risk management principles and lifecycle activities
  • Experience conducting risk assessments and analyzing control environments
  • Strong analytical, critical thinking, and problem-solving capabilities
  • Excellent written and verbal communication skills
  • Ability to challenge stakeholders and influence risk-informed decision-making
  • Advanced proficiency in Microsoft Excel, PowerPoint, and reporting tools
  • Experience in financial services, insurance, healthcare, or another regulated industry
  • Familiarity with operational resilience, business continuity, vendor management, or cybersecurity risk management practices
  • Experience with Governance, Risk, and Compliance platforms and third-party risk management tools
  • Working knowledge of industry risk management and third-party oversight frameworks and standards
  • Professional certification such as CRISC, CISA, CISSP, CBCP, MBCI, CTPRP, or equivalent
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
9,112 Employees

What We Do

HBC is a diversified global retailer focused on driving the performance of high quality stores and their omni-channel offerings and unlocking the value of real estate holdings. Founded in 1670, we are the oldest company in North America.

Similar Jobs

In-Office
Oakville, ON, CAN
27053 Employees
64K-85K Annually

Hilton Logo Hilton

Director Of Engineering

Software • Hospitality
In-Office
Toronto, ON, CAN
121228 Employees
1-1 Annually

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Temporary Sales Associate

eCommerce • Fashion • Retail • Sales • Wearables • Design
Hybrid
Toronto, ON, CAN
16000 Employees
18-22 Hourly

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Temporary Sales Support Associate

eCommerce • Fashion • Retail • Sales • Wearables • Design
Hybrid
Toronto, ON, CAN
16000 Employees
18-22 Hourly

Similar Companies Hiring

Tastewise Thumbnail
Artificial Intelligence • Big Data • Food • Retail • Software • Generative AI • Big Data Analytics
NYC, NYC
120 Employees
Scotch Thumbnail
Artificial Intelligence • eCommerce • Fintech • Payments • Retail • Software • Analytics
US
35 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account