Senior Technical Analyst, Third-Party Risk Management

Posted 9 Days Ago
Be an Early Applicant
Regina, SK, CAN
In-Office
95K-128K Annually
Senior level
Fintech • Financial Services
The Role
Assess and monitor cybersecurity, privacy, and operational risks of third-party vendors. Review SOC 2 reports and security documentation, complete vendor assessments, identify control gaps, recommend mitigations, and communicate findings to vendors and stakeholders. Support remediation, escalation, and ongoing vendor oversight in a high-volume assessment environment.
Summary Generated by Built In

Closing Date (MM/DD/YYYY):

08/31/2026

Worker Type:

Permanent

Language(s) Required:

English

Term Duration (in months):

Salary Range (plus eligible to receive a performance based incentive, applicable to position) :

$94,620 - $128,020

Why FCC?

At FCC, we’re proud to be 100% invested in Canadian agriculture and food. As a federal Crown corporation, we provide financing, knowledge resources and business management software to over 103,000 customers nationwide.

Here’s what you can expect when you join our team:

  • Competitive total rewards packages: market-aligned and performance-based salary and incentive programs, flexible and comprehensive group benefit and savings plans, and well-being support through benefits and wellness programs

  • Purpose-driven work: We build strong relationships, share knowledge and support the people who feed the world

  • Growth: Learning and development opportunities to help you thrive

  • Hybrid work options

.

How you’ll make an impact

As a Senior Technical Analyst, Third-Party Risk Management (TPRM), you’ll assess and monitor technology, cybersecurity, privacy and operational risks associated with third-party service providers. You’ll provide independent analysis and risk-based recommendations to ensure vendor services align with organizational policies, security standards, regulatory requirements and risk appetite.

Working closely with business owners, procurement, cybersecurity, privacy, legal and vendor representatives, you’ll evaluate third-party controls, identify potential risks, facilitate remediation activities and support ongoing vendor oversight throughout the vendor lifecycle.

We’re looking for a strong analytical thinker who can assess vendor security risks, interpret technical documentation and turn findings into practical recommendations. Someone who’s comfortable reviewing security reports, asking thoughtful questions and communicating clearly with both technical teams and business stakeholders.

If you have a foundation in information security or cybersecurity, enjoy independent assessment work and can explain complex technical topics in plain language, this could be the role for you.

What you’ll do

  • Review vendor security documentation, including SOC 2 reports, security questionnaires and supporting evidence, to assess alignment with FCC requirements
  • Complete vendor assessments from a shared queue, taking ownership of assigned assessments from intake through recommendation
  • Analyze information security, business continuity and privacy considerations to identify vendor risks, control gaps and mitigation needs
  • Collaborate with third-party risk management, cybersecurity, privacy and business stakeholders to clarify assessment questions and support consistent decision-making
  • Communicate assessment findings and recommendations to vendors and internal stakeholders in clear, practical language
  • Contribute to a high-volume assessment environment by managing priorities, documenting rationale and escalating risks or exceptions when needed

What you’ll bring to the team

Required qualifications:

  • A bachelor’s degree in computer science, information systems, cybersecurity, information security or a related discipline
  • At least four years of related experience in information security, cybersecurity, technology risk, vendor risk management, security governance, risk and compliance, or a related technical risk field (or an equivalent combination of education and experience)
  • Strong knowledge of information security concepts, controls and risk assessment practices
  • Experience interpreting technical security documentation and assessing vendor controls against defined requirements
  • Ability to assess risks, identify control gaps and provide practical recommendations that support business and vendor decisions
  • Strong written and verbal communication skills, including the ability to explain technical security topics to non-technical and senior stakeholders
  • Ability to work independently, manage multiple assessments and collaborate with team members when questions or escalations arise

Preferred qualifications:

  • Experience reviewing SOC 2 reports or other third-party assurance reports
  • Experience in third-party risk management, vendor security assessments, security compliance or a regulated environment
  • Professional certification such as CISA, CISM, CISSP, CRISC or a privacy-related designation
  • Knowledge of security, privacy or operational resilience frameworks such as ISO 27001, NIST, SOC 2, OSFI guidance or business continuity practices

Not sure you meet every requirement? We encourage you to apply anyway.

You belong here  
At FCC, we’re committed to creating an inclusive, equitable and accessible workplace – one that reflects the communities where we live, work and play. Our team is made stronger through diversity, and we’re dedicated to building a workforce that brings together a range of backgrounds, abilities and perspectives.  
   
We encourage qualified applicants to apply, including members of these four employment equity groups:  
• Indigenous Peoples  
• Members of visible minority groups  
• Persons with disabilities  
• Women  

Accessibility and accommodations   

To support an inclusive and accessible candidate experience, we encourage anyone needing an adjustment or accommodation during any stage of the recruitment process to email us at:  [email protected]. An HR partner will respond and work with applicants who request a reasonable accommodation. Information received in relation to accommodation requests will not impact hiring decisions. 

Skills Required

  • Bachelor's degree in computer science, information systems, cybersecurity, information security or a related discipline
  • At least four years of related experience in information security, cybersecurity, technology risk, vendor risk management, security governance, risk and compliance, or a related technical risk field (or equivalent combination of education and experience)
  • Strong knowledge of information security concepts, controls and risk assessment practices
  • Experience interpreting technical security documentation and assessing vendor controls against defined requirements
  • Ability to assess risks, identify control gaps and provide practical recommendations that support business and vendor decisions
  • Strong written and verbal communication skills, including the ability to explain technical security topics to non-technical and senior stakeholders
  • Ability to work independently, manage multiple assessments and collaborate with team members when questions or escalations arise
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Regina
2,299 Employees
Year Founded: 1959

What We Do

FCC is a federal Crown corporation that is 100% invested in Canadian agriculture and food. With 100 offices across the country (and our headquarters in Regina), we’ve built a culture of teamwork, leadership and respect. We offer financing, insurance, software, learning programs, and other business services to producers, agribusiness owners and agri-food entrepreneurs across the country. FCC is one of Canada’s best employers. Here, diverse people pull together to achieve challenging and rewarding goals. Learn and grow in an environment of acceptance and accountability. We want our employees to succeed, and our culture helps them do it.

Similar Jobs

Enverus Logo Enverus

Data Specialist - 26327D

Big Data • Information Technology • Software • Analytics • Energy
In-Office or Remote
2 Locations
1800 Employees

Superhuman Logo Superhuman

Designer

Artificial Intelligence • Information Technology • Machine Learning • Natural Language Processing • Productivity • Software • Generative AI
Remote or Hybrid
2 Locations
1500 Employees
190K-286K Annually

HiBob Logo HiBob

Associate Account Executive

HR Tech • Information Technology • Professional Services • Sales • Software
Remote or Hybrid
Canada
1350 Employees

HiBob Logo HiBob

Account Executive

HR Tech • Information Technology • Professional Services • Sales • Software
Remote or Hybrid
Canada
1350 Employees
95K-119K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account