Our client, is seeking an authoritative, highly experienced Info Security Analyst V (Third-Party Cyber Risk Lead) to join their core enterprise information security and risk governance division.
...
In this senior consulting role, you will take full ownership of leading and executing end-to-end third-party cyber risk assessments across global suppliers and vendor ecosystems. Acting as a lead subject matter expert in technology controls and information security, you will evaluate supplier security postures, identify potential control gaps, and collaborate with internal and external stakeholders to formulate robust risk mitigation and remediation strategies. Operating at the business application, portfolio, and overall enterprise level, you will ensure supplier integrations adhere strictly to enterprise technology control standards, industry risk frameworks, and regulatory guidelines.
Duration: 3-Month Contract (with potential for extension)
Work Arrangement: Hybrid (2 days per week on-site at the corporate office, 3 days work from home; anchor days are flexible. Potential future transition to 4 days on-site)
Advantages
High-Visibility Enterprise Scope: Lead comprehensive cyber risk evaluations for global suppliers across a major enterprise financial institution.
Strategic Subject Matter Leadership: Serve as the prime expert resource guiding business leaders, technical teams, and third-party vendor executives on technology controls and risk mitigation.
Cross-Functional Impact: Drive department-level initiatives and deliver complex, high-impact risk analysis reports for functional and enterprise leadership.
Balanced Hybrid Model: Enjoy a flexible hybrid schedule combining collaborative on-site days with remote execution.
Responsibilities
Third-Party Risk Assessment Execution
Scoping & Assessment Leadership: Coordinate with key risk stakeholders to initiate, scope, and execute thorough third-party cyber risk assessments for new and existing suppliers across all risk tiers.
Enterprise Security Evaluation: Lead or contribute to complex cyber risk evaluations at the business application, portfolio, and global enterprise architecture levels.
Stakeholder Communication: Articulate technical risk assessment findings, compliance gaps, and security evaluations clearly to both technical and non-technical internal and external stakeholders.
Mitigation Governance & Process Optimization
Remediation & Validation: Coordinate with risk partners and vendors to establish actionable risk mitigation plans. Independently validate and test remediation controls upon vendor implementation.
Standards & Regulatory Compliance: Conduct all risk evaluations in strict compliance with internal policies, enterprise technology control standards, and applicable financial regulatory guidelines.
Continuous Process Improvement: Contribute to the continuous review of internal TPRM methodologies, identifying opportunities to streamline assessment workflows and elevate the organization's technology risk culture.
Qualifications
TPRM & Risk Assessor Experience: 10+ years of dedicated professional experience performing third-party cyber risk assessments and vendor security evaluations.
Domain Expertise: Expert-level command of IT security risk disciplines, technology controls, and enterprise risk management practices.
Complex Initiative Delivery: Demonstrated track record leading and participating in comprehensive, enterprise-scale security assessment projects.
Lead Expert Capability: Proven ability to act as the primary expert resource in technology controls and information security when engaging with business units and third-party vendor leads.
Soft Skills & Communication: Exceptional written and verbal communication skills with the proven ability to present complex risk findings to non-technical executive audiences; strong collaboration, coordination, and stakeholder management abilities.
Preferred Assets & Nice-to-Haves
Active CISSP (Certified Information Systems Security Professional) or equivalent recognized information security accreditation (e.g., CISA, CRISC, CTPRP).
Prior third-party risk management experience within a Tier-1 Bank or Regulated Financial Institution.
Summary
If you are a tech-savvy Info Security Analyst V who pairs an absolute command of third-party cyber risk methodologies and IT control frameworks with 10+ years of enterprise vendor assessment leadership, this 3-month hybrid contract is an outstanding opportunity. Bring your risk evaluation precision, stakeholder communication skills, and collaborative security focus to our client's team today!
Randstad Canada is committed to fostering a workforce reflective of all peoples of Canada. As a result, we are committed to developing and implementing strategies to increase the equity, diversity and inclusion within the workplace by examining our internal policies, practices, and systems throughout the entire lifecycle of our workforce, including its recruitment, retention and advancement for all employees. In addition to our deep commitment to respecting human rights, we are dedicated to positive actions to affect change to ensure everyone has full participation in the workforce free from any barriers, systemic or otherwise, especially equity-seeking groups who are usually underrepresented in Canada's workforce, including those who identify as women or non-binary/gender non-conforming; Indigenous or Aboriginal Peoples; persons with disabilities (visible or invisible) and; members of visible minorities, racialized groups and the LGBTQ2+ community.
Randstad Canada is committed to creating and maintaining an inclusive and accessible workplace for all its candidates and employees by supporting their accessibility and accommodation needs throughout the employment lifecycle. We ask that all job applications please identify any accommodation requirements by sending an email to accessibility@randstad.ca to ensure their ability to fully participate in the interview process.
This posting is for existing and upcoming vacancies.
show more
Our client, is seeking an authoritative, highly experienced Info Security Analyst V (Third-Party Cyber Risk Lead) to join their core enterprise information security and risk governance division.
In this senior consulting role, you will take full ownership of leading and executing end-to-end third-party cyber risk assessments across global suppliers and vendor ecosystems. Acting as a lead subject matter expert in technology controls and information security, you will evaluate supplier security postures, identify potential control gaps, and collaborate with internal and external stakeholders to formulate robust risk mitigation and remediation strategies. Operating at the business application, portfolio, and overall enterprise level, you will ensure supplier integrations adhere strictly to enterprise technology control standards, industry risk frameworks, and regulatory guidelines.
Duration: 3-Month Contract (with potential for extension)
Work Arrangement: Hybrid (2 days per week on-site at the corporate office, 3 days work from home; anchor days are flexible. Potential future transition to 4 days on-site)
Advantages
...
High-Visibility Enterprise Scope: Lead comprehensive cyber risk evaluations for global suppliers across a major enterprise financial institution.
Strategic Subject Matter Leadership: Serve as the prime expert resource guiding business leaders, technical teams, and third-party vendor executives on technology controls and risk mitigation.
Cross-Functional Impact: Drive department-level initiatives and deliver complex, high-impact risk analysis reports for functional and enterprise leadership.
Balanced Hybrid Model: Enjoy a flexible hybrid schedule combining collaborative on-site days with remote execution.
Responsibilities
Third-Party Risk Assessment Execution
Scoping & Assessment Leadership: Coordinate with key risk stakeholders to initiate, scope, and execute thorough third-party cyber risk assessments for new and existing suppliers across all risk tiers.
Enterprise Security Evaluation: Lead or contribute to complex cyber risk evaluations at the business application, portfolio, and global enterprise architecture levels.
Stakeholder Communication: Articulate technical risk assessment findings, compliance gaps, and security evaluations clearly to both technical and non-technical internal and external stakeholders.
Mitigation Governance & Process Optimization
Remediation & Validation: Coordinate with risk partners and vendors to establish actionable risk mitigation plans. Independently validate and test remediation controls upon vendor implementation.
Standards & Regulatory Compliance: Conduct all risk evaluations in strict compliance with internal policies, enterprise technology control standards, and applicable financial regulatory guidelines.
Continuous Process Improvement: Contribute to the continuous review of internal TPRM methodologies, identifying opportunities to streamline assessment workflows and elevate the organization's technology risk culture.
Qualifications
TPRM & Risk Assessor Experience: 10+ years of dedicated professional experience performing third-party cyber risk assessments and vendor security evaluations.
Domain Expertise: Expert-level command of IT security risk disciplines, technology controls, and enterprise risk management practices.
Complex Initiative Delivery: Demonstrated track record leading and participating in comprehensive, enterprise-scale security assessment projects.
Lead Expert Capability: Proven ability to act as the primary expert resource in technology controls and information security when engaging with business units and third-party vendor leads.
Soft Skills & Communication: Exceptional written and verbal communication skills with the proven ability to present complex risk findings to non-technical executive audiences; strong collaboration, coordination, and stakeholder management abilities.
Preferred Assets & Nice-to-Haves
Active CISSP (Certified Information Systems Security Professional) or equivalent recognized information security accreditation (e.g., CISA, CRISC, CTPRP).
Prior third-party risk management experience within a Tier-1 Bank or Regulated Financial Institution.
Summary
If you are a tech-savvy Info Security Analyst V who pairs an absolute command of third-party cyber risk methodologies and IT control frameworks with 10+ years of enterprise vendor assessment leadership, this 3-month hybrid contract is an outstanding opportunity. Bring your risk evaluation precision, stakeholder communication skills, and collaborative security focus to our client's team today!
Randstad Canada is committed to fostering a workforce reflective of all peoples of Canada. As a result, we are committed to developing and implementing strategies to increase the equity, diversity and inclusion within the workplace by examining our internal policies, practices, and systems throughout the entire lifecycle of our workforce, including its recruitment, retention and advancement for all employees. In addition to our deep commitment to respecting human rights, we are dedicated to positive actions to affect change to ensure everyone has full participation in the workforce free from any barriers, systemic or otherwise, especially equity-seeking groups who are usually underrepresented in Canada's workforce, including those who identify as women or non-binary/gender non-conforming; Indigenous or Aboriginal Peoples; persons with disabilities (visible or invisible) and; members of visible minorities, racialized groups and the LGBTQ2+ community.
Randstad Canada is committed to creating and maintaining an inclusive and accessible workplace for all its candidates and employees by supporting their accessibility and accommodation needs throughout the employment lifecycle. We ask that all job applications please identify any accommodation requirements by sending an email to accessibility@randstad.ca to ensure their ability to fully participate in the interview process.
This posting is for existing and upcoming vacancies.
show more