Third Party Risk Management Lead (Fixed-Term 6 months)
Location(s): Help Headquarters
Job Type: Full Time Regular
myWork Program: Hybrid
Starting Salary Range: $73,800.00 - $92,300.00
Background Screening Requirement:
- Enhanced Criminal Record Check
- Credit Check
- Identity Verification
- Employment Verification
- References
Job Purpose
The Third Party Risk Management Lead supports Coast Capital’s Third Party Risk Management (TPRM) program within Strategic Supplier Sourcing. This role is responsible for coordinating end-to-end supplier risk assessments, facilitating due diligence activities, and ensuring third-party relationships are managed in accordance with Coast Capital’s risk appetite, governance framework, and regulatory requirements. Working closely with Strategic Sourcing, Information Security, Privacy, Finance, Legal, and Operational Risk teams, the incumbent assesses and monitors supplier risks throughout the vendor lifecycle, supports policy and framework development, and maintains centralized vendor risk information and reporting. This role plays a key part in strengthening supplier governance, regulatory compliance, and sustainable business decision-making.
This is a 6-month Fixed Term position. This role is primarily remote, with occasional in-office attendance based on business needs. The role may be based out of our Surrey, BC or Toronto, ON office. The incumbent will typically attend in-person meetings approximately once every two months
Accountabilities
- Support and administer the Third Party Risk Management program and related governance processes.
- Conduct and validate inherent risk assessments for vendor engagements.
- Perform preliminary information security, privacy, financial, and operational risk assessments.
- Facilitate end-to-end supplier risk assessments, including due diligence, residual risk determination, and approvals.
- Partner with business owners and risk subject matter experts to identify, assess, and mitigate supplier risks.
- Provide risk analysis and recommendations that support informed business decisions and sustainable outcomes.
- Maintain a centralized vendor repository including vendor profiles, contracts, risk assessments, and supporting documentation.
- Monitor supplier risks throughout the lifecycle of vendor relationships and track remediation activities.
- Support the development, implementation, and continuous improvement of third-party risk policies, procedures, and frameworks.
- Maintain risk registers and assessment tools to track, monitor, and report on supplier risks and controls.
- Ensure compliance with applicable regulatory requirements and industry guidelines, including OSFI, AML/ATF, and Basel expectations.
- Prepare risk reports, portfolio monitoring tools, audit responses, and management reporting.
- Support internal and external audits through the collection and validation of risk documentation and evidence.
- Contribute to supplier governance and transformation initiatives that improve risk management effectiveness and operational efficiency.
Skills & Qualifications
- Bachelor’s degree in business, Economics, Risk Management, Information Security, Finance, or a related discipline.
- Professional certification or designation in Risk Management, Information Security, or Privacy is considered an asset.
- 4–6+ years of experience in Third Party Risk Management, Vendor Risk Management, Audit, Information Security, Privacy, or Operational Risk.
- Experience within Banking, Financial Services, Credit Union, or other regulated industries is preferred.
- Strong understanding of third-party risk management, vendor governance, due diligence, and supplier lifecycle management.
- Knowledge of information security, privacy, operational, financial, and regulatory risk management principles.
- Experience conducting inherent and residual risk assessments and coordinating due diligence reviews.
- Experience developing or maintaining policies, procedures, and risk management frameworks.
- Working knowledge of OSFI, Basel, AML/ATF, outsourcing risk management, and enterprise risk management practices.
- Experience with third-party risk assessment platforms, GRC systems, or vendor management tools is an asset.
- Strong proficiency in Microsoft Office, including Excel, PowerPoint, Word, and SharePoint.
- Excellent stakeholder management, communication, and relationship-building skills.
- Strong analytical, research, problem-solving, and critical-thinking capabilities.
- Demonstrated ability to manage multiple priorities, work independently, and deliver results in a fast-paced environment.
- Strong organizational skills, presentation abilities, and attention to detail.
Equity, Diversity & Inclusion at Coast Capital
Don’t meet every single requirement? At Coast Capital, we believe everyone has potential. We are committed to building better, brighter, more inclusive futures for everyone – including our employees. We see the potential in our employees to achieve amazing things and want to invest in your future. If you’re excited about this career opportunity and your experience may not perfectly align with every qualification in this job posting, we still encourage you to apply. You may be just the right candidate for this or other opportunities at Coast Capital.
At Coast Capital, we are committed to equity, diversity and inclusion. We strongly encourage applications from Indigenous Peoples, Black, and racialized persons, persons with disabilities, people of diverse sexual and gender identities and women. We value applicants who have demonstrated a commitment to equity, diversity and inclusion and recognize that diverse perspectives, experiences and expertise benefit of our employees, our members, and our community.
Coast Capital is committed to providing an accessible recruitment experience. If you are a candidate with a disability and require accommodation(s) during any stage of the recruitment process, please contact us at accessibility@coastcapitalsavings.com or 778-391-5836. This contact is intended solely for inquiries or feedback related to accessibility barriers, accommodation requests or alternate format requests. We will work with you to ensure your needs are met. You will only receive a response to inquiries related to these topics.