Senior Technical Analyst, Third-Party Risk Management

FCC / FACRegina, SK
CA$94,620 - CA$128,020Hybrid

About The Position

As a Senior Technical Analyst, Third-Party Risk Management (TPRM), you’ll assess and monitor technology, cybersecurity, privacy and operational risks associated with third-party service providers. You’ll provide independent analysis and risk-based recommendations to ensure vendor services align with organizational policies, security standards, regulatory requirements and risk appetite. Working closely with business owners, procurement, cybersecurity, privacy, legal and vendor representatives, you’ll evaluate third-party controls, identify potential risks, facilitate remediation activities and support ongoing vendor oversight throughout the vendor lifecycle. We’re looking for a strong analytical thinker who can assess vendor security risks, interpret technical documentation and turn findings into practical recommendations. Someone who’s comfortable reviewing security reports, asking thoughtful questions and communicating clearly with both technical teams and business stakeholders. If you have a foundation in information security or cybersecurity, enjoy independent assessment work and can explain complex technical topics in plain language, this could be the role for you.

Requirements

  • A bachelor’s degree in computer science, information systems, cybersecurity, information security or a related discipline
  • At least four years of related experience in information security, cybersecurity, technology risk, vendor risk management, security governance, risk and compliance, or a related technical risk field (or an equivalent combination of education and experience)
  • Strong knowledge of information security concepts, controls and risk assessment practices
  • Experience interpreting technical security documentation and assessing vendor controls against defined requirements
  • Ability to assess risks, identify control gaps and provide practical recommendations that support business and vendor decisions
  • Strong written and verbal communication skills, including the ability to explain technical security topics to non-technical and senior stakeholders
  • Ability to work independently, manage multiple assessments and collaborate with team members when questions or escalations arise

Nice To Haves

  • Experience reviewing SOC 2 reports or other third-party assurance reports
  • Experience in third-party risk management, vendor security assessments, security compliance or a regulated environment
  • Professional certification such as CISA, CISM, CISSP, CRISC or a privacy-related designation
  • Knowledge of security, privacy or operational resilience frameworks such as ISO 27001, NIST, SOC 2, OSFI guidance or business continuity practices

Responsibilities

  • Review vendor security documentation, including SOC 2 reports, security questionnaires and supporting evidence, to assess alignment with FCC requirements
  • Complete vendor assessments from a shared queue, taking ownership of assigned assessments from intake through recommendation
  • Analyze information security, business continuity and privacy considerations to identify vendor risks, control gaps and mitigation needs
  • Collaborate with third-party risk management, cybersecurity, privacy and business stakeholders to clarify assessment questions and support consistent decision-making
  • Communicate assessment findings and recommendations to vendors and internal stakeholders in clear, practical language
  • Contribute to a high-volume assessment environment by managing priorities, documenting rationale and escalating risks or exceptions when needed

Benefits

  • market-aligned and performance-based salary and incentive programs
  • flexible and comprehensive group benefit and savings plans
  • well-being support through benefits and wellness programs
  • Learning and development opportunities
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service