Farm Credit Canada logo
Farm Credit CanadaPosted 1 week ago

Senior Technical Analyst, Third-Party Risk Management

$94,620–$128,020 year

HybridRegina, Saskatchewan, Canada

Full TimeSenior LevelLargeAGRICULTURE

Job Summary

Review vendor security documentation, including SOC 2 reports and questionnaires, to assess alignment with FCC requirements. Complete vendor assessments from intake through recommendation, analyzing information security, business continuity, and privacy considerations to identify control gaps. Collaborate with third-party risk management, cybersecurity, privacy, and business stakeholders to clarify assessment questions and support consistent decision-making. Communicate assessment findings and recommendations to vendors and internal stakeholders in clear, practical language while managing priorities in a high-volume environment.

Required Qualifications

  • A bachelor's degree in computer science, information systems, cybersecurity, information security or a related discipline
  • At least four years of related experience in information security, cybersecurity, technology risk, vendor risk management, security governance, risk and compliance, or a related technical risk field (or an equivalent combination of education and experience)
  • Strong knowledge of information security concepts, controls and risk assessment practices
  • Experience interpreting technical security documentation and assessing vendor controls against defined requirements
  • Ability to assess risks, identify control gaps and provide practical recommendations that support business and vendor decisions
  • Strong written and verbal communication skills, including the ability to explain technical security topics to non-technical and senior stakeholders
  • Ability to work independently, manage multiple assessments and collaborate with team members when questions or escalations arise

Desired Qualifications

  • Experience reviewing SOC 2 reports or other third-party assurance reports
  • Experience in third-party risk management, vendor security assessments, security compliance or a regulated environment
  • Professional certification such as CISA, CISM, CISSP, CRISC or a privacy-related designation
  • Knowledge of security, privacy or operational resilience frameworks such as ISO 27001, NIST, SOC 2, OSFI guidance or business continuity practices
  • Bilingualism (English and French)

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce