CareerPlanSign in

Senior Information Security Analyst, Third-Party Security and Data Breach Expert (T & I) (Telework/Hybrid)

Montreal, QC, CA🌐 Remote💼 Full-time🗓 2026-09-11 → 2026-09-26

Core

Lead the organization-wide Third-Party Risk Management (TPRM) program, overseeing vendor security assessments, defining risk frameworks, and managing data breach response for external partners.

Role type

Senior IC Information Security Analyst (Third-Party Risk & Data Breach)

Builds

Third-Party Risk Management (TPRM) program, risk registers, and security compliance frameworks for vendors.

Domain

Information Security, Third-Party Risk Management, Regulatory Compliance

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

Third-Party Risk Management (TPRM), security assessment methodologies, regulatory compliance (GDPR, Law 25), contractual security requirements, risk mitigation strategies, vendor negotiation, security incident response, risk register management, security standards (ISO 27001, NIST), cloud architecture security, network security, cryptographic principles, business continuity planning.

Preferred skills

CISSP, CRISC, CBCP, CISA, CISM certifications.

Technologies

ISO/IEC 27001, NIST SP 800-53, COBIT, ITIL, SOC 2 Type II, GDPR, Law 25, firewalls, IDS/IPS, DNS, encryption.

Responsibilities

Lead and oversee the organization-wide TPRM program from process development to implementation. Define and maintain third-party risk classification frameworks and security assessment questionnaires. Evaluate third-party security posture by reviewing SOC 2, ISO 27001, and penetration test results. Assess security gaps and formulate risk mitigation strategies or compensating controls. Define and validate complex contractual security requirements including audit rights and incident notification SLAs. Negotiate directly with vendor security leaders to enforce organizational security requirements. Provide technical leadership during third-party security incidents or data breaches. Maintain an up-to-date mapping and inventory of all external partners and their risk levels. Schedule and perform ongoing security evaluations based on vendor criticality. Produce governance dashboards and metrics (KPIs/KRIs) for leadership. Advance the TPRM strategy in response to emerging cyber threats and regulatory updates.

Seniority

Senior, hands-on IC

Sourced via workday · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.