×
Register Here to Apply for Jobs or Post Jobs. X

Senior Director, Vendor IT Risk Management (Global Security

Job in Toronto, Ontario, C6A, Canada
Listing for: RBC
Full Time position
Listed on 2026-08-18
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Consultant, IT Project Manager
Job Description & How to Apply Below
Position: Senior Director, Vendor IT Risk Management (Global Security)
Job Description   The Senior Director, Vendor IT Risk Management (Global Security) is a strategic leadership position responsible for driving the management and evolution of core third party IT risk practices s role sits within the Global Cyber Security (GCS) Global IT Risk team and focuses on identifying, assessing, and advising on risks resulting from RBC’s third-party supply chain management engagements, considering safety, soundness, resiliency, risk, and compliance to RBC practices, policies, and guidelines.

As Senior Director, you will lead a team of direct reports and indirect reports and manage the enterprise-wide third-party supply chain management assessment program that covers all technology-related supplier engagements across RBC. You will serve as a subject matter expert in third party supply chain management risk and partner with other RBC risk teams, senior leadership, and staff to drive change and effectively manage risks in an open, collaborative environment to further mature the business risk culture.

The is responsible for transforming third party IT Risk practices to be more proactive, leveraging new technologies including Artificial Intelligence to enhance third party IT risk due diligence capabilities and increase coverage of suppliers while gaining insights to ensure risks are effectively identified.
What will you do?
Core Third Party Supply Chain Management & IT Risk Management
- Contract Reviews:
Participate in contract reviews to ensure appropriate IT risk-related clauses exist that support the organization’s right to review/audit the security practices of its third parties
SOC Reviews:
Participate in SOC (Qualified Opinion) reviews as required and provide appropriate guidance to risk owners on control effectiveness and risk implications
M&A IT Risk Assessments:
Complete comprehensive IT risk assessments for mergers and acquisitions, evaluating technology risks, integration challenges, and control environments
Define and advance third-party risk management maturity across the enterprise, establishing centralized standards while adapting to emerging risks and evolving organizational capabilities
Third Party Reporting and Analytics:
Assist with the creation of third-party presentations, KRIs, KPIs and associated materials, and risk summaries for senior management and Board committees
Third Party Control Assessments & Continuous Monitoring
- Lead the enterprise-wide third-party control assessment program for all technology-related supplier engagements across RBC
Establish and maintain standardized assessment frameworks covering cybersecurity, data protection, operational resilience, and technology governance domains
Advisory Services to Supplier Management Offices (SMOs)- Provide strategic third-party supply chain management advisory support to internal Supplier Management Offices across all business units and functions
Develop risk guidance, best practices, and decision-making frameworks that enable SMOs to make informed supplier selection and management decisions
Partner with SMOs on contract negotiations to ensure appropriate risk management clauses and control requirements are incorporated
Process Development & Tools Enhancement
- Leverage Artificial Intelligence and advanced analytics to increase supplier coverage, automate risk scoring, and generate predictive insights
Design and deploy data-driven risk identification capabilities that enable proactive risk management and early warning systems
Manage complex stakeholder relationships across business units, including Procurement, GCS Teams, GRM Cyber and Technology Risk, Compliance, Legal, Privacy, BCM, Third Party Risk, SMO, and Lines of Business
Provide support, expertise, feedback, coaching, and development to build the capability of more junior staff, and promote a mindset for sustained success, growth, and diversity within the team
What do you need to succeed?
Must have:
10+ years of experience in cyber security/third party IT risk with demonstrated progression to senior management roles, highly skilled at managing vendor/supplier relationships and service delivery partnerships
Highly skilled at navigating complex risk…
Position Requirements
10+ Years work experience
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary