Montreal Exchange

Senior Analyst, Enterprise Risk Management (Third-Party Risk & Regulatory Initiative Focus)

Montreal Exchange$85K — $90K *
Finance & Insurance
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Finance, Business Administration, or related field (Master's preferred)
  • Minimum of 3 years of relevant experience in risk management, audit, or compliance in financial services or consulting
  • Proven track record in delivering ERM/ORM projects, including Cybersecurity and Crisis Management
  • Solid understanding of financial institutions and market infrastructures
  • Exceptional written and verbal communication skills
  • Ability to manage multiple priorities independently and drive results

Responsibilities

  • Support the development of the Third Party Risk Management (TPRM) governance framework
  • Implement the TPRM program across CDCC and CDS with risk-based vendor assessments
  • Provide guidance to Business Units on TPRM governance requirements
  • Contribute to the quarterly reporting process on third-party risk profiles
  • Assist in deploying new tools for third-party monitoring
  • Address non-financial risk regulatory inquiries and support best practices development
  • Facilitate end-to-end incident reporting and track corrective actions

Benefits

  • Hybrid work model (2-3 days in office)
  • Opportunities for professional development and certifications in risk management
  • Collaborative environment with cross-functional teams
  • Chance to influence key regulatory initiatives in the financial sector
Full Job Description
Join a pivotal second-line position at the heart of Canada's financial market infrastructure. As a Senior Analyst, Enterprise Risk Management, you will support the delivery of the Enterprise Risk Management (ERM) and Operational Resilience programs across the Canadian Depository for Securities (CDS)-Canada's central securities depository, clearing, and settlement hub-and the Canadian Derivatives Clearing Corporation (CDCC)-the national central counterparty for exchange-traded and over-the-counter derivatives-collectively known as "TMX Post-Trade." You will play a vital role in safeguarding the organization by proactively identifying, assessing, and mitigating significant non-financial risks across complex vendor and regulatory landscapes. This position carries a primary focus on advancing the Third-Party Risk Management (TPRM) program through comprehensive risk assessments and continuous framework evolution, while driving critical regulatory initiatives and facilitating end-to-end incident reporting. This role reports to: Manager, Enterprise Risk Management & Non-Financial Resilience Job Location: Hybrid (2-3 days in office) - we are open to candidates being located in one of our Canadian office locations: Toronto or Montreal. Key Responsibilities: Third Party Risk Management (TPRM) 3 Support the Manager, ERM in developing and maintaining the TPRM governance framework, ensuring alignment with CDCC and CDS risk appetite. 3 Support the efficient and effective implementation of the TPRM program across CDCC and CDS, including performing materiality assessment and risk-based due diligence on vendors onboarded as part of new business initiatives and BAU. 3 Provide guidance and training to Business Units on the requirements and responsibilities included in the TPRM governance. 3 Contribute to the preparation and delivery of the quarterly reporting process on the third-party risk profile. 3 Assist in the deployment and application of new tools to automate and optimize third-party monitoring and reporting processes. 3 Support the Manager, ERM in driving continuous improvement of Post-Trade's TPRM program by analyzing industry trends and benchmarking against evolving global regulations (i.e. DORA), operational resilience and regulatory compliance. Regulatory Initiatives & Reviews 3 Support the Manager, ERM in addressing non-financial risk regulatory inquiries related to regulatory initiatives and reviews. 3 Support the Manager, ERM in developing and implementing emerging best practices that align with both regulatory requirements and broader industry standards. 3 Support the Manager, ERM in monitoring and analyzing internal and external environments to identify emerging risks that may impact TMX Post-Trade's strategic objectives and risk profile, and report to senior management. Incident Reporting 3 Facilitate the end-to-end incident reporting process, ensuring risk events are accurately documented, tracked, and escalated in a timely manner. 3 Support root cause analyses of identified incidents and partnering with business units to track the implementation of corrective action plans. Collaborative Opportunities Across Enterprise Risk Management Programs: While the primary focus is on Third Party Risk Management (TPRM) and Regulatory Initiatives & Reviews, there may be opportunities to contribute in a supportive role to initiatives within: 3 Operational Risk Management (ORM): Support risk assessment and oversight for operational activities. Monitor key risk indicators, and analyze operational risk data to identify trends and inform strategic decisions. 3 Change Management Risk Evaluation (CMRE): Support the identification, assessment, and oversight of the overall risk profile associated with significant changes and projects. Monitor adherence to change procedures and facilitate post-implementation reviews. 3 Cyber Risk Management: Collaborate with the Information Security Office to track cyber threats, cyber incidents, and remediation efforts. Assist in embedding cyber risk considerations into broader risk programs and contribute to executive cybersecurity reporting. 3 Business Continuity Management: Coordinate and maintain Business Impact Analyses (BIA) and Business Continuity Plans (BCP). Provide training and oversight for Disaster Recovery (DR) and BCP testing. Must haves: 3 Education: Bachelor's degree in Finance, Business Administration, or a related field (Master's degree preferred). 3 Experience: Minimum of 3 years of relevant experience in risk management, audit, or compliance functions within financial services or consulting firms. 3 Core Risk Expertise: Proven track record delivering ERM/ORM projects, including Operational Resilience, Risk Appetite, Third-Party Risk Management, Internal Controls, Business Continuity Management, Crisis Management, and Cybersecurity concepts. 3 Domain Knowledge: Solid understanding of financial institutions, market infrastructures, and financial markets. 3 Communication Skills: Exceptional written and verbal communication skills, with the ability to articulate complex risk concepts clearly and concisely to diverse audiences. 3 Execution & Ownership: Proven ability to work independently across multi-stakeholder environments, manage competing priorities effectively, and drive deliverables to completion with a proactive, results-oriented approach. Nice to Haves: 3 Certifications: Professional designations in Operational Risk Management, Business Continuity Management, Third-Party Risk Management, and/or Cyber Risk Management (e.g., ORM, CBCP, MBCI). 3 Regulatory Familiarity: Knowledge of key regulatory frameworks (e.g., CPMI-IOSCO Principles for FMIs, OSFI B-10, etc.). 3 Language Skills: Fluency in both French and English (written and spoken) is an asset to support regular interaction with bilingual partners and stakeholders. Salary Range: 85K/year - 90K/year CAD. Please note that the salary range included is a guideline only. The salary offered may vary based on factors, including, but not limited to, the successful candidate's relevant knowledge, skills, and experience. The recruiting efforts for this role are intended to fill a vacant position.

Similar Jobs

More Jobs at Montreal Exchange

More Finance & Insurance Jobs

Find similar Senior Analyst, Enterprise Risk Management (Third-Party Risk & Regulatory Initiative Focus) jobs: