Royal Bank of Canada

Senior Director, Vendor IT Risk Management (Global Security)

Royal Bank of Canada$150K — $180K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years experience in cyber security and third party IT risk management at senior management level.
  • Expertise in assessing complex risk trade-offs among vendor criticality, data availability, and control adequacy.
  • Proficient in conducting SOC reviews and mergers & acquisitions IT risk assessments.
  • Experience in transforming third-party supply chain management from reactive to proactive models using AI.
  • Deep knowledge of Cyber Security Frameworks (NIST, ISO 27001) and third-party risk assessment methodologies.
  • Proven capability in developing risk presentations and reports for executive stakeholders.
  • Exceptional interpersonal skills to influence and work collaboratively with senior leaders.

Responsibilities

  • Lead the management and evolution of third party IT risk practices within Global Cyber Security.
  • Conduct comprehensive risk assessments for technology-related supplier engagements.
  • Drive the development of centralized standards for third-party risk management across the enterprise.
  • Create risk summaries, KPIs, and presentations for senior management and Board committees.
  • Establish and maintain risk assessment frameworks in cybersecurity and data protection.
  • Provide strategic advisory support to Supplier Management Offices across business units.
  • Leverage AI and advanced analytics to enhance third party risk capabilities.

Benefits

  • Comprehensive Total Rewards Program including bonuses and flexible benefits.
  • Support for personal development through coaching and management opportunities.
  • Possibility to make a meaningful impact within the organization.
  • Work within a dynamic and high-performing team environment.
  • Access to challenging work and increased accountability opportunities.
  • Variety of job opportunities available across the business.
Full Job Description
Job Description

What is the opportunity?

The Senior Director, Vendor IT Risk Management (Global Security) is a strategic leadership position responsible for driving the management and evolution of core third party IT risk practices at RBC. This role sits within the Global Cyber Security (GCS) Global IT Risk team and focuses on identifying, assessing, and advising on risks resulting from RBC's third-party supply chain management engagements, considering safety, soundness, resiliency, risk, and compliance to RBC practices, policies, and guidelines.

As Senior Director, you will lead a team of direct reports and indirect reports and manage the enterprise-wide third-party supply chain management assessment program that covers all technology-related supplier engagements across RBC. You will serve as a subject matter expert in third party supply chain management risk and partner with other RBC risk teams, senior leadership, and staff to drive change and effectively manage risks in an open, collaborative environment to further mature the business risk culture.

The is responsible for transforming third party IT Risk practices to be more proactive, leveraging new technologies including Artificial Intelligence to enhance third party IT risk due diligence capabilities and increase coverage of suppliers while gaining insights to ensure risks are effectively identified.

What will you do?
  • Core Third Party Supply Chain Management & IT Risk Management- Contract Reviews: Participate in contract reviews to ensure appropriate IT risk-related clauses exist that support the organization's right to review/audit the security practices of its third parties
  • SOC Reviews: Participate in SOC (Qualified Opinion) reviews as required and provide appropriate guidance to risk owners on control effectiveness and risk implications
  • M&A IT Risk Assessments: Complete comprehensive IT risk assessments for mergers and acquisitions, evaluating technology risks, integration challenges, and control environments
  • Define and advance third-party risk management maturity across the enterprise, establishing centralized standards while adapting to emerging risks and evolving organizational capabilities
  • Third Party Reporting and Analytics: Assist with the creation of third-party presentations, KRIs, KPIs and associated materials, and risk summaries for senior management and Board committees
  • Third Party Control Assessments & Continuous Monitoring- Lead the enterprise-wide third-party control assessment program for all technology-related supplier engagements across RBC
  • Establish and maintain standardized assessment frameworks covering cybersecurity, data protection, operational resilience, and technology governance domains
  • Advisory Services to Supplier Management Offices (SMOs)- Provide strategic third-party supply chain management advisory support to internal Supplier Management Offices across all business units and functions
  • Develop risk guidance, best practices, and decision-making frameworks that enable SMOs to make informed supplier selection and management decisions
  • Partner with SMOs on contract negotiations to ensure appropriate risk management clauses and control requirements are incorporated
  • Process Development & Tools Enhancement- Leverage Artificial Intelligence and advanced analytics to increase supplier coverage, automate risk scoring, and generate predictive insights
  • Design and deploy data-driven risk identification capabilities that enable proactive risk management and early warning systems
  • Manage complex stakeholder relationships across business units, including Procurement, GCS Teams, GRM Cyber and Technology Risk, Compliance, Legal, Privacy, BCM, Third Party Risk, SMO, and Lines of Business
  • Provide support, expertise, feedback, coaching, and development to build the capability of more junior staff, and promote a mindset for sustained success, growth, and diversity within the team


What do you need to succeed?

Must have:

  • 10+ years of experience in cyber security/third party IT risk with demonstrated progression to senior management roles, highly skilled at managing vendor/supplier relationships and service delivery partnerships
  • Highly skilled at navigating complex risk trade-offs-including vendor criticality assessment, data availability challenges, model risk, and control adequacy determinations-while balancing risk protection with business enablement
  • 10+ years of cyber security, data protection, operational resilience, and technology governance
  • 10+ years executing transformation initiatives that evolve third-party supply chain management practices from reactive to proactive models. With experience implementing AI and advanced analytics in risk management, to enable teams through technological and process innovation while sustaining operational excellence
  • SOC Reviews & Risk Assessments: 10+ years of experience conducting SOC reviews and comprehensive IT risk assessments for mergers and acquisitions, with demonstrated ability to evaluate technology risks, integration challenges, and control environments while providing strategic guidance to risk owners on control effectiveness and risk implications
  • Third-Party Risk Reporting & Executive Communication: 10+ years of experience developing third-party risk presentations, KRIs, KPIs, and risk summaries for senior management and Board committees, with proven ability to translate complex risk data into actionable intelligence for executive stakeholders
  • Deep experience with Cyber Security Frameworks - NIST, ISO 27001, with comprehensive knowledge of third-party risk assessment methodologies, control frameworks, and industry standards
  • Exceptional ability to influence and collaborate with senior leaders, business partners, and external stakeholders


Nice to have:
  • ISACA approved certifications together with other cyber security bodies or technical qualifications (CISSP preferred)
  • Experience with AI implementation in risk management domains
  • Advanced education in business, risk management, technology, or related field

What's in it for you?

We thrive on the challenge to be our best, progressive thinking to keep growing, and working together to deliver trusted advice to help our clients thrive and communities prosper. We care about each other, reaching our potential, making a difference to our communities, and achieving success that is mutual.
  • A comprehensive Total Rewards Program including bonuses and flexible benefits, competitive compensation, commissions, and stock where applicable
  • Leaders who support your development through coaching and managing opportunities
  • Ability to make a difference and lasting impact
  • Work in a dynamic, collaborative, progressive, and high-performing team
  • Opportunities to do challenging work
  • Opportunities to take on progressively greater accountabilities
  • Access to a variety of job opportunities across business


#LI-POST
#TechPJ

Job Skills
Business Analytics, Decision Making, Financial Risk Management (FRM), Operational Delivery, Quality Management, Results-Oriented, Risk Management, Strategic Thinking

Additional Job Details

Address:

16 YORK ST:TORONTO

City:

Toronto

Country:

Canada

Work hours/week:

37.5

Employment Type:

Full time

Platform:

TECHNOLOGY AND OPERATIONS

Job Type:

Regular

Pay Type:

Salaried

Posted Date:

2026-07-13

Application Deadline:

2026-08-04
Note: Applications will be accepted until 11:59 PM on the day prior to the application deadline date above

About Royal Bank of Canada

Royal Bank of Canada Careers

Join the dynamic team at Royal Bank of Canada (RBC), a global leader in financial services and a company committed to excellence and innovation. At RBC, we offer a wide range of job opportunities that empower professionals to shape their career paths with leadership, diversity training, and continuous growth.

Work You’ll Do

At Royal Bank of Canada, we are not just hiring; we are building a culture of innovation and leadership. Our team members are at the forefront of the financial industry, driving transformation and delivering targeted solutions that meet the evolving needs of our clients and communities.

Explore Job Opportunities and Employment at RBC

Whether you are starting your career or looking to take it to the next level, RBC offers positions that challenge your skills and fuel your ambition. From entry-level positions to leadership roles, our job opportunities span across various functions and regions. Join us and be part of a team that values professional growth and diversity.

Internship and Professional Development

Kickstart your career with an internship at Royal Bank of Canada. Our internships provide invaluable hands-on experience, networking opportunities, and insights into the financial services industry. Interns at RBC gain the skills necessary to excel and are often considered for full-time positions within the company.

Benefits and Culture

At RBC, we prioritize the well-being and satisfaction of our employees. Our benefits package is designed to support our team members at every stage of their life and career. RBC’s culture is built on a foundation of respect, integrity, and responsibility, fostering an environment where everyone can thrive.

Career Growth and Innovation

We believe in nurturing the potential of our employees through continuous learning and career development programs. At RBC, you will find endless opportunities to grow professionally through on-the-job experiences, formal training programs, and leadership development initiatives. Our commitment to innovation means we are constantly seeking out new ideas and perspectives, making RBC a perfect place for those who aim to lead and innovate.

Diversity and Inclusion

Diversity is our strength. At Royal Bank of Canada, we are committed to building an inclusive workplace where every employee feels valued and respected. Our diversity training programs are designed to educate and inspire, creating a more inclusive and equitable workplace.

Join Our Team

Search open positions that match your skills and interests. We look for passionate, curious, creative, and solution-driven team players. Start your journey with RBC today and be part of a world-class team known for its commitment to client service, community involvement, and innovation.

Stay Connected

Keep up to date with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work here at Royal Bank of Canada.

Job Alert Emails

Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding career opportunities awaiting you at RBC. Explore the possibilities with Royal Bank of Canada, where your future is filled with potential and the path to success is paved with countless opportunities for professional and personal growth. Join us and shape not just your career but the future of the financial industry.
Learn more about Royal Bank of Canada
Size
86,007 employees
Market Cap
$130.3 billion
Industry
5 Year Trend
+8.7%
NASDAQ

Similar Jobs

More Jobs at Royal Bank of Canada

More Information Technology Jobs

Find similar Senior Director, Vendor IT Risk Management (Global Security) jobs: