Senior Manager, Procurement Vendor Risk & Governance
The Senior Manager, Procurement Vendor Risk & Governance is responsible for leading key elements of the Company's Third-Party Risk Management (TPRM) and governance program. This role provides strategic leadership, oversight, and effective challenge to ensure procurement-managed third parties are governed in accordance with internal standards, regulatory requirements, and enterprise risk management expectations.
The incumbent serves as a senior subject matter expert in Third-Party Risk Management and Operational Risk Management, providing guidance on governance frameworks, risk assessments, ongoing monitoring, regulatory compliance, operational resilience, and risk reporting.
The role partners closely with Business Units, Procurement, Operational Risk, Compliance, Legal, Information Security, and Audit functions to strengthen third-party risk oversight and drive continuous improvement of governance practices. The incumbent is accountable for the development and delivery of governance processes, reporting, metrics, training, executive communications, quality assurance, and regulatory engagement activities.
The role also leads the Procurement Governance Quality Assurance (QA) Program, providing independent review and challenge of governance activities to promote consistency, regulatory compliance, control effectiveness, and continuous improvement across procurement-managed third-party risk processes.
Position Responsibilities
- Lead the execution and continuous enhancement of the Third-Party Risk Management and Vendor Governance framework, ensuring alignment with regulatory requirements and enterprise risk management practices.
- Provide leadership and oversight of third-party risk governance activities across the third-party lifecycle, including onboarding, ongoing monitoring, issue management, and offboarding.
- Serve as a senior subject matter expert on third-party risk, operational risk, outsourcing risk, and regulatory requirements, providing guidance and effective challenge to stakeholders and business partners.
- Lead the development, implementation, and maintenance of governance policies, standards, procedures, methodologies, and tools supporting third-party risk management.
- Define, monitor, and report key risk indicators (KRIs), key performance indicators (KPIs), control effectiveness metrics, and governance outcomes to senior leadership, executive committees, and risk governance forums.
- Lead preparation and coordination of responses to regulatory reviews, examinations, internal audits, external audits, operational risk assessments, and compliance reviews.
- Partner with Operational Risk, Compliance, Legal, Technology Risk, Privacy, Information Security, Procurement, and business stakeholders to support effective risk management and governance decision-making.
- Analyze emerging risks, industry trends, regulatory developments, and evolving third-party risk practices and recommend enhancements to governance processes and controls.
- Oversee the development of executive and Board-level reporting, providing meaningful insights into third-party risk exposure, risk trends, remediation activities, and program effectiveness.
- Drive continuous improvement initiatives, including process optimization, automation, data analytics, governance transformation, and operational effectiveness enhancements.
- Support and mentor team members, fostering a culture of risk awareness, accountability, continuous improvement, and professional development.
- Participate in strategic planning activities and contribute to the evolution of the global third-party risk and governance operating model.
- Lead the Procurement Governance Quality Assurance (QA) Program, including the execution of risk-based quality reviews across third-party risk assessments, due diligence, ongoing monitoring, governance decisions, and lifecycle controls. Monitor adherence to policies, standards, procedures, and regulatory requirements; identify trends and improvement opportunities; provide reporting and insights to leadership; and drive remediation activities to strengthen governance effectiveness, consistency, and control quality.
- Lead, develop, and coach a team of risk and governance professionals, providing performance management, talent development, succession planning, workforce planning, and day-to-day leadership. Foster a culture of accountability, innovation, continuous improvement, and operational excellence while ensuring successful delivery of strategic and operational objectives.
Required Qualifications
- Undergraduate degree in Business, Finance, Risk Management, Accounting, Technology, Law, or a related discipline.
- 8+ years of progressive experience in Third-Party Risk Management, Vendor Governance, Operational Risk, Enterprise Risk, Compliance, Audit, Procurement, or related functions.
- Strong understanding of third-party risk management frameworks, outsourcing risk management, operational risk principles, regulatory expectations, and governance best practices.
- Demonstrated knowledge of risk assessment methodologies, risk reporting, governance practices, quality assurance programs, and control frameworks.
- Experience designing, implementing, or leading Quality Assurance (QA), Quality Control (QC), operational risk testing, compliance testing, or governance review programs.
- Strong understanding of control effectiveness reviews, root cause analysis, issue remediation, and continuous improvement methodologies.
- Experience supporting regulatory examinations, audits, issue management, corrective action plans, and governance committees.
- Strong analytical capabilities with the ability to interpret complex data and communicate meaningful insights to senior stakeholders.
- Proven ability to influence decisions and build productive relationships across business, risk, and control functions.
- Experience developing executive and Board-level reporting and presentations.
- Strong communication, stakeholder management, and leadership skills.
- Ability to lead cross-functional initiatives, manage competing priorities, and operate effectively in a complex global environment.
- Professional certifications such as CRISC, CISA, CISSP, ORM, CPA, or equivalent are considered an asset.
Leadership Competencies
- Strategic thinker with the ability to connect risk management activities to broader business objectives.
- Demonstrates strong judgment and sound decision-making in complex and ambiguous situations.
- Leads with accountability, integrity, and a strong risk-based mindset.
- Influences without authority and effectively challenges stakeholders when required.
- Builds high-performing teams and develops talent.
- Champions innovation, process improvement, and operational excellence.
- Communicates complexity with clarity to executive audiences.
- Promotes a culture of quality, continuous improvement, and strong governance practices.
When you join our team:
We’ll empower you to learn and grow the career you want.
We’ll recognize and support you in a flexible environment where well-being and inclusion are more than just words.
As part of our global team, we’ll support you in shaping the future you want to see.
The role being advertised is an existing vacancy.
About Manulife and John Hancock
Manulife Financial Corporation is a leading international financial services provider, helping people make their decisions easier and lives better. To learn more about us, visit .
Manulife is an Equal Opportunity Employer
At Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.
It is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process, contact hr@manulife.com.
Referenced Salary Location
Toronto, OntarioWorking Arrangement
Salary range is expected to be between
$92,900.00 CAD - $142,900.00 CADEmployees also have the opportunity to participate in incentive programs and earn incentive compensation tied to business and individual performance. The actual salary will vary depending on local market conditions, geography and relevant job-related factors such as knowledge, skills, qualifications, experience, and education/training. If you are applying for this role outside of the primary location, please contact hr@manulife.com for the salary range for your location.
Manulife offers eligible employees a wide array of customizable benefits, including health, dental, mental health, vision, short- and long-term disability, life and AD&D insurance coverage, adoption/surrogacy and wellness benefits, and employee/family assistance plans. We also offer eligible employees various retirement savings plans (including pension and a global share ownership plan with employer matching contributions) and financial education and counseling resources. Our generous paid time off program in Canada includes holidays, vacation, personal, and sick days, and we offer the full range of statutory leaves of absence. If you are applying for this role in the U.S., please contact hr@manulife.com for more information about U.S.-specific paid time off provisions.
We use data and analytics technologies, such as artificial intelligence (AI), and automated processing tools, to analyze and process the information you provide to us or third parties in the application process. For more information, please refer to our personal information collection statement.