We’re looking for a senior operational risk person to join our team. Initially, this is going to be a part-time role but we’d love for it to become a full-time role, depending on the need and fit. We take bringing on new team members very seriously. We’re a small and close-knit team, and fit is just as important as experience. We’d be lying if we said that “can we just handle the work ourselves” isn’t something that was brought up (multiple times). You’re reading this posting because we need a very capable human, and maybe that’s you.
While we know many great folks, we’ve chosen to post this role publicly in the interest of widening the possible field to include candidates that we might not know personally. We have done it before and we lucked out!
What does the job actually entail?
We’re compliance and risk consultants. Our core areas of practice include:
- Anti-Money Laundering (AML), Anti-Terrorist Financing (ATF)
- Canadian Sanctions
- Privacy
- Regulatory Compliance
- Operational Risk Management (including Retail Payment Compliance)
- Pan-Canadian Trust Framework (PCTF)
Most of the companies that we work with are AML reporting entities (banks, credit unions, money services businesses, securities dealers, dealers in precious metals and precious stones, real estate brokerages, etc.). Our work is generally project-based, and those projects include:
- Developing and updating compliance and risk policies and procedures;
- Developing risk assessments;
- Designing and delivering training;
- Conducting effectiveness reviews/audits;
- Helping clients to prepare for reviews and regulatory examinations;
- Helping clients to remediate review and regulatory examination findings; and
- Helping clients with compliance-related questions.
The person we are looking for would be responsible for the following:
- Design, document, and improve policies, procedures, and internal control frameworks to meet regulatory expectations and industry best practices.
- Advise clients on compliance with operational risk management requirements (RPAA and OSFI E-21). This includes third-party risk, incident response, fraud business continuity and safeguarding requirements.
- Support the development and implementation of operational risk management frameworks, governance structures, and reporting mechanisms.
- Guide clients through compliance with the RPAA, including registration, risk management frameworks, incident reporting, and safeguarding of end-user funds.
- Lead operational risk assessments, control reviews, and gap analyses across client operations, with a focus on payment service providers and fintechs.
- Provide guidance on privacy and data governance issues, including compliance with PIPEDA and other applicable provincial privacy legislation.
- Monitor emerging regulatory changes and industry developments to inform clients and update risk frameworks accordingly.
- Liaise with client legal, compliance and risk teams as needed on matters related to risk, compliance, and governance.
To do this effectively, we believe that you need to have deep, hands-on experience in these areas. This is why all of our team members have over 10,000 hours of in-house compliance experience. This is non-negotiable. Additionally, we are looking for the following qualifications:
- Deep knowledge of operational risk frameworks, including proven experience implementing or assessing operational risk programs in line with it.
- Strong working knowledge of Canadian privacy laws and their application to operational and data risk.
- Experience developing and implementing risk and compliance frameworks, including for third-party/vendor risk, incident response, and operational resilience.
- Excellent communication skills, with the ability to explain complex regulatory concepts to stakeholders at all levels.
- Strong writing skills for client deliverables, policies, and presentations.
- Proficient knowledge of Microsoft Office (Word, Excel, Powerpoint, etc).
Additionally, if you have any of the below it is a definite asset:
- Experience advising or working with PSPs, MSBs and/or fintechs.
- Experience with developing and or updating AML policies and procedures.
- Experience with conducting AML effectiveness reviews.
- Designing and delivering training.
- Experience and/or knowledge of the Pan-Canadian Trust Framework (PCTF).
- Prior experience engaging directly with Canadian regulators.
- Relevant certifications (i.e. RIMS CRM CIPP/C, CRISC, FRM, CIA). and
- Bilingualism (English/French) is a plus but not required.
What it’s like working at Outlier
We think our team is pretty great: professional, friendly, and incredibly nerdy. At first, we might seem intimidating, or even a little cliquey, but we’ll do everything we can to bring you into the fold. That said, you’ll need to identify and ask for what you need. Autonomy is a big part of how we work.
No two days are the same. We work on different projects that move at different paces, and sometimes things get hectic — it can be stressful. You’ll need to be comfortable providing your own structure and managing your schedule, while keeping in mind the needs of the business and our clients. As long as the desired outcomes are delivered on time, you can work at your own pace and from your own location. Most of our work is done remotely, though occasionally we may need to be on site with clients. We also have an office in downtown Toronto for when the need arises (and you’re welcome to work from that location whenever you like).
Our clients are professionals, entrepreneurs, and thought leaders. They’re smart, driven, and often push boundaries and ways of thinking, which means we’re constantly learning from them as well as answering their questions. They won’t always be compliance-minded, but the conversations are rarely boring. It’s often an absolutely incredible journey.
Our compensation model is radically transparent and tied to individual performance. Consultants earn a share of the revenue from each project they’re part of. These are democratic decisions, visible to the entire team, which helps ensure fairness. We know that openly discussing compensation can feel awkward at first — we try to approach it with empathy and openness.
Some things that we think are probably true about the right candidate
- You’re really good at what you do, but you are never satisfied.
- Every time you’ve left a job, they’ve had to hire several people to replace you. You try not to gloat about this too much, but sometimes you can’t help it.
- When put in charge of a well-functioning system, you’re likely to test “process improvements” until something breaks.
- You’re at your very best when you’re fixing something broken or building something new – those challenges invigorate you.
- When a business person tells you what they want to build, you immediately start thinking about how to execute their ideas within the parameters of existing law and regulation.
- The phrase “that’s the way we’ve always done it” makes you either shudder or clench your jaw (maybe both).
- In your spare time, you probably deconstruct, make or build things.
Want to apply?
Send an email with your resume attached in PDF format to: ninjas@outliercanada.com by July 14, 2025.
The subject line should read: Risk Ninja, 2025
In the body of the email, please indicate why you believe that you would be a good fit, referencing this posting, as well as where you clocked your 10,000 hours of in-house compliance practice. Please feel free to include any questions that you have for us at the outset as well.
Please note that messages submitted in any other format via any other channels will not be considered. Only applicants selected for an interview will be contacted. A reminder, only Canadian citizens need apply.
