Pacific Life Logo

Pacific Life

Third Party Risk Management Analyst

Reposted Yesterday
Be an Early Applicant
In-Office
Newport Beach, CA, USA
113K-139K Annually
Senior level
In-Office
Newport Beach, CA, USA
113K-139K Annually
Senior level
The TPRM Capability Lead oversees the TPRM program, ensuring governance, risk assessment, and compliance with policies and regulations, while partnering with various stakeholders to manage third party risks effectively.
The summary above was generated by AI

Job Description:

The Third Party Risk Management (TPRM) Analyst is a senior individual contributor responsible for governing and overseeing Pacific Life’s enterprise TPRM program within the 2nd line of defense, with clear accountability for the design, maintenance, and enforcement of policies, standards, and control frameworks. This role ensures robust cybersecurity, resilience, and third party due diligence practices are consistently applied and aligned with regulatory expectations, while driving continuous enhancement of governance structures supporting third party outsourcing risk. This is a hybrid role (4 days per week onsite) in our Newport Beach, CA office.

Operating with a high degree of autonomy, the TPRM Analyst leverages deep subject matter expertise to oversee risk assessment, due diligence, and ongoing monitoring activities, with particular emphasis on cybersecurity controls, data protection, and critical vendor dependencies. The role partners closely with procurement, legal, information security, and business leaders to ensure risks across third and fourth party relationships are appropriately identified, governed, and mitigated.

As a trusted advisor, this role provides independent challenge and oversight to the first line of defense, ensuring adherence to established policies and control expectations while managing complex deliverables end-to-end. The position operates with minimal supervision within a team of approximately 35 professionals in Operational Risk & Resilience, part of Enterprise Risk Management, and collaborates closely with Service Owners, Service Managers, Service Leads, Capability Leads, and OR&R liaisons supporting effective first line execution.

How you will make an impact:

  • Govern and enforce adherence to TPRM policies, standards, and control frameworks across the enterprise
  • Ensure alignment with applicable regulatory expectations (e.g., NAIC, state DOI) and industry standards (e.g., NIST, ISO, Shared Assessments)
  • Oversee and challenge third party due diligence reviews that span cybersecurity, data privacy, business continuity, financial, and operational risk elements
  • Partner with the 1st line of defense to identify control gaps, assess residual risk, and ensure timely development and execution of risk treatment plans
  • Escalate material risks, control deficiencies, and vendor issues through established governance and risk committee structures
  • Develop and deliver executive and committee level reporting on third party risk exposure, trends, and emerging third party risks
  • Serve as a trusted advisor to the business while providing effective 2nd line challenge to ensure appropriate risk based decisions
  • Leverage industry best practices and external insights to strengthen governance, oversight, and program maturity

The experience you will bring:

  • Bachelor’s degree or equivalent professional experience
  • Minimum 5+ years of experience in third-party risk management, operational risk, information security risk, or related GRC disciplines
  • In-depth knowledge of TPRM frameworks, lifecycle practices, and regulatory expectations
  • Strong understanding of interconnected risk domains (cybersecurity, privacy, business continuity, and vendor operational risk)
  • Proven ability to solve complex problems using both conceptual and practical approaches
  • Demonstrated ability to operate independently with minimal guidance and sound judgment
  • Experience in financial services, preferably life insurance or annuities
  • Familiarity with industry frameworks and standards (e.g., NIST CSF, ISO 27001/22301, Shared Assessments SIG/VRMMM)
  • Relevant professional certifications (e.g., CRVPM, CISA, CRISC, CISSP, CTPRP) and experience with TPRM platforms/continuous monitoring tools
  • Strong competencies in analytical thinking, stakeholder influence, communication, and driving continuous improvement5+ years of relevant experience in business resilience, business continuity, or operational resilience

What will make you stand out:

  • Demonstrated governance mindset, with proven ownership of TPRM policies, standards, and control frameworks, and ability to enforce consistent adherence across the enterprise
  • Bring deep expertise in cybersecurity due diligence and third party risk domains, with the ability to independently challenge assessments and drive risk informed decisions
  • Operate as a highly credible second line advisor, effectively balancing partnership with the business while delivering objective challenge and oversight
  • Proven track record of enhancing program maturity, including implementing scalable monitoring, improving control effectiveness, and aligning to evolving regulatory expectations
  • Excel at translating complex risk insights into clear, executive-level reporting and actionable recommendations for senior leadership and risk committees

#LI-KP1

Base Pay Range:

The base pay range noted represents the company’s good faith minimum and maximum range for this role at the time of posting. The actual compensation offered to a candidate will be dependent upon several factors, including but not limited to experience, qualifications and geographic location. Also, most employees are eligible for additional incentive pay.

$113,490.00 - $138,710.00

Your Benefits Start Day 1  
 

Your wellbeing is important to Pacific Life, and we’re committed to providing you with flexible benefits that you can tailor to meet your needs. Whether you are focusing on your physical, financial, emotional, or social wellbeing, we’ve got you covered.

  • Prioritization of your health and well-being including Medical, Dental, Vision, and Wellbeing Reimbursement Account that can be used on yourself or your eligible dependents

  • Generous paid time off options including: Paid Time Off, Holiday Schedules, and Financial Planning Time Off

  • Paid Parental Leave as well as an Adoption Assistance Program

  • Competitive 401k savings plan with company match and an additional contribution regardless of participation

You Can Be Who You Are

We are committed to a culture of diversity and inclusion that embraces the authenticity of all employees, partners and communities. We support all employees to thrive and achieve their fullest potential.

What’s life like at Pacific Life? Visit Instagram.com/lifeatpacificlife

EEO Statement:

Pacific Life Insurance Company is an Equal Opportunity /Affirmative Action Employer, M/F/D/V. If you are a qualified individual with a disability or a disabled veteran, you have the right to request an accommodation if you are unable or limited in your ability to use or access our career center as a result of your disability. To request an accommodation, contact a Human Resources Representative at Pacific Life Insurance Company.

HQ

Pacific Life Newport Beach, California, USA Office

700 Newport Center Drive, Newport Beach, CA, United States, 92660

Pacific Life Aliso Viejo, California, USA Office

45 Enterprise, Aliso Viejo, United States, 92656

Similar Jobs

5 Days Ago
Remote or Hybrid
USA
85K-120K Annually
Mid level
85K-120K Annually
Mid level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Manage and mature CrowdStrike's Third Party Risk Management program: develop policies, lead vendor security assessments across the lifecycle, prioritize and manage remediation, build dashboards and reports, partner with Procurement/Legal/IT, automate GRC workflows, monitor third-party threats, and deliver training to stakeholders.
Top Skills: Ai TechnologiesBitsightCrowdstrike ProductsCsa-CcmGdprGrcIso 27001Iso 27002Nist 800-53OnetrustPci-DssPenetration Testing Results ReviewProcessunitySbomSecurityscorecardServicenowSoc 1Soc 2Soc Reports ReviewTprm
5 Hours Ago
Remote or Hybrid
USA
130K-200K Annually
Senior level
130K-200K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Lead global brand media strategy end-to-end: strategy, agency management, creative partnership, experimentation, measurement, and budget ownership. Drive brand awareness via cross-functional collaboration, run brand health studies, analyze performance and scale effective channels.
Top Skills: AI
7 Hours Ago
Remote or Hybrid
USA
115K-160K Annually
Senior level
115K-160K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Conduct cloud-focused Red Team/Blue Team (CRTBT) engagements, emulating adversary TTPs against customer cloud environments, collaborate with client SOC/IR teams, manage engagements end-to-end, develop automation and tooling for adversary emulation, and recommend long-term enhancements to improve cloud detection and response.
Top Skills: AIAutomationAWSAzureCloud SecurityEndpoint SecurityGCPM365Microsoft Entra IdNetwork SecurityScriptingSocThreat IntelligenceTooling Development

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account