Jobs › Third Party Risk Management Analyst
Third Party Risk Management Analyst
Job at a glance
- Category
- GRC
- Work arrangement
- Hybrid
- Location
- Newport Beach, CA
- Salary range
- $113,490 to $138,710
- Posted
- Jul 30, 2026
Free. One click to unsubscribe. We never share your address.
Pacific Life is hiring a Third Party Risk Management Analyst in Newport Beach, CA. This is a GRC job in the governance, risk, and compliance field, with a posted range of $113,490 to $138,710. Review the full details below and apply directly with Pacific Life.
Job Description: The Third Party Risk Management (TPRM) Analyst is a senior individual contributor responsible for governing and overseeing Pacific Life’s enterprise TPRM program within the 2nd line of defense, with clear accountability for the design, maintenance, and enforcement of policies, standards, and control frameworks. This role ensures robust cybersecurity, resilience, and third party due diligence practices are consistently applied and aligned with regulatory expectations, while driving continuous enhancement of governance structures supporting third party outsourcing risk. This is a hybrid role (4 days per week onsite) in our Newport Beach, CA office. Operating with a high degree of autonomy, the TPRM Analyst leverages deep subject matter expertise to oversee risk assessment, due diligence, and ongoing monitoring activities, with particular emphasis on cybersecurity controls, data protection, and critical vendor dependencies. The role partners closely with procurement, legal, information security, and business leaders to ensure risks across third and fourth party relationships are appropriately identified, governed, and mitigated. As a trusted advisor, this role provides independent challenge and oversight to the first line of defense, ensuring adherence to established policies and control expectations while managing complex deliverables end-to-end. The position operates with minimal supervision within a team of approximately 35 professionals in Operational Risk & Resilience, part of Enterprise Risk Management, and collaborates closely with Service Owners, Service Managers, Service Leads, Capability Leads, and OR&R liaisons supporting effective first line execution. How you will make an impact: Govern and enforce adherence to TPRM policies, standards, and control frameworks across the enterprise Ensure alignment with applicable regulatory expectations (e.g., NAIC, state DOI) and industry standards (e.g., NIST, ISO, Shared Assessments) Oversee and challenge third party due diligence reviews that span cybersecurity, data privacy, business continuity, financial, and operational risk elements Partner with the 1st line of defense to identify control gaps, assess residual risk, and ensure timely development and execution of risk treatment plans Escalate material risks, control deficiencies, and vendor issues through established governance and risk committee structures Develop and deliver executive and committee level reporting on third party risk
Full responsibilities and requirements are on Pacific Life's application page.
Apply for this job →Location and market context
This job is based in Newport Beach, CA on a hybrid schedule. Local candidates benefit from being close to Pacific Life's teams and regional hiring market, while the hybrid arrangement offers some flexibility. Confirm the exact in-office expectation and any relocation support with the employer.
About third-party risk jobs
Third-party and vendor risk teams assess and monitor the security, privacy, and compliance posture of suppliers, an area under sharp regulatory and operational focus as AI vendors proliferate. Jobs like this one are typically evaluated against frameworks such as third-party risk frameworks, SOC 2, ISO/IEC 27001, and vendor due-diligence and monitoring practices.
How to position yourself for this third-party risk job
Strong candidates emphasize vendor due diligence and assessment, ongoing monitoring, contract and control requirements, and coordinating across security, privacy, and procurement. In your resume and outreach, tie your experience to how Pacific Life would apply third-party risk frameworks, SOC 2, ISO/IEC 27001, and vendor due-diligence and monitoring practices, and lead with concrete outcomes rather than duties.
Similar GRC jobs
More GRC jobs: All GRC jobs · Search by category & location