GRC CareersConnecting Talent and Trust. Post a Job Log in

JobsCaliforniaNewport BeachThird Party Risk Management Analyst

Third Party Risk Management Analyst

Pacific Life
Third-Party RiskHybridFull-timeNewport Beach, CA$113,490 - $138,710

Pacific Life is hiring for the role of Third Party Risk Management Analyst, Newport Beach, CA (Hybrid). This is a Third-Party Risk role in the governance, risk, and compliance field, with a posted range of $113,490 - $138,710. Review the full details below and apply directly with Pacific Life.

Organization: Pacific LifeLocation: Newport Beach, CAWorkplace: HybridFocus: Third-Party RiskSalary: $113,490 - $138,710Posted: Jul 30, 2026
Pacific Life is hiring for this Third-Party Risk role in Newport Beach, one of the metros GRC Careers tracks for governance, risk, and compliance hiring. See other GRC roles in Newport Beach →

Job Description: The Third Party Risk Management (TPRM) Analyst is a senior individual contributor responsible for governing and overseeing Pacific Life’s enterprise TPRM program within the 2nd line of defense, with clear accountability for the design, maintenance, and enforcement of policies, standards, and control frameworks. This role ensures robust cybersecurity, resilience, and third party due diligence practices are consistently applied and aligned with regulatory expectations, while driving continuous enhancement of governance structures supporting third party outsourcing risk. This is a hybrid role (4 days per week onsite) in our Newport Beach, CA office. Operating with a high degree of autonomy, the TPRM Analyst leverages deep subject matter expertise to oversee risk assessment, due diligence, and ongoing monitoring activities, with particular emphasis on cybersecurity controls, data protection, and critical vendor dependencies. The role partners closely with procurement, legal, information security, and business leaders to ensure risks across third and fourth party relationships are appropriately identified, governed, and mitigated. As a trusted advisor, this role provides independent challenge and oversight to the first line of defense, ensuring adherence to established policies and control expectations while managing complex deliverables end-to-end. The position operates with minimal supervision within a team of approximately 35 professionals in Operational Risk & Resilience, part of Enterprise Risk Management, and collaborates closely with Service Owners, Service Managers, Service Leads, Capability Leads, and OR&R liaisons supporting effective first line execution. How you will make an impact: Govern and enforce adherence to TPRM policies, standards, and control frameworks across the enterprise Ensure alignment with applicable regulatory expectations (e.g., NAIC, state DOI) and industry standards (e.g., NIST, ISO, Shared Assessments) Oversee and challenge third party due diligence reviews that span cybersecurity, data privacy, business continuity, financial, and operational risk elements Partner with the 1st line of defense to identify control gaps, assess residual risk, and ensure timely development and execution of risk treatment plans Escalate material risks, control deficiencies, and vendor issues through established governance and risk committee structures Develop and deliver executive and committee level reporting on third party risk exposure, trends, and emerging third party risks Serve as a trusted advisor to the business while providing effective 2nd line challenge to ensure appropriate risk based decisions Leverage industry best practices and external insights to strengthen governance, oversight, and program maturity The experience you will bring: Bachelor’s degree or equivalent professional experience Minimum 5+ years of experience in third-party risk management, operational risk, information security risk, or related GRC disciplines In-depth knowledge of TPRM frameworks, lifecycle practices, and regulatory expectations Strong understanding of interconnected risk domains (cybersecurity, privacy, business continuity, and vendor operational risk) Proven ability to solve complex problems using both conceptual and practical approaches Demonstrated ability to operate independently with minimal guidance and sound judgment Experience in financial services, preferably life insurance or annuities Familiarity with industry frameworks and standards (e.g., NIST CSF, ISO 27001/22301, Shared Assessments SIG/VRMMM) Relevant professional certifications (e.g., CRVPM, CISA, CRISC, CISSP, CTPRP) and experience with TPRM platforms/continuous monitoring tools Strong competencies in analytical thinking, stakeholder influence, communication, and driving continuous improvement5+ years of relevant experience in business resilience, business continuity, or operational resilience What will make you stand out: Demonstrated governance mindset, with proven ownership of TPRM policies, standards, and control frameworks, and ability to enforce consistent adherence across the enterprise Bring deep expertise in cybersecurity due diligence and third party risk domains, with the ability to independently challenge assessments and drive risk informed decisions Operate as a highly credible second line advisor, effectively balancing partnership with the business while delivering objective challenge and oversight Proven track record of enhancing program maturity, including implementing scalable monitoring, improving control effectiveness, and aligning to evolving regulatory expectations Excel at translating complex risk insights into clear, executive-level reporting and actionable recommendations for senior leadership and risk committees #LI-KP1 Base Pay Range: The base pay range noted represents the company’s good faith minimum and maximum range for this role at the time of posting. The actual compensation offered to a candidate will be dependent upon several factors, including but not limited to experience, qualifications and geographic location. Also, most employees are eligible for additional incentive pay. $113,490.00 - $138,710.00 Your Benefits Start Day 1 Your wellbeing is important to Pacific Life, and we’re committed to providing you with flexible benefits that you can tailor to meet your needs. Whether you are focusing on your physical, financial, emotional, or social wellbeing, we’ve got you covered. Prioritization of your health and well-being including Medical, Dental, Vision, and Wellbeing Reimbursement Account that can be used on yourself or your eligible dependents Generous paid time off options including: Paid Time Off, Holiday Schedules, and Financial Planning Time Off Paid Parental Leave as well as an Adoption Assistance Program Competitive 401k savings plan with company match and an additional contribution regardless of participation You Can Be Who You Are We are committed to a

Location and market context

This role is based in Newport Beach on-site. Local candidates benefit from being close to Pacific Life's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.

About third-party risk roles

Third-party and vendor risk teams assess and monitor the security, privacy, and compliance posture of suppliers, an area under sharp regulatory and operational focus as AI vendors proliferate. Roles like this one are typically evaluated against frameworks such as third-party risk frameworks, SOC 2, ISO/IEC 27001, and vendor due-diligence and monitoring practices.

How to position yourself for this third-party risk role

Strong candidates emphasize vendor due diligence and assessment, ongoing monitoring, contract and control requirements, and coordinating across security, privacy, and procurement. In your resume and outreach, tie your experience to how Pacific Life would apply third-party risk frameworks, SOC 2, ISO/IEC 27001, and vendor due-diligence and monitoring practices, and lead with concrete outcomes rather than duties.

Similar GRC roles

Employer, or see something wrong with this posting? Report this posting and we will review it promptly.