The Third Party Risk Management (TPRM) Analyst is a senior individual contributor responsible for governing and overseeing Pacific Life's enterprise TPRM program within the 2nd line of defense, with ...
The Third Party Risk Management (TPRM) Analyst is a senior individual contributor responsible for governing and overseeing Pacific Life's enterprise TPRM program within the 2nd line of defense, with ...
The Third Party Risk Management (TPRM) Analyst is a senior individual contributor responsible for governing and overseeing Pacific Life's enterprise TPRM program within the 2nd line of defense, with ...
The Third Party Risk Management (TPRM) Analyst is a senior individual contributor responsible for governing and overseeing Pacific Life's enterprise TPRM program within the 2nd line of defense, with ...
The Third Party Risk Management (TPRM) Analyst is a senior individual contributor responsible for governing and overseeing Pacific Life's enterprise TPRM program within the 2nd line of defense, with ...
The Third Party Risk Management (TPRM) Analyst is a senior individual contributor responsible for governing and overseeing Pacific Life's enterprise TPRM program within the 2nd line of defense, with ...
About the role Anthropic's Third Party Risk Management (TPRM) team sits within Security GRC and is ... analysis and treatment, and financial and solvency screening. On the Highest-Risk side that means ...
About the role Anthropic's Third Party Risk Management (TPRM) team sits within Security GRC and is ... analysis and treatment, and financial and solvency screening. On the Highest-Risk side that means ...
Senior Cybersecurity Risk Analyst - USA Remote
Sacramento, CA · Remote
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Senior Cybersecurity Risk Analyst - USA Remote
Sacramento, CA · Remote
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Senior Cybersecurity Risk Analyst - USA Remote
San Diego, CA · Remote
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Senior Cybersecurity Risk Analyst - USA Remote
San Diego, CA · Remote
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Senior Cybersecurity Risk Analyst - USA Remote
Los Angeles, CA · Remote
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Senior Cybersecurity Risk Analyst - USA Remote
Los Angeles, CA · Remote
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Senior Cybersecurity Risk Analyst - USA Remote
Orange, CA · Remote
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Senior Cybersecurity Risk Analyst - USA Remote
Orange, CA · Remote
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Third-Party / Vendor Risk Management (Primary Focus) * Design, implement, operate, and continuously ... impact analysis, and post incident follow-up. * Contribute to security awareness and training ...
Third-Party / Vendor Risk Management (Primary Focus) * Design, implement, operate, and continuously ... impact analysis, and post incident follow-up. * Contribute to security awareness and training ...
Product Mgr, Third-Party Risk Management
Santa Clara, CA · On-site +1
$108K - $148K/yr
Partner with analytics teams to build dashboards and actionable insights * Use data to drive ... Additional Information Time Type: Full time Employee Type: Assignee / Regular Travel: Yes, 20% of ...
Product Mgr, Third-Party Risk Management
Santa Clara, CA · On-site +1
$108K - $148K/yr
Partner with analytics teams to build dashboards and actionable insights * Use data to drive ... Additional Information Time Type: Full time Employee Type: Assignee / Regular Travel: Yes, 20% of ...
Third Party Risk Management and Customer Trust Lead
Foster City, CA · On-site
$210K - $270K/yr
You'll analyze SOC 2 documentation, security assessments, and system architectures to determine ... Full-Time Employee Benefits Include: Competitive Salary & Equity 401(k) Program with a 4% match (US ...
Third Party Risk Management and Customer Trust Lead
Foster City, CA · On-site
$210K - $270K/yr
You'll analyze SOC 2 documentation, security assessments, and system architectures to determine ... Full-Time Employee Benefits Include: Competitive Salary & Equity 401(k) Program with a 4% match (US ...
Enterprise Risk Management (ERM) Analyst
Folsom, CA · On-site
$110K - $120K/yr
Analyze vendor documentation, including SOC reports, financial statements, business continuity ... Track and report third-party risk metrics, KRIs, assessment results, and remediation activities to ...
Enterprise Risk Management (ERM) Analyst
Folsom, CA · On-site
$110K - $120K/yr
Analyze vendor documentation, including SOC reports, financial statements, business continuity ... Track and report third-party risk metrics, KRIs, assessment results, and remediation activities to ...
Enterprise Risk Management (ERM) Analyst
Folsom, CA · Hybrid
$110K - $120K/yr
Track and report third-party risk metrics, KRIs, assessment results, and remediation activities to ... Employment Type: Full-Time
Enterprise Risk Management (ERM) Analyst
Folsom, CA · Hybrid
$110K - $120K/yr
Track and report third-party risk metrics, KRIs, assessment results, and remediation activities to ... Employment Type: Full-Time
Enterprise Risk Management (ERM) Analyst
Folsom, CA · Hybrid
$110K - $120K/yr
Vendor Risk Management * Assist with third-party risk assessments and due diligence reviews for new ... Analyze vendor documentation, including SOC reports, financial statements, business continuity ...
Enterprise Risk Management (ERM) Analyst
Folsom, CA · Hybrid
$110K - $120K/yr
Vendor Risk Management * Assist with third-party risk assessments and due diligence reviews for new ... Analyze vendor documentation, including SOC reports, financial statements, business continuity ...
Analyze vendor documentation, including SOC reports, financial statements, business continuity ... Track and report third-party risk metrics, KRIs, assessment results, and remediation activities to ...
Quick apply
Analyze vendor documentation, including SOC reports, financial statements, business continuity ... Track and report third-party risk metrics, KRIs, assessment results, and remediation activities to ...
Risk Management Analyst
Sacramento, CA · On-site
Risk Management Analyst Location: Sacramento, CA Duration: 12 Months Minimum Skills: * Must ... Experience with audit processes and disciplines including third party risk management. * Working ...
Risk Management Analyst
Sacramento, CA · On-site
Risk Management Analyst Location: Sacramento, CA Duration: 12 Months Minimum Skills: * Must ... Experience with audit processes and disciplines including third party risk management. * Working ...
Execute and oversee the full third-party risk lifecycle, including onboarding, inherent and ... impact analysis, and post incident followup. * Contribute to security awareness and training ...
Execute and oversee the full third-party risk lifecycle, including onboarding, inherent and ... impact analysis, and post incident followup. * Contribute to security awareness and training ...
Execute and oversee the full third-party risk lifecycle, including onboarding, inherent and ... analysis, and post incident follow‑up. * Contribute to security awareness and training ...
Quick apply
Execute and oversee the full third-party risk lifecycle, including onboarding, inherent and ... analysis, and post incident follow‑up. * Contribute to security awareness and training ...
Role: Cyber Security Analyst Location: Santa Clara, CA Duration: Long Term Duties and ... At least one Third-party Risk Management (TPRM) application platform used to monitor the risks ...
Role: Cyber Security Analyst Location: Santa Clara, CA Duration: Long Term Duties and ... At least one Third-party Risk Management (TPRM) application platform used to monitor the risks ...
Wealth Management Risk Analyst
$71K - $75K/yr
... third-party operations (Cetera). * Assist with the preparation for the presentation of findings to various levels of leadership at the bank. Assist with the communication of results of risk ...
Wealth Management Risk Analyst
$71K - $75K/yr
... third-party operations (Cetera). * Assist with the preparation for the presentation of findings to various levels of leadership at the bank. Assist with the communication of results of risk ...
Full Time Third Party Risk Analyst information
What is the difference between Full Time Third Party Risk Analyst vs Contract Third Party Risk Analyst?
| Aspect | Full Time Third Party Risk Analyst | Contract Third Party Risk Analyst |
|---|---|---|
| Employment Type | Permanent, full-time | Temporary, project-based |
| Certifications | Typically required or preferred (e.g., CRISC, CTPRP) | Often required, but may vary |
| Work Environment | In-house, corporate setting | Remote or on-site, client-specific |
| Industry Usage | Common in finance, banking, and insurance | Used across industries for specific projects |
While both roles focus on third-party risk management, Full Time Third Party Risk Analysts are permanent employees working within a company, whereas Contract Third Party Risk Analysts are temporary contractors hired for specific projects. The full-time role offers stability and ongoing responsibilities, while the contract position provides flexibility and project-based work. Both roles often require similar certifications and industry knowledge, but employment type and work environment differ significantly.

Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Posted 29 days ago
Pacific Life rating
7.4
Based on 14 frontline employees who took The Breakroom Quiz
221st of 299 rated insurance
Job description
Job Description:
The Third Party Risk Management (TPRM) Analyst is a senior individual contributor responsible for governing and overseeing Pacific Life's enterprise TPRM program within the 2nd line of defense, with clear accountability for the design, maintenance, and enforcement of policies, standards, and control frameworks. This role ensures robust cybersecurity, resilience, and third party due diligence practices are consistently applied and aligned with regulatory expectations, while driving continuous enhancement of governance structures supporting third party outsourcing risk. This is a hybrid role (4 days per week onsite) in our Newport Beach, CA office.
Operating with a high degree of autonomy, the TPRM Analyst leverages deep subject matter expertise to oversee risk assessment, due diligence, and ongoing monitoring activities, with particular emphasis on cybersecurity controls, data protection, and critical vendor dependencies. The role partners closely with procurement, legal, information security, and business leaders to ensure risks across third and fourth party relationships are appropriately identified, governed, and mitigated.
As a trusted advisor, this role provides independent challenge and oversight to the first line of defense, ensuring adherence to established policies and control expectations while managing complex deliverables end-to-end. The position operates with minimal supervision within a team of approximately 35 professionals in Operational Risk & Resilience, part of Enterprise Risk Management, and collaborates closely with Service Owners, Service Managers, Service Leads, Capability Leads, and OR&R liaisons supporting effective first line execution.
How you will make an impact:
- Govern and enforce adherence to TPRM policies, standards, and control frameworks across the enterprise
- Ensure alignment with applicable regulatory expectations (e.g., NAIC, state DOI) and industry standards (e.g., NIST, ISO, Shared Assessments)
- Oversee and challenge third party due diligence reviews that span cybersecurity, data privacy, business continuity, financial, and operational risk elements
- Partner with the 1st line of defense to identify control gaps, assess residual risk, and ensure timely development and execution of risk treatment plans
- Escalate material risks, control deficiencies, and vendor issues through established governance and risk committee structures
- Develop and deliver executive and committee level reporting on third party risk exposure, trends, and emerging third party risks
- Serve as a trusted advisor to the business while providing effective 2nd line challenge to ensure appropriate risk based decisions
- Leverage industry best practices and external insights to strengthen governance, oversight, and program maturity
The experience you will bring:
- Bachelor's degree or equivalent professional experience
- Minimum 5+ years of experience in third-party risk management, operational risk, information security risk, or related GRC disciplines
- In-depth knowledge of TPRM frameworks, lifecycle practices, and regulatory expectations
- Strong understanding of interconnected risk domains (cybersecurity, privacy, business continuity, and vendor operational risk)
- Proven ability to solve complex problems using both conceptual and practical approaches
- Demonstrated ability to operate independently with minimal guidance and sound judgment
- Experience in financial services, preferably life insurance or annuities
- Familiarity with industry frameworks and standards (e.g., NIST CSF, ISO 27001/22301, Shared Assessments SIG/VRMMM)
- Relevant professional certifications (e.g., CRVPM, CISA, CRISC, CISSP, CTPRP) and experience with TPRM platforms/continuous monitoring tools
- Strong competencies in analytical thinking, stakeholder influence, communication, and driving continuous improvement5+ years of relevant experience in business resilience, business continuity, or operational resilience
What will make you stand out:
- Demonstrated governance mindset, with proven ownership of TPRM policies, standards, and control frameworks, and ability to enforce consistent adherence across the enterprise
- Bring deep expertise in cybersecurity due diligence and third party risk domains, with the ability to independently challenge assessments and drive risk informed decisions
- Operate as a highly credible second line advisor, effectively balancing partnership with the business while delivering objective challenge and oversight
- Proven track record of enhancing program maturity, including implementing scalable monitoring, improving control effectiveness, and aligning to evolving regulatory expectations
- Excel at translating complex risk insights into clear, executive-level reporting and actionable recommendations for senior leadership and risk committees
#LI-KP1
Base Pay Range:
The base pay range noted represents the company's good faith minimum and maximum range for this role at the time of posting. The actual compensation offered to a candidate will be dependent upon several factors, including but not limited to experience, qualifications and geographic location. Also, most employees are eligible for additional incentive pay.
$113,490.00 - $138,710.00Your Benefits Start Day 1
Your wellbeing is important to Pacific Life, and we're committed to providing you with flexible benefits that you can tailor to meet your needs. Whether you are focusing on your physical, financial, emotional, or social wellbeing, we've got you covered.
Prioritization of your health and well-being including Medical, Dental, Vision, and Wellbeing Reimbursement Account that can be used on yourself or your eligible dependents
Generous paid time off options including: Paid Time Off, Holiday Schedules, and Financial Planning Time Off
Paid Parental Leave as well as an Adoption Assistance Program
Competitive 401k savings plan with company match and an additional contribution regardless of participation
You Can Be Who You Are
We are committed to a culture of diversity and inclusion that embraces the authenticity of all employees, partners and communities. We support all employees to thrive and achieve their fullest potential.
What's life like at Pacific Life? Visit Instagram.com/lifeatpacificlife
EEO Statement:
Pacific Life Insurance Company is an Equal Opportunity /Affirmative Action Employer, M/F/D/V. If you are a qualified individual with a disability or a disabled veteran, you have the right to request an accommodation if you are unable or limited in your ability to use or access our career center as a result of your disability. To request an accommodation, contact a Human Resources Representative at Pacific Life Insurance Company.
What Pacific Life employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Pacific Life
Sourced by ZipRecruiter
When you purchase life insurance and retirement solutions, you're buying a promise. A promise that today, tomorrow or ten years from now, we'll be there. For more than 150 years, our clients have trusted Pacific Life to protect what matters most to them - their families, their businesses, their futures.
Industry
Finance and insurance
Company size
1,001 - 5,000 Employees
Headquarters location
Newport Beach, CA, US
Year founded
1868