1

Internship Vendor Risk Analyst Jobs in California

Sr IT Vendor Manager

Irvine, CA ยท On-site

$116K - $197K/yr

Standardize governance, segmentation, risk scoring, financial tracking, and spend analytics. * Deliver training programs to upskill internal and vendor teams. What you bring to the role: * Bachelor ...

Standardize governance, segmentation, risk scoring, financial tracking, and spend analytics. * Deliver training programs to upskill internal and vendor teams. What you bring to the role: * Bachelor ...

Manager, IT Risk Operations

Palo Alto, CA ยท On-site

$147K - $198K/yr

Analyze incident, change, and problem management data toidentifytrends and improvement opportunities * Drive workflow optimization and automation within ServiceNow Vendor Risk Management * Review and ...

Experience in IT sourcing, vendor risk management, or third-party compliance audits. * Understanding of contract terms, TCO analysis, and budget planning.

The Associate Security Trust Analyst plays a critical role in helping ensure the security ... Third-Party Risk Management (TPRM) * Conduct vendor security assessments, including collecting and ...

Showing results 41-60

Internship Vendor Risk Analyst information

What is an internship vendor risk analyst?

An Internship Vendor Risk Analyst is an entry-level position, often designed for students or recent graduates, that focuses on assessing and managing the risks associated with third-party vendors. Interns in this role help organizations evaluate the security, compliance, and reliability of vendors by analyzing documentation, conducting risk assessments, and supporting ongoing risk monitoring activities. They work under the guidance of senior analysts to ensure vendors meet company standards and regulatory requirements, gaining hands-on experience in risk management and vendor oversight.

What are the key skills and qualifications needed to thrive as an internship vendor risk analyst, and why are they important?

To thrive as an Internship Vendor Risk Analyst, you need a solid understanding of risk assessment, vendor management principles, and basic knowledge of compliance frameworks, often supported by coursework in finance, business, or information security. Familiarity with tools like Excel, risk management software, and platforms such as SAP Ariba or RSA Archer is typically expected. Attention to detail, analytical thinking, and effective communication are standout soft skills for gathering data and collaborating with internal stakeholders. These skills are crucial for identifying potential vendor risks, ensuring regulatory compliance, and supporting organizational decision-making.

What are some common challenges internship vendor risk analysts face when assessing third-party vendors?

Internship Vendor Risk Analysts often encounter challenges such as limited access to comprehensive vendor data, navigating complex regulatory requirements, and balancing multiple stakeholder interests. Interns must learn to evaluate risk with incomplete information and communicate findings clearly to both internal teams and vendors. Building strong analytical and communication skills, as well as understanding the organization's risk appetite, are key to overcoming these challenges and making meaningful contributions during the internship.

What is the difference between Internship Vendor Risk Analyst vs Vendor Risk Analyst?

AspectInternship Vendor Risk AnalystVendor Risk Analyst
CredentialsTypically pursuing or recent graduate, some certifications optionalUsually requires professional certifications like CRISC or CTP
Work EnvironmentInternship setting, entry-level tasks, learning-focusedFull-time role, responsible for ongoing risk assessments
Industry UsageCommon in finance, consulting, and tech companies for trainingEstablished position in risk management departments across industries

The Internship Vendor Risk Analyst is an entry-level role designed for students or recent graduates gaining experience in vendor risk management. In contrast, the Vendor Risk Analyst is a full-time professional responsible for ongoing risk assessments and mitigation strategies. While both roles involve evaluating vendor risks, the internship focuses on learning and support, whereas the analyst role involves independent decision-making and expertise.

What are the most commonly searched types of Vendor Risk Analyst jobs in California?

The most popular types of Vendor Risk Analyst jobs in California are:

What cities in California are hiring for Internship Vendor Risk Analyst jobs?

Cities in California with the most Internship Vendor Risk Analyst job openings:

Infographic showing various Internship Vendor Risk Analyst job openings in California as of August 2026, with employment types broken down into 1% As Needed, 88% Full Time, 8% Part Time, and 3% Contract. Highlights an 88% Physical, 4% Hybrid, and 8% Remote job distribution.

Third Party Risk Management Analyst

Pacific Asset Management, LLC

Newport Beach, CA โ€ข On-site

$113.49 - $138.71/hr

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted yesterday

New


Job description

Job Description

The Third Party Risk Management (TPRM) Capability Lead is a senior individual contributor responsible for governing and overseeing Pacific Lifeโ€™s enterprise TPRM program within the 2nd line of defense, with clear accountability for the design, maintenance, and enforcement of policies, standards, and control frameworks. This role ensures robust cybersecurity, resilience, and third party due diligence practices are consistently applied and aligned with regulatory expectations, while driving continuous enhancement of governance structures supporting third party outsourcing risk. This is a hybrid role (4 days per week onsite) in our Newport Beach, CA office. Operating with a high degree of autonomy, the TPRM Lead leverages deep subject matter expertise to oversee risk assessment, due diligence, and ongoing monitoring activities, with particular emphasis on cybersecurity controls, data protection, and critical vendor dependencies. The role partners closely with procurement, legal, information security, and business leaders to ensure risks across third and fourth party relationships are appropriately identified, governed, and mitigated. As a trusted advisor, this role provides independent challenge and oversight to the first line of defense, ensuring adherence to established policies and control expectations while managing complex deliverables endโ€‘toโ€‘end. The position operates with minimal supervision within a team of approximately 35 professionals in Operational Risk & Resilience, part of Enterprise Risk Management, and collaborates closely with Service Owners, Service Managers, Service Leads, Capability Leads, and OR&R liaisons supporting effective first line execution.

How you will make an impact
  • Govern and enforce adherence to TPRM policies, standards, and control frameworks across the enterprise.
  • Ensure alignment with applicable regulatory expectations (e.g., NAIC, state DOI) and industry standards (e.g., NIST, ISO, Shared Assessments).
  • Oversee and challenge third party due diligence reviews that span cybersecurity, data privacy, business continuity, financial, and operational risk elements.
  • Partner with the 1st line of defense to identify control gaps, assess residual risk, and ensure timely development and execution of risk treatment plans.
  • Escalate material risks, control deficiencies, and vendor issues through established governance and risk committee structures.
  • Develop and deliver executive and committee level reporting on third party risk exposure, trends, and emerging third party risks.
  • Serve as a trusted advisor to the business while providing effective 2nd line challenge to ensure appropriate risk based decisions.
  • Leverage industry best practices and external insights to strengthen governance, oversight, and program maturity.
The experience you will bring
  • Bachelorโ€™s degree or equivalent professional experience.
  • Minimum 5+ years of experience in thirdโ€‘party risk management, operational risk, information security risk, or related GRC disciplines.
  • Inโ€‘depth knowledge of TPRM frameworks, lifecycle practices, and regulatory expectations.
  • Strong understanding of interconnected risk domains (cybersecurity, privacy, business continuity, and vendor operational risk).
  • Proven ability to solve complex problems using both conceptual and practical approaches.
  • Demonstrated ability to operate independently with minimal guidance and sound judgment.
  • Experience in financial services, preferably life insurance or annuities.
  • Familiarity with industry frameworks and standards (e.g., NIST CSF, ISO 27001/22301, Shared Assessments SIG/VRMMM).
  • Relevant professional certifications (e.g., CRVPM, CISA, CRISC, CISSP, CTPRP) and experience with TPRM platforms/continuous monitoring tools.
  • Strong competencies in analytical thinking, stakeholder influence, communication, and driving continuous improvement.
  • 5+ years of relevant experience in business resilience, business continuity, or operational resilience.
What will make you stand out
  • Demonstrated governance mindset, with proven ownership of TPRM policies, standards, and control frameworks, and ability to enforce consistent adherence across the enterprise.
  • Bring deep expertise in cybersecurity due diligence and thirdโ€‘party risk domains, with the ability to independently challenge assessments and drive riskโ€‘informed decisions.
  • Operate as a highly credible second line advisor, effectively balancing partnership with the business while delivering objective challenge and oversight.
  • Proven track record of enhancing program maturity, including implementing scalable monitoring, improving control effectiveness, and aligning to evolving regulatory expectations.
  • Excel at translating complex risk insights into clear, executiveโ€‘level reporting and actionable recommendations for senior leadership and risk committees.
Base Pay Range

$113,490.00 - $138,710.00. The base pay range represents the companyโ€™s good faith minimum and maximum range for this role at the time of posting. The actual compensation offered to a candidate will be dependent upon several factors, including but not limited to experience, qualifications and geographic location. Also, most employees are eligible for additional incentive pay.

Your Benefits

Your wellbeing is important to Pacific Life, and weโ€™re committed to providing you with flexible benefits that you can tailor to meet your needs. Whether you are focusing on your physical, financial, emotional, or social wellbeing, weโ€™ve got you covered. Prioritization of your health and wellโ€‘being includes Medical, Dental, Vision, and Wellbeing Reimbursement Account that can be used on yourself or your eligible dependents. Generous paid time off options including Paid Time Off, Holiday Schedules, and Financial Planning Time Off; Paid Parental Leave as well as an Adoption Assistance Program; Competitive 401K savings plan with company match and an additional contribution regardless of participation.

EEO Statement

Pacific Life Insurance Company is an Equal Opportunity /Affirmative Action Employer, M/F/D/V. If you are a qualified individual with a disability or a disabled veteran, you have the right to request an accommodation if you are unable or limited in your ability to use or access our career center as a result of your disability. To request an accommodation, contact a Human Resources Representative at Pacific Life Insurance Company.

#J-18808-Ljbffr