The Third Party Risk Management (TPRM) Analyst is a senior individual contributor responsible for ... This role ensures robust cybersecurity, resilience, and third party due diligence practices are ...
The Third Party Risk Management (TPRM) Analyst is a senior individual contributor responsible for ... This role ensures robust cybersecurity, resilience, and third party due diligence practices are ...
The Third Party Risk Management (TPRM) Analyst is a senior individual contributor responsible for ... This role ensures robust cybersecurity, resilience, and third party due diligence practices are ...
The Third Party Risk Management (TPRM) Analyst is a senior individual contributor responsible for ... This role ensures robust cybersecurity, resilience, and third party due diligence practices are ...
Cybersecurity Program Manager
Watsonville, CA · On-site
$116K - $158K/yr
Develop and maintain a third-party cybersecurity risk management program to evaluate and validate vendor security practices and ensure partners meet company standards * Manage the cybersecurity ...
Cybersecurity Program Manager
Watsonville, CA · On-site
$116K - $158K/yr
Develop and maintain a third-party cybersecurity risk management program to evaluate and validate vendor security practices and ensure partners meet company standards * Manage the cybersecurity ...
The Third Party Risk Management (TPRM) Analyst is a senior individual contributor responsible for ... This role ensures robust cybersecurity, resilience, and third party due diligence practices are ...
The Third Party Risk Management (TPRM) Analyst is a senior individual contributor responsible for ... This role ensures robust cybersecurity, resilience, and third party due diligence practices are ...
Cybersecurity Program Manager
$116K - $158K/yr
Develop and maintain a third-party cybersecurity risk management program to evaluate and validate vendor security practices and ensure partners meet company standards * Manage the cybersecurity ...
Cybersecurity Program Manager
$116K - $158K/yr
Develop and maintain a third-party cybersecurity risk management program to evaluate and validate vendor security practices and ensure partners meet company standards * Manage the cybersecurity ...
Medical Device Cybersecurity Risk Specialist
Irvine, CA · On-site
$110K - $125K/yr
... third-party healthcare vendor applications. • Understanding of common cybersecurity controls including network security, endpoint protection, identity and access management, encryption, logging ...
Medical Device Cybersecurity Risk Specialist
Irvine, CA · On-site
$110K - $125K/yr
... third-party healthcare vendor applications. • Understanding of common cybersecurity controls including network security, endpoint protection, identity and access management, encryption, logging ...
Medical Device Cybersecurity Risk Specialist
Irvine, CA · On-site
$110K - $120K/yr
... third-party healthcare vendor applications. • Understanding of common cybersecurity controls including network security, endpoint protection, identity and access management, encryption, logging ...
Medical Device Cybersecurity Risk Specialist
Irvine, CA · On-site
$110K - $120K/yr
... third-party healthcare vendor applications. • Understanding of common cybersecurity controls including network security, endpoint protection, identity and access management, encryption, logging ...
Senior Cybersecurity Risk Analyst - USA Remote
San Diego, CA · Remote
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Senior Cybersecurity Risk Analyst - USA Remote
San Diego, CA · Remote
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Senior Cybersecurity Risk Analyst - USA Remote
Los Angeles, CA · Remote
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Senior Cybersecurity Risk Analyst - USA Remote
Los Angeles, CA · Remote
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Senior Cybersecurity Risk Analyst - USA Remote
Sacramento, CA · Remote
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Senior Cybersecurity Risk Analyst - USA Remote
Sacramento, CA · Remote
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Senior Cybersecurity Risk Analyst - USA Remote
Orange, CA · Remote
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Senior Cybersecurity Risk Analyst - USA Remote
Orange, CA · Remote
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Cybersecurity Counsel
$130K - $177K/yr
Experience with supply chain cybersecurity risk management, including advising on third-party security risk assessments, preparation of SBOMs and HBOMs, and supply chain cybersecurity. * Strong ...
Cybersecurity Counsel
$130K - $177K/yr
Experience with supply chain cybersecurity risk management, including advising on third-party security risk assessments, preparation of SBOMs and HBOMs, and supply chain cybersecurity. * Strong ...
Cybersecurity Counsel
Mountain View, CA · On-site
Experience with supply chain cybersecurity risk management, including advising on third-party security risk assessments, preparation of SBOMs and HBOMs, and supply chain cybersecurity. * Strong ...
Cybersecurity Counsel
Mountain View, CA · On-site
Experience with supply chain cybersecurity risk management, including advising on third-party security risk assessments, preparation of SBOMs and HBOMs, and supply chain cybersecurity. * Strong ...
Security Risk Manager
San Francisco, CA · On-site
... just third-party risk management or compliance or vulnerability management). * Consulting with Big 4 * Security Risk management / Cybersecurity risk management experience for 5+ years ...
Security Risk Manager
San Francisco, CA · On-site
... just third-party risk management or compliance or vulnerability management). * Consulting with Big 4 * Security Risk management / Cybersecurity risk management experience for 5+ years ...
Sr. Cybersecurity Audit Analyst
$100K - $129K/yr
Coordinate end-to-end external third-party cybersecurity audits, including scoping, readiness planning, timelines, and evidence coordination * Serve as the primary point of contact between external ...
Sr. Cybersecurity Audit Analyst
$100K - $129K/yr
Coordinate end-to-end external third-party cybersecurity audits, including scoping, readiness planning, timelines, and evidence coordination * Serve as the primary point of contact between external ...
Cybersecurity Engineering, Risk & Governance Senior Advisor
Rosemead, CA · On-site
$182K - $274K/yr
The role partners across cybersecurity, infrastructure, application, OT/ICS, compliance, risk, audit, operations, and third-party teams to ensure cyber requirements are not treated as after-the-fact ...
Cybersecurity Engineering, Risk & Governance Senior Advisor
Rosemead, CA · On-site
$182K - $274K/yr
The role partners across cybersecurity, infrastructure, application, OT/ICS, compliance, risk, audit, operations, and third-party teams to ensure cyber requirements are not treated as after-the-fact ...
Senior CyberSecurity
San Jose, CA · On-site
$85 - $95/hr
Position: Senior CyberSecurity GRC Analyst (San Jose, CA) Job Overview: Governance & Compliance ... Third T-Party Risk Management (TPRM): o Own and maintain Third-Party Risk Management evaluation ...
Senior CyberSecurity
San Jose, CA · On-site
$85 - $95/hr
Position: Senior CyberSecurity GRC Analyst (San Jose, CA) Job Overview: Governance & Compliance ... Third T-Party Risk Management (TPRM): o Own and maintain Third-Party Risk Management evaluation ...
Vice President, Cybersecurity
Los Angeles, CA · On-site
$169K - $211K/yr
... and third-party risk management program that ensures security requirements extend to managed ... Required : • 15+ years of progressive cybersecurity leadership experience, with 10+ years leading ...
Vice President, Cybersecurity
Los Angeles, CA · On-site
$169K - $211K/yr
... and third-party risk management program that ensures security requirements extend to managed ... Required : • 15+ years of progressive cybersecurity leadership experience, with 10+ years leading ...
Sr. Cybersecurity Audit Analyst
Redlands, CA · On-site
$87K - $150K/yr
Coordinate end-to-end external third-party cybersecurity audits, including scoping, readiness planning, timelines, and evidence coordination * Serve as the primary point of contact between external ...
Sr. Cybersecurity Audit Analyst
Redlands, CA · On-site
$87K - $150K/yr
Coordinate end-to-end external third-party cybersecurity audits, including scoping, readiness planning, timelines, and evidence coordination * Serve as the primary point of contact between external ...
... SaaS and third-party ecosystem. Responsibilities : • Own the product strategy and roadmap for ... Required : • 7+ years of Product Management experience, ideally in B2B SaaS, cybersecurity, risk ...
... SaaS and third-party ecosystem. Responsibilities : • Own the product strategy and roadmap for ... Required : • 7+ years of Product Management experience, ideally in B2B SaaS, cybersecurity, risk ...
Third Party Cybersecurity Risk information
How much does a third party risk analyst make?
Is third party risk management a good career?
What is third-party risk management in cybersecurity?
What is the difference between Third Party Cybersecurity Risk vs Cybersecurity Analyst?
| Aspect | Third Party Cybersecurity Risk | Cybersecurity Analyst |
|---|---|---|
| Certifications | ISO 27001, CISSP, CISA | CISSP, CompTIA Security+, CEH |
| Work Environment | Vendor assessments, risk management teams, client organizations | Security operations centers, IT departments, consulting firms |
| Industry Usage | Supply chain, vendor management, compliance | Network security, incident response, vulnerability assessment |
Third Party Cybersecurity Risk professionals focus on evaluating and managing risks from external vendors and partners, ensuring compliance and reducing supply chain vulnerabilities. Cybersecurity Analysts primarily monitor, analyze, and respond to security threats within an organization’s own systems. While both roles require security certifications and involve risk assessment, their focus areas and work environments differ significantly.
Can you make $500,000 a year in cyber security?
- Grc Third Party Risk Analyst
- Third Party Risk Assessment
- Internship Military Cyber Security
- Remote Risk Management Internships
- Assistant Cybersecurity Policy
- Internship Remote Incident Response
- Freelance Security Risk Assessment
- Manager Environmental Social Governance
- Cybersecurity Grc Internship
- Senior Remote Risk Management
Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Posted 27 days ago
Job description
Job Description:
The Third Party Risk Management (TPRM) Analyst is a senior individual contributor responsible for governing and overseeing Pacific Life's enterprise TPRM program within the 2nd line of defense, with clear accountability for the design, maintenance, and enforcement of policies, standards, and control frameworks. This role ensures robust cybersecurity, resilience, and third party due diligence practices are consistently applied and aligned with regulatory expectations, while driving continuous enhancement of governance structures supporting third party outsourcing risk. This is a hybrid role (4 days per week onsite) in our Newport Beach, CA office.
Operating with a high degree of autonomy, the TPRM Analyst leverages deep subject matter expertise to oversee risk assessment, due diligence, and ongoing monitoring activities, with particular emphasis on cybersecurity controls, data protection, and critical vendor dependencies. The role partners closely with procurement, legal, information security, and business leaders to ensure risks across third and fourth party relationships are appropriately identified, governed, and mitigated.
As a trusted advisor, this role provides independent challenge and oversight to the first line of defense, ensuring adherence to established policies and control expectations while managing complex deliverables end-to-end. The position operates with minimal supervision within a team of approximately 35 professionals in Operational Risk & Resilience, part of Enterprise Risk Management, and collaborates closely with Service Owners, Service Managers, Service Leads, Capability Leads, and OR&R liaisons supporting effective first line execution.
How you will make an impact:
- Govern and enforce adherence to TPRM policies, standards, and control frameworks across the enterprise
- Ensure alignment with applicable regulatory expectations (e.g., NAIC, state DOI) and industry standards (e.g., NIST, ISO, Shared Assessments)
- Oversee and challenge third party due diligence reviews that span cybersecurity, data privacy, business continuity, financial, and operational risk elements
- Partner with the 1st line of defense to identify control gaps, assess residual risk, and ensure timely development and execution of risk treatment plans
- Escalate material risks, control deficiencies, and vendor issues through established governance and risk committee structures
- Develop and deliver executive and committee level reporting on third party risk exposure, trends, and emerging third party risks
- Serve as a trusted advisor to the business while providing effective 2nd line challenge to ensure appropriate risk based decisions
- Leverage industry best practices and external insights to strengthen governance, oversight, and program maturity
The experience you will bring:
- Bachelor's degree or equivalent professional experience
- Minimum 5+ years of experience in third-party risk management, operational risk, information security risk, or related GRC disciplines
- In-depth knowledge of TPRM frameworks, lifecycle practices, and regulatory expectations
- Strong understanding of interconnected risk domains (cybersecurity, privacy, business continuity, and vendor operational risk)
- Proven ability to solve complex problems using both conceptual and practical approaches
- Demonstrated ability to operate independently with minimal guidance and sound judgment
- Experience in financial services, preferably life insurance or annuities
- Familiarity with industry frameworks and standards (e.g., NIST CSF, ISO 27001/22301, Shared Assessments SIG/VRMMM)
- Relevant professional certifications (e.g., CRVPM, CISA, CRISC, CISSP, CTPRP) and experience with TPRM platforms/continuous monitoring tools
- Strong competencies in analytical thinking, stakeholder influence, communication, and driving continuous improvement5+ years of relevant experience in business resilience, business continuity, or operational resilience
What will make you stand out:
- Demonstrated governance mindset, with proven ownership of TPRM policies, standards, and control frameworks, and ability to enforce consistent adherence across the enterprise
- Bring deep expertise in cybersecurity due diligence and third party risk domains, with the ability to independently challenge assessments and drive risk informed decisions
- Operate as a highly credible second line advisor, effectively balancing partnership with the business while delivering objective challenge and oversight
- Proven track record of enhancing program maturity, including implementing scalable monitoring, improving control effectiveness, and aligning to evolving regulatory expectations
- Excel at translating complex risk insights into clear, executive-level reporting and actionable recommendations for senior leadership and risk committees
#LI-KP1
Base Pay Range:
The base pay range noted represents the company's good faith minimum and maximum range for this role at the time of posting. The actual compensation offered to a candidate will be dependent upon several factors, including but not limited to experience, qualifications and geographic location. Also, most employees are eligible for additional incentive pay.
$113,490.00 - $138,710.00Your Benefits Start Day 1
Your wellbeing is important to Pacific Life, and we're committed to providing you with flexible benefits that you can tailor to meet your needs. Whether you are focusing on your physical, financial, emotional, or social wellbeing, we've got you covered.
Prioritization of your health and well-being including Medical, Dental, Vision, and Wellbeing Reimbursement Account that can be used on yourself or your eligible dependents
Generous paid time off options including: Paid Time Off, Holiday Schedules, and Financial Planning Time Off
Paid Parental Leave as well as an Adoption Assistance Program
Competitive 401k savings plan with company match and an additional contribution regardless of participation
You Can Be Who You Are
We are committed to a culture of diversity and inclusion that embraces the authenticity of all employees, partners and communities. We support all employees to thrive and achieve their fullest potential.
What's life like at Pacific Life? Visit Instagram.com/lifeatpacificlife
EEO Statement:
Pacific Life Insurance Company is an Equal Opportunity /Affirmative Action Employer, M/F/D/V. If you are a qualified individual with a disability or a disabled veteran, you have the right to request an accommodation if you are unable or limited in your ability to use or access our career center as a result of your disability. To request an accommodation, contact a Human Resources Representative at Pacific Life Insurance Company.