Skip to main content
Back to jobs

Third Party Risk Management Capability Lead

External
pacificlife logoPacificlife · Newport Beach Ca-700
Full-timeHybrid3w ago
ExcelInformation SecurityLeadershipRisk Management
Cover LetterConnect

Prepare for this interview

Elite

AI-generated questions, company research, and talking points tailored to this role


Benefits

Vision insurance

Additional Information

Job Description: The Third Party Risk Management (TPRM) Capability Lead is a senior individual contributor responsible for governing and overseeing Pacific Life's enterprise TPRM program within the 2nd line of defense, with clear accountability for the design, maintenance, and enforcement of policies, standards, and control frameworks. This role ensures robust cybersecurity, resilience, and third party due diligence practices are consistently applied and aligned with regulatory expectations, while driving continuous enhancement of governance structures supporting third party outsourcing risk. This is a hybrid role (4 days per week onsite) in our Newport Beach, CA office. Operating with a high degree of autonomy, the TPRM Lead leverages deep subject matter expertise to oversee risk assessment, due diligence, and ongoing monitoring activities, with particular emphasis on cybersecurity controls, data protection, and critical vendor dependencies. The role partners closely with procurement, legal, information security, and business leaders to ensure risks across third and fourth party relationships are appropriately identified, governed, and mitigated. As a trusted advisor, this role provides independent challenge and oversight to the first line of defense, ensuring adherence to established policies and control expectations while managing complex deliverables end-to-end. The position operates with minimal supervision within a team of approximately 35 professionals in Operational Risk & Resilience, part of Enterprise Risk Management, and collaborates closely with Service Owners, Service Managers, Service Leads, Capability Leads, and OR&R liaisons supporting effective first line execution. How you will make an impact: Govern and enforce adherence to TPRM policies, standards, and control frameworks across the enterprise Ensure alignment with applicable regulatory expectations (e.g., NAIC, state DOI) and industry standards (e.g., NIST, ISO, Shared Assessments) Oversee and challenge third party due diligence reviews that span cybersecurity, data privacy, business continuity, financial, and operational risk elements Partner with the 1st line of defense to identify control gaps, assess residual risk, and ensure timely development and execution of risk treatment plans Escalate material risks, control deficiencies, and vendor issues through established governance and risk committee structures Develop and deliver executive and committee level reporting on third party risk exposure, trends, and emerging third party risks Serve as a trusted advisor to the business while providing effective 2nd line challenge to ensure appropriate risk based decisions Leverage industry best practices and external insights to strengthen governance, oversight, and program maturity The experience you will bring: Bachelor's degree or equivalent professional experience Minimum 5+ years of experience in third-party risk management, operational risk, information security risk, or related GRC disciplines In-depth knowledge of TPRM frameworks, lifecycle practices, and regulatory expectations Strong understanding of interconnected risk domains (cybersecurity, privacy, business continuity, and vendor operational risk) Proven ability to solve complex problems using both conceptual and practical approaches Demonstrated ability to operate independently with minimal guidance and sound judgment Experience in financial services, preferably life insurance or annuities Familiarity with industry frameworks and standards (e.g., NIST CSF, ISO 27001/22301, Shared Assessments SIG/VRMMM) Relevant professional certifications (e.g., CRVPM, CISA, CRISC, CISSP, CTPRP) and experience with TPRM platforms/continuous monitoring tools Strong competencies in analytical thinking, stakeholder influence, communication, and driving continuous improvement5+ years of relevant experience in business resilience, business continuity, or operational resilience What will make you stand out: Demonstrated governance mindset, with proven ownership of TPRM policies, standards, and control frameworks, and ability to enforce consistent adherence across the enterprise Bring deep expertise in cybersecurity due diligence and third party risk domains, with the ability to independently challenge assessments and drive risk informed decisions Operate as a highly credible second line advisor, effectively balancing partnership with the business while delivering objective challenge and oversight Proven track record of enhancing program maturity, including implementing scalable monitoring, improving control effectiveness, and aligning to evolving regulatory expectations Excel at translating complex risk insights into clear, executive-level reporting and actionable recommendations for senior leadership and risk committees #LI-SD Base Pay Range: The base pay range noted represents the company's good faith minimum and maximum range for this role at the time of posting. The actual compensation offe


Your Match

How well this role fits your profile.

Company Intel

What employees say

Worked at pacificlife? Share your experience

Interested in this role?

Apply on the company's website.

Cover LetterConnect