Back to jobs
New

Third Party Compliance Manager

Los Angeles, CA

MediaAlpha is a customer acquisition solutions provider powered by technology and data science. The company provides industry-leading solutions designed to reach consumers shopping within high-consideration categories such as property and casualty insurance, health insurance, life insurance, and more.

MediaAlpha is hiring a Third-Party Compliance Manager to build and lead our enterprise-wide vendor and ecosystem security program. This individual contributor role will own day-to-day TPRM operations, working hands-on to define strategy and execute across our three core focus areas: maintaining an inventory of third-party tools and platforms, verifying vendors are implemented according to security requirements, and conducting security reviews of new and existing solutions. You'll partner closely with Security, Privacy, Legal, Compliance, Engineering, Revenue Operations, and IT leaders.

As the primary hands-on operator, you'll coordinate security assessments and vendor reviews, build program infrastructure and processes, and track remediation efforts to closure. You'll be responsible for scaling the program as our vendor portfolio grows, shaping TPRM as an in-house capability while executing assessments and driving results yourself.

Your core responsibilities include managing information risks at scale across vendors, SaaS platforms, APIs, shared service providers, and supply chain dependencies. You'll transform our TPRM approach from periodic questionnaires to continuous, automation-enabled monitoring, expand visibility into fourth-party risks, and coordinate with engineering, privacy, and procurement teams to address technical, operational, and contractual exposures.

 

Responsibilities

  • Define and drive the TPRM roadmap and strategy - evolving the program into a scalable, repeatable process.
  • Maintain and optimize our Third-Party Risk Management function responsible for driving third party risk assessments, continuous monitoring and incident support
  • Audit new and existing third parties that are involved in exchange of information with our organization.
  • Partner with Information Services to design and integrate automation and continuous monitoring tools (e.g., Vanta) into third party workflows.
  • Embed security risk requirements into procurement, legal and contracting processes
  • Oversee technical integration reviews for SaaS, APIs, cloud platforms, and data-sharing workflows
  • Perform third party risk reviews of systems and services utilized by the organization.
  • Ensure fourth-party and ecosystem dependency risks are incorporated into TPRM processes.
  • Develop insights, dashboards and reporting that provides executive visibility into vendor, fourth-party and ecosystem risk
  • Partner with Information Services and Engineering to  ensure vendor-related vulnerabilities and incidents are effectively resolved.
  • Represent TPRM as a product and capability to leadership, customers, and stakeholders.
  • Complete Third Party Questionnaires sent to our organization, and ensure Third Party Questionnaires we send are completed appropriately.
  • Ensure our Trust Portal is maintained, the documentation is up to date, and inquiries are supported as they arise.
  • Support the Cyber Audit and the Exchange Compliance systems, addressing relevant requests as appropriate.
  • Maintain evidence repository and report tracking of TPRM compliance.
  • Provide TPRM training to internal business units and vendor relationship owners

Qualifications:

  • 7+ years of experience in third-party/vendor security risk management, supply chain risk, security, procurement, or GRC
  • Experience with TPRM methodologies, frameworks, and regulations (e.g., SIG, CSA, ISO,, NIST)
  • Experience with managing third party risks associated with SaaS, APIs, cloud services and architectures, and supply-chain ecosystems
  • Proven ability to define and deliver roadmaps, evolving manual TPRM program into an automated, scalable product
  • Hands-on knowledge of TPRM tools and continuous monitoring platforms (Vanta, BitSight, SecurityScorecard, ServiceNow, OneTrust, Process Unity, etc.)
  • Experience supporting vendor-related security incidents
  • Strong communication skills, with ability to brief senior leadership
  • Ability to partner effectively with varying business stakeholders with differing priorities

 

Preferred Skills

  • Advanced degree or two or more certifications (CRISC, CTPRP, CISM, CISSP, CISA, CIPT)
  • Experience scaling global TPRM programs across diverse regulatory environments
  • Knowledge of security and privacy frameworks (SOC 2, ISO 27001, NIST CSF, GDPR)
  • Experience developing executive dashboards, scorecards, and reporting.
  • Track record of building trusted partnerships with senior stakeholders across the enterprise - especially with Compliance, Legal, Security, Engineering, and Finance.
  • Comfortable using AI as a partner in your day to day work activities.

 

 

Compensation & Benefits

We are excited to offer a competitive base pay range of $113,000 to $200,000 per year for this position, based on experience and qualifications. But that's not all - as a valued member of our team, you will also have access to an array of top-notch benefits, including:

  • Annual bonus program and participation in our Restricted Stock Unit program
  • 100% Employer-paid health, dental, and vision insurance for you, your dependents, and spouse or registered domestic partner
  • 100% Employer paid long term disability, and life insurance
  • 401(k) retirement plan with matching contributions to help you plan for your future
  • Open Paid Time Off policy with a birthday day off and 11 holidays 
  • Professional development reimbursement
  • Cell Phone, Wellness, and Internet expense reimbursement, along with a subscription to the Calm App
  • 100% fully paid parental leave for team members up to 22 weeks for the primary caregiver and 12 weeks for the secondary caregiver 
  • Dog-friendly offices (LA and AZ) along with a $300 pet adoption reimbursement 

 

Diversity, Equity, and Inclusion

MediaAlpha is committed to fostering, cultivating, and maintaining a culture of diversity, equity, and inclusion. Our philosophy and actions are built on the premise that as an employer and citizens of our communities, we can create opportunities for lasting change. 

Fair Chance

MediaAlpha will consider qualified applicants, including those with criminal histories, in a manner consistent with state and local "Fair Chance" laws. We are also committed to providing reasonable accommodations for qualified applicants with disabilities and disabled veterans in our application process. If you need assistance or an accommodation due to a disability, please contact us at peopleops@mediaalpha.com or (213) 316-6256.

 

 

Create a Job Alert

Interested in building your career at MediaAlpha? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Education

Select...
Select...
Select...

Select...

When you apply to a job on this site, any personal data you provide, or which is collected as part of this process, will be processed by MediaAlpha in order to manage its recruitment and hiring related activities. Under European data protection laws, your rights may include the right to access, port, erase, restrict, rectify or object to the processing of your personal data or where we rely on consent, the right to withdraw that consent. More details about our processing and your rights are set out in our Job Applicant Privacy Notice.

California Privacy Rights Notice for Job Applicants

Under the California Consumer Privacy Act (“CCPA”), MediaAlpha is required to inform California residents who are our job applicants or prospective talent (together “job applicants”) about the categories of personal information we collect about you and the purposes for which we will use this information. This notice contains disclosures required by the CCPA and applies only to personal information that is subject to the CCPA.

Please review MediaAlpha's privacy policy and select "Confirmed" below to proceed.

Select...

U.S. Standard Demographic Questions

We invite applicants to share their demographic background. This information is completely voluntary. If you choose to complete this survey, your responses will be collected anonymously and in aggregate. The information will help us identify areas of improvement in our hiring process.

Select...
Select...
Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in MediaAlpha’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.