Position:
Security Third Party Risk Management Lead
Company:
Cloudflare
Location:
United States, Austin
Employment type:
Not specified
Work Arrangement:
Not specified
Short Summary:
The Security Third Party Risk Management Lead is a senior individual-contributor role responsible for leading the Third Party Risk function, executing vendor & data center security reviews, and mentoring team members.
Responsibilities:
- Own and drive the operational execution of the third party risk management program, ensuring high standards.
- Serve as the subject matter expert for vendor security review methodology and risk treatment decisions.
- Lead the vendor risk assessment process and refine security policies governing vendor engagements.
- Identify inefficiencies in vendor security workflows and implement improvements.
- Coordinate the team's operational work and provide mentorship on assessment methodology and best practices.
- Make timely decisions on risk findings and act as the escalation point for complex cases.
- Support negotiation of security contract terms with vendors.
- Act as a primary point of coordination with various teams across the vendor lifecycle.
- Report on third party risk posture and program operations to security leadership.
Requirement:
- 8+ years of experience in Security GRC.
- Expertise in operating a third party/vendor risk program.
- Knowledge of security control frameworks (ISO 27001, SOC 2, PCI, NIST 800-53).
- Understanding of security contract terms and vendor negotiation.
- Ability to mentor peers and drive operational improvements.
- Strong organizational, analytical, and interpersonal skills.
Benefits:
Not specified