Security Third Party Risk Management Lead

Cloudflare
Austin
Workplace: OnsiteFull timeFunction: Legal, Risk & ComplianceExperience: 8+ yearsSkills: ["Mentoring","Technical guidance","Influencing","Cross-functional coordination","Organizational and analytical skills"]

Own and drive Cloudflare’s third-party risk management program, leading vendor risk assessments, security contract terms, and continuous monitoring. Serve as the go-to subject matter expert on vendor security review methodology, vendor tiering, and risk treatment decisions. Coordinate specialists’ day-to-day work, identify inefficiencies, and lead program improvement projects. Mentor Third Party Risk Management Specialists on assessment methodology, risk decisions, tooling, and best practices while partnering with Procurement and cross-functional stakeholders.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Cloudflare
Cloudflare
1 day ago

Security Third Party Risk Management Lead

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 6 hours agoStatus: Live

Job Summary

Own and drive Cloudflare’s third-party risk management program, leading vendor risk assessments, security contract terms, and continuous monitoring. Serve as the go-to subject matter expert on vendor security review methodology, vendor tiering, and risk treatment decisions. Coordinate specialists’ day-to-day work, identify inefficiencies, and lead program improvement projects. Mentor Third Party Risk Management Specialists on assessment methodology, risk decisions, tooling, and best practices while partnering with Procurement and cross-functional stakeholders.
Location: Austin
Workplace: Onsite
Employment Type: Full time
Job Function: Legal, Risk & Compliance
Seniority: Mid level

Key Responsibilities

  • •Own and drive the operational execution of the third-party risk management program, including vendor risk assessments, security contract terms, and continuous monitoring.
  • •Serve as the subject matter expert for vendor security review methodology, vendor tiering, and risk treatment decisions.
  • •Lead the day-to-day vendor risk assessment process by applying and refining security policies and standards across different vendor engagement types.
  • •Proactively identify and implement improvements to increase effectiveness, quality, and scalability of vendor security workflows.
  • •Provide technical guidance and mentorship to Third Party Risk Management Specialists, including assessment methodology, risk decisions, tooling, and best practices.

Key Requirements

  • •8+ years of experience in Security GRC.
  • •Deep, hands-on end-to-end experience operating a third-party/vendor risk program.
  • •Subject-matter expertise across security control frameworks including ISO 27001, SOC 2, PCI, and NIST 800-53.
  • •Strong understanding of security contract terms and vendor negotiation support.
  • •Demonstrated ability to mentor peers and provide technical guidance.
Experience:8+ yearsSecurity GRCThird-party riskVendor risk
Skills:MentoringTechnical guidanceInfluencingCross-functional coordinationOrganizational and analytical skills
Languages:English
Tech Stack:ISO 27001SOC 2PCINIST 800-53AI workflows

Company Brief

Cloudflare
Provides a global network and cloud platform that delivers security, performance, and reliability services for web applications, APIs, and Internet properties, including CDN, DDoS protection, DNS, and zero-trust security solutions.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 2009
WebsiteLinkedIn