New The Skills of Tomorrow: how AI-exposed is every skill in 2026? See the data →
Cloudflare

Security Third Party Risk Management Lead

Cloudflare
Apply →
senior full-time Austin, TX

First indexed 4 Aug 2026

Description

The Security Third Party Risk Management Lead is a senior individual-contributor role. You will be the technical and operational leader for our Third Party Risk function , owning the execution and continuous improvement of vendor & data center security reviews, serving as the go-to subject matter expert for the team, and mentoring Third Party Risk Management Specialists as they deliver high-quality assessments at scale.

Key Responsibilities:

  • Own and drive the operational execution of our third-party risk management program , vendor risk assessments, security contract terms, and continuous monitoring , ensuring work is completed efficiently and to a consistently high standard.
  • Serve as the subject matter expert and go-to technical resource for vendor security review methodology, vendor tiering, and risk treatment decisions.
  • Lead the vendor risk assessment process day to day, applying and refining the security policies and standards that govern different types of vendor engagements.
  • Proactively identify inefficiencies in vendor security workflows and propose and implement improvements that increase effectiveness, quality, and scalability.
  • Coordinate the team's operational work , running check-ins with the specialists to drive assessments, escalations, and projects across the finish line.
  • Provide technical guidance and mentorship to Third Party Risk Management Specialists on assessment methodology, risk decisions, tooling, and best practices.
  • Make timely, well-reasoned decisions on risk findings and policy exceptions , assessing risk, compensating controls, and acceptable risk thresholds , and act as the escalation point for complex or ambiguous cases.
  • Support negotiation of security contract terms with vendors by maintaining guidance for Contracts/Legal teams and helping resolve contract escalations.
  • Act as a primary point of coordination with Sourcing, Contracts, Legal, Privacy, and Security teams across the vendor lifecycle , onboarding, implementation, monitoring, and offboarding , influencing how vendor security integrates into their processes.
  • Support the design, implementation, and improvement of Procurement/GRC tools and AI workflows.
  • Report on third-party risk posture and program operations to the Director, Information Security GRC, and security leadership.

Requirements:

  • Experience typically gained in 8+ years working in Security GRC.
  • Deep, hands-on expertise operating a third-party/vendor risk program end to end.
  • Subject-matter expertise across security control frameworks , ISO 27001, SOC 2, PCI, NIST 800-53.
  • Solid understanding of security contract terms and vendor negotiation support.
  • Demonstrated ability to mentor peers and provide technical guidance.
  • A track record of identifying process inefficiencies and driving operational improvements at scale.
  • Strong ability to influence and coordinate across cross-functional teams.
  • Strong organisational, analytical, and interpersonal skills.
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting: https://job-boards.greenhouse.io/cloudflare/jobs/8099937