Description
The Security Third Party Risk Management Lead is a senior individual-contributor role. You will be the technical and operational leader for our Third Party Risk function , owning the execution and continuous improvement of vendor & data center security reviews, serving as the go-to subject matter expert for the team, and mentoring Third Party Risk Management Specialists as they deliver high-quality assessments at scale.
Key Responsibilities:
- Own and drive the operational execution of our third-party risk management program , vendor risk assessments, security contract terms, and continuous monitoring , ensuring work is completed efficiently and to a consistently high standard.
- Serve as the subject matter expert and go-to technical resource for vendor security review methodology, vendor tiering, and risk treatment decisions.
- Lead the vendor risk assessment process day to day, applying and refining the security policies and standards that govern different types of vendor engagements.
- Proactively identify inefficiencies in vendor security workflows and propose and implement improvements that increase effectiveness, quality, and scalability.
- Coordinate the team's operational work , running check-ins with the specialists to drive assessments, escalations, and projects across the finish line.
- Provide technical guidance and mentorship to Third Party Risk Management Specialists on assessment methodology, risk decisions, tooling, and best practices.
- Make timely, well-reasoned decisions on risk findings and policy exceptions , assessing risk, compensating controls, and acceptable risk thresholds , and act as the escalation point for complex or ambiguous cases.
- Support negotiation of security contract terms with vendors by maintaining guidance for Contracts/Legal teams and helping resolve contract escalations.
- Act as a primary point of coordination with Sourcing, Contracts, Legal, Privacy, and Security teams across the vendor lifecycle , onboarding, implementation, monitoring, and offboarding , influencing how vendor security integrates into their processes.
- Support the design, implementation, and improvement of Procurement/GRC tools and AI workflows.
- Report on third-party risk posture and program operations to the Director, Information Security GRC, and security leadership.
Requirements:
- Experience typically gained in 8+ years working in Security GRC.
- Deep, hands-on expertise operating a third-party/vendor risk program end to end.
- Subject-matter expertise across security control frameworks , ISO 27001, SOC 2, PCI, NIST 800-53.
- Solid understanding of security contract terms and vendor negotiation support.
- Demonstrated ability to mentor peers and provide technical guidance.
- A track record of identifying process inefficiencies and driving operational improvements at scale.
- Strong ability to influence and coordinate across cross-functional teams.
- Strong organisational, analytical, and interpersonal skills.
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting:
https://job-boards.greenhouse.io/cloudflare/jobs/8099937