# Security Third Party Risk Management Lead

**Company**: Cloudflare
**Location**: Austin, TX
**Experience**: senior
**Job type**: full-time
**Category**: IT
**Industry**: Technology

**Apply**: https://job-boards.greenhouse.io/cloudflare/jobs/8099937?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_7a34ddf3-f5f

## Description

The Security Third Party Risk Management Lead is a senior individual-contributor role. You will be the technical and operational leader for our Third Party Risk function , owning the execution and continuous improvement of vendor & data center security reviews, serving as the go-to subject matter expert for the team, and mentoring Third Party Risk Management Specialists as they deliver high-quality assessments at scale.

Key Responsibilities:

- Own and drive the operational execution of our third-party risk management program , vendor risk assessments, security contract terms, and continuous monitoring , ensuring work is completed efficiently and to a consistently high standard.

- Serve as the subject matter expert and go-to technical resource for vendor security review methodology, vendor tiering, and risk treatment decisions.

- Lead the vendor risk assessment process day to day, applying and refining the security policies and standards that govern different types of vendor engagements.

- Proactively identify inefficiencies in vendor security workflows and propose and implement improvements that increase effectiveness, quality, and scalability.

- Coordinate the team's operational work , running check-ins with the specialists to drive assessments, escalations, and projects across the finish line.

- Provide technical guidance and mentorship to Third Party Risk Management Specialists on assessment methodology, risk decisions, tooling, and best practices.

- Make timely, well-reasoned decisions on risk findings and policy exceptions , assessing risk, compensating controls, and acceptable risk thresholds , and act as the escalation point for complex or ambiguous cases.

- Support negotiation of security contract terms with vendors by maintaining guidance for Contracts/Legal teams and helping resolve contract escalations.

- Act as a primary point of coordination with Sourcing, Contracts, Legal, Privacy, and Security teams across the vendor lifecycle , onboarding, implementation, monitoring, and offboarding , influencing how vendor security integrates into their processes.

- Support the design, implementation, and improvement of Procurement/GRC tools and AI workflows.

- Report on third-party risk posture and program operations to the Director, Information Security GRC, and security leadership.

Requirements:

- Experience typically gained in 8+ years working in Security GRC.

- Deep, hands-on expertise operating a third-party/vendor risk program end to end.

- Subject-matter expertise across security control frameworks , ISO 27001, SOC 2, PCI, NIST 800-53.

- Solid understanding of security contract terms and vendor negotiation support.

- Demonstrated ability to mentor peers and provide technical guidance.

- A track record of identifying process inefficiencies and driving operational improvements at scale.

- Strong ability to influence and coordinate across cross-functional teams.

- Strong organisational, analytical, and interpersonal skills.

## Skills

### Required
- Security GRC
- Third-party risk management
- Vendor risk assessments
- Security contract terms
- ISO 27001
- SOC 2
- PCI
- NIST 800-53

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/cloudflare/jobs/8099937?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
