SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Cloudflare is seeking a Security Third Party Risk Management Lead to own the execution and continuous improvement of their vendor and data center security review program. This is a senior individual-contributor role reporting to the Director of Information Security GRC.
You will serve as the technical and operational leader for the Third Party Risk function, acting as the go-to subject matter expert and mentoring Third Party Risk Management Specialists. Key responsibilities include:
- Own and drive operational execution of the third party risk management program, including vendor risk assessments, security contract terms, and continuous monitoring, ensuring consistently high-quality delivery.
- Serve as the subject matter expert on vendor security review methodology, vendor tiering, and risk treatment decisions.
- Lead the vendor risk assessment process day-to-day, applying and refining security policies and standards for different vendor types (cloud, contractor, software, hardware, data centers).
- Proactively identify inefficiencies in vendor security workflows and implement improvements that increase effectiveness, quality, and scalability.
- Coordinate team operations, running check-ins with specialists to drive assessments, escalations, and projects to completion.
- Provide technical guidance and mentorship to specialists on assessment methodology, risk decisions, tooling, and best practices.
- Make timely, well-reasoned decisions on risk findings and policy exceptions, serving as the escalation point for complex cases.
- Support negotiation of security contract terms with vendors by providing guidance to Contracts/Legal teams and resolving escalations.
- Act as primary point of coordination with Sourcing, Contracts, Legal, Privacy, and Security teams across the vendor lifecycle.
- Support design, implementation, and improvement of Procurement/GRC tools and AI workflows.
- Report on third party risk posture and program operations to security leadership.
Required experience: 8+ years in Security GRC with deep, hands-on expertise operating a third party/vendor risk program end-to-end. Subject-matter expertise across security control frameworks (ISO 27001, SOC 2, PCI, NIST 800-53), understanding of security contract terms, and demonstrated ability to mentor peers and provide technical guidance.