Security Third Party Risk Management Specialist managing vendor security reviews and risks at Cloudflare. Collaborating across teams to support third party risk management in a hybrid work environment.
Responsibilities
Execute vendor security reviews by collecting and analyzing vendor security control documentation and audit reports.
Assist in identifying third-party security risks, documenting findings, and recommending risk treatment options.
Collaborate with the Contracts & Legal teams to ensure security contract requirements are incorporated into vendor agreements.
Support the maintenance of Cloudflare’s vendor master list, ensuring data accuracy and proper classification of critical vendors.
Help the team monitor current security events (e.g., zero-day vulnerabilities) and support outreach to vendors to confirm their status and remediation efforts.
Gather and prepare evidence of vendor security reviews to support Cloudflare’s security certification audits.
Liaise and coordinate with stakeholders across Cloudflare’s Procurement, IT, Contracts, Legal, and Privacy teams to ensure vendor due diligence workflows are completed efficiently.
Assist in the ongoing improvement of the vendor security review process, documentation, and tooling.
Some travel may be required to engage teammates and stakeholders in San Francisco, Austin, or other global Cloudflare locations.
Requirements
2-5 years working in Security GRC
Experience reviewing vendor security documentation including ISO 27001, SOC 2, PCI DSS, and other audit reports
Senior Cybersecurity Scrum Master focusing on release management at AT&T, collaborating across teams and managing production change requests with an Agile mindset.
BISO responsible for planning and executing enterprise - wide information security initiatives at Elsevier. Driving cybersecurity awareness and managing technical risk assessments for organizational improvements.
Develop innovative Cloud architectures on Microsoft Azure platforms. Secure cloud infrastructure and applications against various threats while working in a project team.
Analista Pleno de Segurança Patrimonial na Hershey Brasil, responsável por suporte de segurança física e gestão de serviços de segurança. Atuará em conformidade e gestão de crise em São Roque.
Regional Information Security Officer managing security protocols and compliance for KARL STORZ. Leading local ISOs and enhancing information security measures across subsidiaries.
CISO managing information security and privacy governance at Puzzel, a leading cloud - based contact center provider in Europe. Engaging with stakeholders for compliance and risk management.
Manager of IT Support & Endpoint Security overseeing service desk operations and endpoint security strategies. Leading a team to deliver high - quality technical support and manage IT security policies.
Senior Security Officer responsible for security and safety duties in acute care settings. Providing armed presence and response, coordinating with law enforcement as required.
Security Officer overseeing sensitive information protection and compliance with regulations. Collaborating with internal teams ensure security policy implementation and risk management under EU standards.