Cloudflare
Manager, Security Third Party Risk Management
Job Posted 7 Days Ago
Be an Early Applicant
Manage the third party risk program, lead vendor assessments, negotiate contract terms, and oversee a team of specialists in risk management.
The Team
We are looking to hire an experienced manager for our Third Party Risk Program on our Security Governance, Risk, and Compliance team. This role will be responsible for managing a team of third party risk specialists, overseeing vendor & data center security reviews, and maturing our third party risk program & tooling.
What you'll do
- Own and manage our third party risk management program controls including vendor risk assessments, security contract terms, and continuous monitoring.
- Determine strategy for assessing and tiering Cloudflare vendors based on security impact.
- Lead Cloudflare's vendor risk assessment process by setting security policies and standards for various types of vendor engagements.
- Ensure that vendors are assessed in accordance with Cloudflare's security policies and standards.
- Support negotiation of security contract terms with vendors by maintaining guidance for Contracts/Legal teams and addressing contract escalations.
- Manage risk findings and policy exceptions identified through the vendor assessments by assessing risk, compensating controls, and determining acceptable risk thresholds.
- Partner with Sourcing, Contracts, Legal, Privacy, and Security teams to support Cloudflare's vendor lifecycle including onboarding, implementation, monitoring, and offboarding.
- Support the design and implementation of a new Procurement tool.
- Manage, engage, and grow a distributed team of Third Party Risk Management Specialists.
- Travel as needed to engage teammates, stakeholders, and vendors in San Francisco, Austin, or other global Cloudflare locations.
Examples of desirable skills, knowledge and experience
- Experience typically gained in 5-8 years working in Security GRC
- Experience managing a third party risk program
- Experience managing a team of GRC specialists
- Solid understanding of security contract terms
- Strong leader and business partner
- Strong organizational, analytical, and interpersonal skills
Top Skills
And Compliance
Procurement Tools
Risk
Security Governance
Similar Jobs at Cloudflare
Cloud • Information Technology • Security • Software • Cybersecurity
Lead the global FinOps strategy, establish governance for cloud deployment, implement cost allocation, design optimization initiatives, create dashboards, and manage relationships with cloud providers.
Top Skills:
APIsAWSAzureETLGCPMachine LearningPython
Cloud • Information Technology • Security • Software • Cybersecurity
Manage sourcing and procurement for Cloudflare's infrastructure, negotiating costs and quality with partners, and collaborating with engineering teams.
Top Skills:
Cloud InfrastructureHardware SourcingNetworking EquipmentPublic Cloud TechnologiesServer Technology
Cloud • Information Technology • Security • Software • Cybersecurity
Lead and execute technology and cybersecurity audits, improving insights through data analytics. Communicate findings and mentor team members, focusing on risk management.
Top Skills:
AICybersecurity FrameworksData Analytics
What you need to know about the Manchester Tech Scene
Home to a £5 billion digital ecosystem, including MediaCity, which consists of major players like the BBC, ITV and Ericsson, Manchester is one of the U.K.'s top digital tech hubs, at the forefront of advancements in film, television and emerging sectors like as e-sports, while also fostering a community of professionals dedicated to pushing creative and technological boundaries.