Security Assurance Analyst

Cloudflare Cloudflare · Enterprise · India · Remote · Security

Cloudflare is seeking a Security Assurance Analyst to join their Security Architecture Team. This role focuses on translating cyber risk tolerance into technical blueprints, implementing controls, and performing preventative security measures. The analyst will be involved in Third-Party Risk Management (TPRM), assessing vendor security postures, conducting technical security assessments of new infrastructure and services, auditing integrations, and ensuring compliance with security standards throughout the vendor lifecycle. The role requires advanced knowledge in Cloud Architecture, Data Encryption, Application Security, and IAM Architecture, as well as experience with GRC platforms and industry assessment standards.

What you'd actually do

  1. You will be on the Third-Party Risk Management (TPRM) program, assessing the security posture of vendors, suppliers, and external partners. This involves performing complex security due diligence, managing risk remediation plans, and ensuring contractual security clauses are enforced throughout the vendor lifecycle.
  2. Conduct in-depth technical security assessments of new software, hardware, and services by evaluating system architecture, data flows, and infrastructure controls.
  3. Review external vulnerability scans and security configuration evidence provided by vendors to identify potential exposure points prior to procurement.
  4. Audit SaaS-to-SaaS and API-based integrations to ensure they follow the principle of least privilege and do not utilize over-privileged scopes or insecure authentication methods.
  5. Perform periodic reviews of existing implementations to detect and remediate "configuration drift," such as unauthorized public data shares or legacy administrative accounts.

Skills

Required

  • advanced studies in Cybersecurity, Computer Science, Information Systems, or similar
  • Excellent written and verbal communication skills
  • 5+ years of experience in GRC (Governance, Risk, and Compliance) or Information Security, with 3+ years leading a TPRM/Vendor Risk program.
  • Deep practical knowledge of industry assessment standards (e.g., SOC 2, ISO 27001, SIG, CSA STAR).
  • Excellent analytical and communication skills
  • Experience with GRC platforms (e.g., ServiceNow GRC, Archer) for workflow automation.

Nice to have

  • CRISC, CTPRP (Certified Third-Party Risk Professional), or CISA.

What the JD emphasized

  • 5+ years of experience in GRC (Governance, Risk, and Compliance) or Information Security, with 3+ years leading a TPRM/Vendor Risk program.