Security Third Party Risk Management Specialist III

Cloudflare Cloudflare · Enterprise · Lisbon, Portugal, London, United Kingdom · Security

Cloudflare is seeking a Security Third Party Risk Management Specialist III to join their Governance, Risk, and Compliance team. The role involves executing vendor security reviews, identifying and documenting third-party security risks, determining security contract requirements, and maintaining the vendor master list. The specialist will also support customer-facing and incident response teams, assist with security certification audits, and partner with various internal teams to ensure vendor due diligence. A key responsibility includes leading projects to improve the vendor security review process, workflow, and tooling. The ideal candidate will have 5-8 years of experience in Security GRC, experience reviewing vendor security documentation (ISO 27001, SOC 2, PCI DSS), identifying security control gaps, and familiarity with security contract requirements.

What you'd actually do

  1. Execute vendor security reviews by collecting and analyzing vendor security control documentation and audit reports.
  2. Identify third-party security risks, documenting findings, and recommending risk treatment options.
  3. Determine security contract requirements & communicate these to the Contracts & Legal teams.
  4. Maintain Cloudflare’s Vendor Master, including our list of Critical vendors.
  5. Support Cloudflare’s customer-facing and incident response teams by ensuring our vendors are not affected by recent zero-day vulnerabilities or security incidents.

Skills

Required

  • Experience typically gained in 5-8 years working in Security GRC
  • Experience reviewing vendor security documentation including ISO 27001, SOC 2, PCI DSS, and other audit reports
  • Experience identifying security controls gaps, determining risk ratings, and recommending mitigating controls
  • Familiarity with security contract requirements
  • Strong organizational, analytical, and interpersonal skills
  • Self-starter with the ability to work independently with a sense of curiosity

What the JD emphasized

  • Security Third Party Risk Management Specialist III
  • vendor security reviews
  • third-party security risks
  • security contract requirements
  • Vendor Master
  • vendor security reviews