Third Party Risk Management Expert

2 weeks ago


San Francisco, California, United States Cloudflare Inc Full time
The Team

We are seeking a seasoned Security Risk Management Specialist to enhance our Governance, Risk, and Compliance division.

This position entails executing vendor security evaluations, managing our vendor database, and overseeing Cloudflare's Third Party Risk Program.

This is a chance to become part of a rapidly expanding and elite security team within a billion-dollar enterprise. We assure you that the work will be engaging.

Key Responsibilities

• Perform Vendor Security Evaluations for third parties supplying data center, hardware, software, cloud, and other services to Cloudflare.

• Evaluate vendor security posture by analyzing security controls and audit documentation.

• Identify security risks associated with third parties and propose risk mitigation strategies.

• Define security contract requirements and relay these to the Contracts & Legal teams.

• Maintain Cloudflare's Vendor Master, including our list of Critical vendors.

• Enhance the Vendor Security Review process, workflow, and tools.

• Assist Cloudflare's customer-facing and incident response teams by ensuring our vendors are safeguarded against recent vulnerabilities or security incidents.

• Support Cloudflare's security certification audits by providing documentation of vendor security evaluations.

• Collaborate with stakeholders across Cloudflare's Procurement, IT, Contracts, Legal, and Privacy teams to ensure efficient vendor due diligence.

• Some travel may be necessary to engage with colleagues and stakeholders in various locations.

Preferred Skills and Experience

• Typically acquired through 4-7 years of experience in Security Governance, Risk, and Compliance.

• Proficient in reviewing vendor security documentation, including ISO 27001, SOC 2, PCI DSS, and other audit reports.

• Experienced in identifying gaps in security controls, assessing risk levels, and recommending corrective measures.

• Familiar with security contract stipulations.

• Strong organizational, analytical, and interpersonal abilities.

• Self-motivated with the capacity to work independently and a keen sense of curiosity.

#J-18808-Ljbffr

  • San Francisco, California, United States LendingClub Full time

    About the RoleLendingClub's Third Party Risk Management (TPRM) team acts as the second line of defense against risks associated with outsourcing services to third parties. The Third Party Risk team works closely with various stakeholders, including Procurement, Risk SMEs, and Business Partners to onboard and manage vendors and other third parties, build...


  • San Francisco, California, United States DoorDash USA Full time

    About DoorDashAt DoorDash, we are committed to building a reliable logistics platform that serves consumers, merchants, and drivers around the clock. Our team is dedicated to ensuring that our global infrastructure remains secure and efficient.Position OverviewThe Governance, Risk, and Compliance (GRC) team is in search of a skilled Third-Party Risk Analyst....


  • San Francisco, California, United States Airtable Full time

    About the RoleAirtable is seeking a highly skilled Third Party Risk Specialist to join our Governance, Risk, Compliance, and Privacy (GRCP) team. As a key member of our team, you will play a critical role in ensuring the security and compliance of our third-party suppliers.Key ResponsibilitiesConduct Third-Party Security and Compliance Reviews: Conduct...


  • San Francisco, California, United States DoorDash USA Full time

    About DoorDashAt DoorDash, we are committed to creating the most reliable logistics platform for delivery services. Our team is dedicated to ensuring that our global infrastructure operates seamlessly, providing uninterrupted service to our diverse marketplace of consumers, merchants, and drivers.Position OverviewThe Governance, Risk, and Compliance (GRC)...


  • San Francisco, California, United States Early Warning Services Full time

    Position OverviewAt Early Warning Services, we have been safeguarding the U.S. financial ecosystem for over three decades with innovative solutions such as Zelle and PazeSM. As a reputable entity in the payments sector, we collaborate with numerous institutions to enhance access to financial services and secure transactions for millions of consumers and...


  • San Jose, California, United States Western Digital Full time

    Job OverviewCompany Overview:At Western Digital, we strive to drive global innovation and redefine technological boundaries, making the seemingly impossible a reality.As a company built on problem-solving, we empower individuals to achieve remarkable feats through the right technology. Our contributions have been pivotal, including supporting monumental...

  • Program Manager

    1 week ago


    San Jose, California, United States Western Digital Full time

    Job SummaryWe are seeking a highly skilled Program Manager - Third Party Risk Management to join our Procurement Digital Transformation and Operations organization's Third Party Risk Management team. As a key member of our team, you will be responsible for leading and managing projects aimed at ensuring effective governance and oversight of our Third Party...


  • San Jose, California, United States KAnand Corporation Full time

    Position: Senior Third-Party Risk Management AnalystLocation: RemoteDuration: Long-term ContractExperience: 10+ YearsNote: Candidates must possess valid work authorization in the USA.ROLE OVERVIEW:The Senior Third-Party Risk Management Analyst will engage with IT stakeholders, project leads, and business executives to oversee vendor risk evaluations...


  • San Jose, California, United States Western Digital Full time

    Job OverviewCompany Overview:At Western Digital, we are driven by a vision to fuel global innovation and redefine the limits of technology, transforming the seemingly impossible into reality.As a company rooted in problem-solving, we empower individuals to achieve remarkable feats through the right technological solutions. Our contributions have historically...


  • San Jose, California, United States Western Digital Full time

    Job OverviewCompany Overview:At Western Digital, we strive to drive global innovation and redefine technological boundaries, making the seemingly impossible a reality.As a pivotal player in the tech industry, Western Digital is comprised of problem solvers who have consistently achieved remarkable feats through the right technology. Our contributions have...


  • San Jose, California, United States Frontend Arts Full time

    Frontend Arts is a dynamic organization dedicated to empowering teams to enhance project management, streamline workflows, and create innovative secure solutions through user-friendly no-code tools. We are on a mission to transform the way businesses operate. We are seeking a talented individual to join our team and contribute to the development and...


  • San Jose, California, United States Western Digital Capital Full time

    Job SummaryWe are seeking a highly experienced Senior Director to lead our Third Party Risk Management and Responsible Sourcing initiatives. As a key member of our Program Management team, you will be responsible for developing and implementing strategic policies and procedures to assess, onboard, monitor, and optimize third-party relationships.Key...

  • Vendor Risk Manager

    7 days ago


    San Francisco, California, United States LendingClub Full time

    About the RoleLendingClub's Third Party Risk Management (TPRM) team acts as the second line of defense against risks associated with outsourcing services to third parties. The Third Party Risk team works closely with various stakeholders, including Procurement, Risk SMEs, and Business Partners to onboard and manage vendors and other third parties, build...


  • San Jose, California, United States VDart Inc Full time

    Job OverviewPosition: Third-Party Risk Management (TPRM) AnalystCompany: VDart IncLocation: Santa Clara, CA and San Jose, CA (Onsite)Contract Duration: 12+ MonthsPosition Summary:The Third-Party Risk Management (TPRM) Analyst will play a pivotal role in collaborating with IT stakeholders, project managers, and business leaders to conduct vendor risk...


  • San Francisco, California, United States SGS Full time

    Job DescriptionSGS is seeking a skilled Third Party Pre-Shipment Inspector to join our team. As a Pre-Shipment Inspector, you will be responsible for verifying the quality and condition of goods and materials before they are shipped.Responsibilities:Verify the accuracy of shipping documents, including bills of lading and packing lists.Conduct physical...


  • San Francisco, California, United States Recruiting from Scratch Full time

    About the RoleWe are seeking a highly skilled Cryptography and Cybersecurity Expert to join our team at Recruiting from Scratch. As a key member of our organization, you will play a crucial role in maintaining the security and integrity of our decentralized AI cloud platform.Key ResponsibilitiesEnhance and design the Proof of Sampling protocol to ensure the...


  • San Francisco, California, United States Rippling Full time

    About Rippling Rippling provides organizations with a unified platform to manage HR, IT, and Finance. It consolidates various workforce systems that are typically dispersed throughout a company, such as payroll, expenses, benefits, and technology assets. For the first time, you can oversee and automate every aspect of the employee lifecycle within a single...


  • San Francisco, California, United States Postman, Inc. Full time

    Senior Security Risk AnalystPostman is recognized as the premier collaboration platform for API development. Our innovative features simplify every phase of API creation and enhance teamwork, enabling the development of superior APIs more efficiently. With over 30 million developers and 500,000 organizations globally utilizing Postman, we are committed to...


  • San Francisco, California, United States Postman, Inc. Full time

    Senior Security Risk AnalystPostman, Inc. stands as a premier collaboration platform dedicated to API development. Our innovative features simplify the API building process and enhance teamwork, enabling the creation of superior APIs more efficiently. With over 30 million developers and 500,000 organizations utilizing Postman globally, we are on a mission to...


  • San Jose, California, United States Frontend Arts Full time

    Frontend Arts is a dynamic organization dedicated to enhancing team collaboration and project management through innovative solutions. Our mission is to empower teams to streamline workflows and create secure solutions using intuitive, no-code tools. We are in search of a dedicated professional to contribute to the success of our Third Party Risk Management...