Leads the execution and continuous improvement of Cloudflare’s third-party security risk program, including vendor assessments, risk decisions, contract support, and monitoring. Requires 8+ years in Security GRC, deep vendor-risk expertise, control-framework knowledge, and strong cross-functional leadership.
Salary not listed
On-site8+ YOESecurity Engineering
About the role
Responsibilities
Own and drive operational execution of the third-party risk management program, including vendor risk assessments, security contract terms, and continuous monitoring.
Serve as the subject-matter expert for vendor security review methodology, vendor tiering, and risk treatment decisions.
Lead vendor risk assessments and apply and refine security policies and standards for cloud, contractor, software, hardware, and data-center engagements.
Identify workflow inefficiencies and implement improvements that increase effectiveness, quality, and scalability.
Coordinate operational work, escalations, assessments, and projects across the team.
Mentor Third Party Risk Management Specialists on assessment methodology, risk decisions, tooling, and best practices.
Assess risk findings, compensating controls, policy exceptions, and acceptable risk thresholds; serve as the escalation point for complex cases.
Support negotiation of security contract terms and maintain guidance for Contracts and Legal teams.
Coordinate with Sourcing, Contracts, Legal, Privacy, and Security teams across the vendor lifecycle.
Support the design and improvement of Procurement/GRC tools and AI workflows.
Report third-party risk posture and program operations to security leadership.
Requirements
8+ years of experience in Security GRC.
Deep, hands-on experience operating a third-party or vendor risk program end to end.
Subject-matter expertise in security control frameworks, including ISO 27001, SOC 2, PCI, and NIST 800-53.
Understanding of security contract terms and vendor negotiation support.
Experience mentoring peers and providing technical guidance.
Track record of identifying process inefficiencies and driving operational improvements at scale.
Strong cross-functional influence and coordination skills.
Strong organizational, analytical, and interpersonal skills.
Additional Information
Applicants who progress to the offer stage may be asked to attend an in-person interview at a Cloudflare office or hub.
The position may require access to information protected under U.S. export control laws; employment may be conditioned on authorization to receive controlled technology without export-license sponsorship.
Leads Fingerprint’s security, IT operations, and compliance function, managing a team and owning application security, SOC 2, identity governance, and enterprise security communications. Requires 7+ years across security, IT, or GRC, team management experience, and demonstrated SOC 2 and application security ownership.
Salary not listedRemote7+ YOESecurity Engineering
Senior Product Security Engineer - QRA
ZooxFoster City, CA +3
Conduct quantitative risk assessments, threat modeling, and cybersecurity standards analysis across autonomous vehicles and cloud services. The role requires a master’s degree, 7+ years of experience, strong systems and embedded-security expertise, and the ability to produce high-quality technical and regulatory deliverables.
217k – 307k/yrHybrid7+ YOESecurity Engineering
Security Engineer - Threat Detection
SnowflakeUnited States
Builds and evolves AI-assisted threat detection, automation, and analytics at cloud scale. Requires 8+ years of security engineering experience, strong Python or Go skills, production software practices, cloud security expertise, and experience with large-scale telemetry and agentic workflows.
211k – 304k/yrRemote8+ YOESecurity Engineering
Senior Information Security Engineer
ZooxFoster City, CA
Senior Information Security Engineer who builds SIEM detections, SOAR automation, and LLM-powered alert-triage workflows. The role requires 8+ years in information security or DevSecOps, strong Python and AWS expertise, and hands-on incident response experience.
190k – 228k/yrHybrid8+ YOESecurity Engineering
Safety Operations Lead
Thinking Machines LabSan Francisco, CA
Leads operational trust and safety for human-AI collaboration products by reviewing abuse cases, enforcing policy, and building automation and detection systems. Requires 7+ years of recurring case-queue experience plus expertise in AI abuse risks, policy operations, and production safety incidents.