Skip to content
CloudflareCloudflareAustin, TX

Security Third Party Risk Management Lead

Leads the execution and continuous improvement of Cloudflare’s third-party security risk program, including vendor assessments, risk decisions, contract support, and monitoring. Requires 8+ years in Security GRC, deep vendor-risk expertise, control-framework knowledge, and strong cross-functional leadership.

Salary not listed
On-site8+ YOESecurity Engineering

About the role

Responsibilities

  • Own and drive operational execution of the third-party risk management program, including vendor risk assessments, security contract terms, and continuous monitoring.
  • Serve as the subject-matter expert for vendor security review methodology, vendor tiering, and risk treatment decisions.
  • Lead vendor risk assessments and apply and refine security policies and standards for cloud, contractor, software, hardware, and data-center engagements.
  • Identify workflow inefficiencies and implement improvements that increase effectiveness, quality, and scalability.
  • Coordinate operational work, escalations, assessments, and projects across the team.
  • Mentor Third Party Risk Management Specialists on assessment methodology, risk decisions, tooling, and best practices.
  • Assess risk findings, compensating controls, policy exceptions, and acceptable risk thresholds; serve as the escalation point for complex cases.
  • Support negotiation of security contract terms and maintain guidance for Contracts and Legal teams.
  • Coordinate with Sourcing, Contracts, Legal, Privacy, and Security teams across the vendor lifecycle.
  • Support the design and improvement of Procurement/GRC tools and AI workflows.
  • Report third-party risk posture and program operations to security leadership.

Requirements

  • 8+ years of experience in Security GRC.
  • Deep, hands-on experience operating a third-party or vendor risk program end to end.
  • Subject-matter expertise in security control frameworks, including ISO 27001, SOC 2, PCI, and NIST 800-53.
  • Understanding of security contract terms and vendor negotiation support.
  • Experience mentoring peers and providing technical guidance.
  • Track record of identifying process inefficiencies and driving operational improvements at scale.
  • Strong cross-functional influence and coordination skills.
  • Strong organizational, analytical, and interpersonal skills.

Additional Information

  • Applicants who progress to the offer stage may be asked to attend an in-person interview at a Cloudflare office or hub.
  • The position may require access to information protected under U.S. export control laws; employment may be conditioned on authorization to receive controlled technology without export-license sponsorship.

Skills

security grcthird-party risk managementvendor risk assessmentsISO 27001SOC 2PCInist 800-53security contract termsvendor negotiationsecurity policiescontinuous monitoringgrc toolsAI Workflows
Fingerprint

Senior Engineering Manager, Security & IT

FingerprintUnited States

Leads Fingerprint’s security, IT operations, and compliance function, managing a team and owning application security, SOC 2, identity governance, and enterprise security communications. Requires 7+ years across security, IT, or GRC, team management experience, and demonstrated SOC 2 and application security ownership.

Salary not listedRemote7+ YOESecurity Engineering
Zoox

Senior Product Security Engineer - QRA

ZooxFoster City, CA +3

Conduct quantitative risk assessments, threat modeling, and cybersecurity standards analysis across autonomous vehicles and cloud services. The role requires a master’s degree, 7+ years of experience, strong systems and embedded-security expertise, and the ability to produce high-quality technical and regulatory deliverables.

217k – 307k/yrHybrid7+ YOESecurity Engineering
Snowflake

Security Engineer - Threat Detection

SnowflakeUnited States

Builds and evolves AI-assisted threat detection, automation, and analytics at cloud scale. Requires 8+ years of security engineering experience, strong Python or Go skills, production software practices, cloud security expertise, and experience with large-scale telemetry and agentic workflows.

211k – 304k/yrRemote8+ YOESecurity Engineering
Zoox

Senior Information Security Engineer

ZooxFoster City, CA

Senior Information Security Engineer who builds SIEM detections, SOAR automation, and LLM-powered alert-triage workflows. The role requires 8+ years in information security or DevSecOps, strong Python and AWS expertise, and hands-on incident response experience.

190k – 228k/yrHybrid8+ YOESecurity Engineering
Thinking Machines Lab

Safety Operations Lead

Thinking Machines LabSan Francisco, CA

Leads operational trust and safety for human-AI collaboration products by reviewing abuse cases, enforcing policy, and building automation and detection systems. Requires 7+ years of recurring case-queue experience plus expertise in AI abuse risks, policy operations, and production safety incidents.

190k – 300k/yrHybrid7+ YOESecurity Engineering