# Security Third Party Risk Management Lead

**Company:** [Cloudflare](https://hotfix.jobs/companies/cloudflare)
**Location:** Austin, TX
**Role:** Security Engineering
**Experience:** 8+ years
**Skills:** security grc, third-party risk management, vendor risk assessments, ISO 27001, SOC 2, PCI, nist 800-53, security contract terms, vendor negotiation, security policies, continuous monitoring, grc tools, AI Workflows
**Posted:** 2026-08-04

> Leads the execution and continuous improvement of Cloudflare’s third-party security risk program, including vendor assessments, risk decisions, contract support, and monitoring. Requires 8+ years in Security GRC, deep vendor-risk expertise, control-framework knowledge, and strong cross-functional leadership.

## Job Description

## Responsibilities
- Own and drive operational execution of the third-party risk management program, including vendor risk assessments, security contract terms, and continuous monitoring.
- Serve as the subject-matter expert for vendor security review methodology, vendor tiering, and risk treatment decisions.
- Lead vendor risk assessments and apply and refine security policies and standards for cloud, contractor, software, hardware, and data-center engagements.
- Identify workflow inefficiencies and implement improvements that increase effectiveness, quality, and scalability.
- Coordinate operational work, escalations, assessments, and projects across the team.
- Mentor Third Party Risk Management Specialists on assessment methodology, risk decisions, tooling, and best practices.
- Assess risk findings, compensating controls, policy exceptions, and acceptable risk thresholds; serve as the escalation point for complex cases.
- Support negotiation of security contract terms and maintain guidance for Contracts and Legal teams.
- Coordinate with Sourcing, Contracts, Legal, Privacy, and Security teams across the vendor lifecycle.
- Support the design and improvement of Procurement/GRC tools and AI workflows.
- Report third-party risk posture and program operations to security leadership.

## Requirements
- 8+ years of experience in Security GRC.
- Deep, hands-on experience operating a third-party or vendor risk program end to end.
- Subject-matter expertise in security control frameworks, including ISO 27001, SOC 2, PCI, and NIST 800-53.
- Understanding of security contract terms and vendor negotiation support.
- Experience mentoring peers and providing technical guidance.
- Track record of identifying process inefficiencies and driving operational improvements at scale.
- Strong cross-functional influence and coordination skills.
- Strong organizational, analytical, and interpersonal skills.

## Additional Information
- Applicants who progress to the offer stage may be asked to attend an in-person interview at a Cloudflare office or hub.
- The position may require access to information protected under U.S. export control laws; employment may be conditioned on authorization to receive controlled technology without export-license sponsorship.

## Similar roles

- [Senior Engineering Manager, Security & IT](https://hotfix.jobs/jobs/b26070cd-790f-4fd6-a569-bf791d46913a) - Fingerprint - Remote
- [Senior Product Security Engineer - QRA](https://hotfix.jobs/jobs/016d868c-3522-4a9b-a8fc-6de7e3855a4a) - Zoox - Foster City, CA - $217k – $307k/yr
- [Security Engineer - Threat Detection](https://hotfix.jobs/jobs/43718920-68b7-4e4a-8adf-20703e2271c3) - Snowflake - Remote - $211k – $304k/yr
- [Senior Information Security Engineer](https://hotfix.jobs/jobs/ce08603c-ef42-46b3-9e93-601ca9a1e56f) - Zoox - Foster City, CA - $190k – $228k/yr
- [Safety Operations Lead](https://hotfix.jobs/jobs/c83ceda2-d7a3-405c-ae10-b680f0dd7577) - Thinking Machines Lab - San Francisco, CA - $190k – $300k/yr

**Apply:** https://hotfix.jobs/jobs/3cdfb666-22e5-490e-9522-d87a304c2ced
**Canonical:** https://hotfix.jobs/jobs/3cdfb666-22e5-490e-9522-d87a304c2ced