Security Third Party Risk Management Lead

CloudflareAustin, TX
Onsite

About The Position

The Security Third Party Risk Management Lead is a senior individual-contributor role at Cloudflare. This role is responsible for the technical and operational leadership of the Third Party Risk function, including the execution and continuous improvement of vendor and data center security reviews. The lead will serve as the subject matter expert for the team and mentor Third Party Risk Management Specialists. This role requires expertise, coordination, and influence to set the operational standards for the program, drive projects for improvement, and represent the team in interactions with Procurement and other cross-functional partners. While direct people management is handled by the Director of Information Security GRC, this role will mentor specialists on assessment methodology, risk decisions, and best practices.

Requirements

  • Experience typically gained in 8+ years working in Security GRC
  • Deep, hands-on expertise operating a third party / vendor risk program end to end.
  • Subject-matter expertise across security control frameworks — ISO 27001, SOC 2, PCI, NIST 800-53.
  • Solid understanding of security contract terms and vendor negotiation support.
  • Demonstrated ability to mentor peers and provide technical guidance.
  • A track record of identifying process inefficiencies and driving operational improvements at scale.
  • Strong ability to influence and coordinate across cross-functional teams.
  • Strong organizational, analytical, and interpersonal skills.

Responsibilities

  • Own and drive the operational execution of the third party risk management program, including vendor risk assessments, security contract terms, and continuous monitoring, ensuring efficiency and high standards.
  • Serve as the subject matter expert and technical resource for vendor security review methodology, vendor tiering, and risk treatment decisions.
  • Lead the vendor risk assessment process, applying and refining security policies and standards for various vendor engagements (cloud, contractor, software, hardware, data centers).
  • Proactively identify and implement improvements to vendor security workflows to enhance effectiveness, quality, and scalability.
  • Coordinate the team's operational work, including driving assessments, escalations, and projects to completion.
  • Provide technical guidance and mentorship to Third Party Risk Management Specialists on assessment methodology, risk decisions, tooling, and best practices.
  • Make timely, well-reasoned decisions on risk findings and policy exceptions, assessing risk, compensating controls, and acceptable risk thresholds, and act as an escalation point for complex cases.
  • Support the negotiation of security contract terms with vendors by maintaining guidance for Contracts/Legal teams and resolving contract escalations.
  • Act as a primary point of coordination with Sourcing, Contracts, Legal, Privacy, and Security teams throughout the vendor lifecycle (onboarding, implementation, monitoring, offboarding), influencing the integration of vendor security.
  • Support the design, implementation, and improvement of Procurement/GRC tools and AI workflows.
  • Report on third party risk posture and program operations to the Director, Information Security GRC, and security leadership.

Benefits

  • Competitive salary and benefits package
  • Opportunity to work on a global network
  • Culture of iteration and AI-driven innovation
  • Equal opportunity employer
  • Commitment to diversity and inclusiveness
  • Reasonable accommodations for individuals with disabilities
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service