Security Third Party Risk Management Specialist III

Cloudflare

Lisboa

Presencial

EUR 60 000 - 80 000

Tempo integral

14 dias+

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Vantagens oferecidas por esta oferta de emprego

Equal opportunity employer
Diversity and inclusiveness commitment
Disability accommodations available

Resumo da oferta

A global cybersecurity company in Lisbon is seeking a Security Third Risk Management Specialist to manage vendor security reviews, address third-party risks, and support certification audits. Ideal candidates should have 5-8 years of experience in Security Governance, Risk, and Compliance, with a strong ability to analyze security documentation such as ISO 27001 and SOC 2. This role includes opportunities for collaboration across various teams and the possibility of occasional travel to global locations.

Qualificações

  • 5-8 years experience in Security Governance, Risk, and Compliance (GRC).
  • Experience with ISO 27001, SOC 2, PCI DSS audit reports.
  • Ability to work independently and possess a sense of curiosity.

Responsabilidades

  • Execute vendor security reviews and document findings.
  • Identify third-party security risks and recommend options.
  • Maintain Cloudflare’s Vendor Master list of critical vendors.

Conhecimentos

Vendor security documentation review
Identification of security risks
Organizational skills
Analytical skills
Interpersonal skills

Descrição da oferta de emprego

About Cloudflare

About Us At Cloudflare, we are on a mission to help build a better Internet. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Our network powers millions of websites and Internet properties for customers ranging from individual bloggers to Fortune 500 companies. Cloudflare’s global network routes web traffic to improve performance and reduce spam and other attacks. We are committed to building a diverse and inclusive team and hire based on potential, supporting employees throughout their time with Cloudflare. Available Locations: Lisbon, Portugal.

We are looking for curious and empathetic individuals who are committed to developing themselves and learning new skills. Come join us!

The Team

We are looking to hire an experienced Security Third Risk Management Specialist on our Governance, Risk, and Compliance team. This role will be responsible for completing vendor security reviews, maintaining our vendor master list, and managing Cloudflare’s Third Party Risk Program.

This is an opportunity to join a rapidly scaling world-class security organization within a billion-dollar business. We guarantee that you won’t get bored.

What You'll Do
  • Execute vendor security reviews by collecting and analyzing vendor security control documentation and audit reports.
  • Identify third-party security risks, document findings, and recommend risk treatment options.
  • Determine security contract requirements and communicate these to the Contracts & Legal teams.
  • Maintain Cloudflare’s Vendor Master, including our list of Critical vendors.
  • Support Cloudflare’s customer-facing and incident response teams by ensuring our vendors are not affected by recent zero-day vulnerabilities or security incidents.
  • Support Cloudflare’s security certification audits by providing evidence of vendor security reviews.
  • Partner with stakeholders across Procurement, IT, Contracts, Legal, and Privacy to ensure vendor due diligence is completed efficiently.
  • Lead projects to improve the Vendor Security Review process, workflow, and tooling.
  • Some travel may be required to engage teammates and stakeholders in San Francisco, Austin, or other global Cloudflare locations.
Desirable Skills, Knowledge and Experience
  • Experience typically gained in 5-8 years working in Security GRC
  • Experience reviewing vendor security documentation including ISO 27001, SOC 2, PCI DSS, and other audit reports
  • Experience identifying security controls gaps, determining risk ratings, and recommending mitigating controls
  • Familiarity with security contract requirements
  • Strong organizational, analytical, and interpersonal skills
  • Self-starter with the ability to work independently with a sense of curiosity
What Makes Cloudflare Special

We’re not just a highly ambitious, large-scale technology company. We’re a technology company with a soul. Protecting the free and open Internet is fundamental to our mission.

Projects

  • Project Galileo: Since 2014, we’ve equipped more than 2,400 journalism and civil society organizations in 111 countries with tools to defend themselves against attacks that would censor their work, at no cost.
  • Athenian Project: In 2017, we created the Athenian Project to protect state and local governments, serving more than 425 local government election websites in 33 states.
  • 1.1.1.1: We released 1.1.1.1 to make the Internet faster, more secure, and privacy-centric. We do not store client IP addresses and will continue to honor our privacy commitments.

Sound like something you’d like to be a part of? We’d love to hear from you!

This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations. Any offer of employment may be conditioned on authorization to receive software or technology controlled under these laws without sponsorship for an export license.

Cloudflare is proud to be an equal opportunity employer. We are committed to providing equal employment opportunity for all people and value diversity and inclusiveness. All qualified applicants will be considered for employment without regard to race, color, religion, sex, gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship, age, physical or mental disability, medical condition, family care status, or any other basis protected by law. We are an AA/Veterans/Disabled Employer.

Cloudflare provides reasonable accommodations to qualified individuals with disabilities. If you require an accommodation to apply, please contact us at hr@cloudflare.com or via mail at 101 Townsend St. San Francisco, CA 94107.

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Incident Response Analyst
Incident Response Analyst

Webhosting • Lisboa

Híbrido
EUR 54 000 - 75 000
Distributed Systems Engineer - Data Platform - Analytics and Alerts
Distributed Systems Engineer - Data Platform - Analytics and Alerts

Cloudflare • Lisboa

Presencial
EUR 54 000 - 91 000
Equity plan
401(k) Retirement Savings Plan
Employee Stock Participation Plan
+1
Distributed Systems Engineer - Data Platform - Logs and Audit Logs
Distributed Systems Engineer - Data Platform - Logs and Audit Logs

Cloudflare • Lisboa

Presencial
EUR 54 000 - 91 000
Equity plan
Flexible paid time off
Customer Experience Manager – French Speaking
Customer Experience Manager – French Speaking

Webhosting • Lisboa

Híbrido
EUR 53 000 - 73 000
Customer Reliability Engineer
Customer Reliability Engineer

Webhosting • Lisboa

Híbrido
EUR 61 000 - 84 000
Equity plan
Senior Customer Experience Manager - German Speaking
Senior Customer Experience Manager - German Speaking

Cloudflare • Lisboa

Presencial
EUR 63 000 - 87 000
Customer Experience Manager - French Speaking
Customer Experience Manager - French Speaking

WinsAbove • Lisboa

Presencial
EUR 53 000 - 73 000
Equity plan
Customer Experience Manager - Russian Speaking
Customer Experience Manager - Russian Speaking

WinsAbove • Lisboa

Presencial
EUR 53 000 - 73 000
Equity plan
Sales incentive
Systems Engineer, Network Automation
Systems Engineer, Network Automation

Triwill Group • Lisboa

Presencial
EUR 54 000 - 68 000
Equity plan
Benefits package
Senior Renewals Account Manager - German Speaking
Senior Renewals Account Manager - German Speaking

WinsAbove • Lisboa

Presencial
EUR 63 000 - 87 000