Information Security Third Party Risk Management Specialist
פורסם אתמול · 0 מועמדים
התפקיד במילים פשוטות
התפקיד כולל ניהול והובלה של תחום סיכוני צד שלישי (TPRM) ואבטחת מידע בשרשרת האספקה של החברה. ביומיום, העובד יבצע הערכות אבטחה לספקי צד שלישי (כמו ספקי ענן ו-SaaS), ינתח שאלוני ציות, יטמיע דרישות אבטחה בחוזים מול ספקים וינטר סיכונים באופן רציף.
- 5+ years of experience in Information Security
- At least 3 years focused on Third-Party Risk Management, vendor assessments, or supply chain security
- Experience with security questionnaire frameworks and vendor risk scoring methodologies
- Understanding of compliance frameworks (SOC2, ISO 27001, GDPR, HIPAA, etc.) and translating requirements into vendor terms
- Familiarity with vendor contracts, SLAs, data processing agreements, and security clauses, including negotiation with legal and procurement
- Experience with high-tech or SaaS companies managing large vendor ecosystems
- Experience with remote-first or distributed organizations and working asynchronously across time zones and cultures
- Hands-on experience building or scaling vendor risk management processes from scratch
- Background in procurement, contract management, or vendor management
- Familiarity with TPRM tools or GRC platforms (OneTrust, Archer, Nessus, Qualys, etc.)
חולץ מתיאור המשרה · מתעדכן אוטומטית
למי זה מתאים
מתאים לאנשי אבטחת מידע עם לפחות 5 שנות ניסיון, מתוכן לפחות 3 שנים בתחום סיכוני ספקים (TPRM) והיכרות מעמיקה עם תקני ציות (כמו SOC2 ו-ISO 27001). פחות מתאים למי שאינם בעלי רקע בבדיקת נאותות של ספקים או במשא ומתן על סעיפי אבטחה בחוזים.
תיאור המשרה המלא
המשרה המקורית · נשמר לעיוןWho We Are Is What We Do.
Deel is the all-in-one payroll and HR platform for global teams. Our vision is to unlock global opportunity for every person, team, and business. Built for the way the world works today, Deel combines HRIS, payroll, compliance, benefits, performance, and equipment management into one seamless platform. With AI-powered tools and a fully owned payroll infrastructure, Deel supports every worker type in 150+ countries—helping businesses scale smarter, faster, and more compliantly.
Among the largest globally distributed companies in the world, our team of 7,000 spans more than 100 countries, speaks 74 languages, and brings a connected and dynamic culture that drives continuous learning and innovation for our customers.
Why should you be part of our success story?
As the fastest-growing Software as a Service (SaaS) company in history, Deel is transforming how global talent connects with world-class companies – breaking down borders that have traditionally limited both hiring and career opportunities. We're not just building software; we're creating the infrastructure for the future of work, enabling a more diverse and inclusive global economy. In 2024 alone, we paid $11.2 billion to workers in nearly 100 currencies and provided healthcare and benefits to workers in 109 countries—ensuring people get paid and protected, no matter where they are.
Our momentum is reflected in our achievements and customer satisfaction: CNBC Disruptor 50, Forbes Cloud 100, Deloitte Fast 500, and repeated recognition on Y Combinator's top companies list – all while maintaining a 4.83 average rating from 15,000 reviews across G2, Trustpilot, Captera, Apple and Google.
Your experience at Deel will be a career accelerator. At the forefront of the global work revolution, you'll tackle complex challenges that impact millions of people's working lives. With our momentum—backed by a $17.3 billion valuation and $1 B in Annual Recurring Revenue (ARR) in just over five years—you'll drive meaningful impact while building expertise that makes you a sought-after leader in the transformation of global work.
We are looking for an experienced Information Security Third Party Risk Management (TPRM) Specialist to improve and oversee our vendor risk management program. This role requires deep expertise in security assessments, vendor evaluation frameworks, compliance questionnaire management, and risk lifecycle governance. The ideal candidate will establish and improve current scalable processes to evaluate, monitor, and remediate third-party risks across our growing global ecosystem—including SaaS providers, cloud vendors, AI services, and critical infrastructure partners. You will drive security decision-making, translate compliance requirements into vendor contracts, and maintain audit trails that demonstrate organizational accountability across the third-party landscape.
The ideal candidate combines vendor risk expertise with proven independent ability and thrives information security best practices in a fast-paced, global, and high-growth environment.
Key Areas of Expertise
• Third-Party Risk Assessment & Vendor Evaluation: Deep experience conducting security questionnaires, reviewing certifications (SOC2, ISO 27001, etc.), and scoring vendor risk profiles.
• Compliance & Contract Governance: Expertise in translating security and compliance requirements into vendor contracts, SLAs, and audit requirements.
• SaaS Security Posture & AI Risk Management: Understanding of cloud service security, SaaS-specific vulnerabilities, and emerging AI vendor risks.
• Working with TPRM software like Panorays, OneTrust etc.
• Providing security requirements for implementations of new systems.
Responsibilities
• Vendor Risk Assessment & Intake: Design and manage vendor security assessment workflows. Integrate security questionnaires (Panorays, etc.) into standardized evaluation processes. Conduct deep-dive security reviews of third-party SaaS providers, cloud vendors, and AI services to determine risk profiles.
• Risk Scoring & Metrics: Develop and maintain vendor risk scoring models aligned with organizational risk appetite. Track key risk indicators (KRIs) for active vendors and escalate material changes in vendor security posture.
• Compliance Questionnaire Management: Own the questionnaire lifecycle—intake, response validation, remediation tracking, and integration into risk decision workflows. Ensure vendor responses are accurate and evidence-backed.
• Contract & SLA Negotiation: Partner with procurement and legal to embed security requirements in vendor contracts. Negotiate security clauses, data protection terms, audit rights, and incident notification obligations.
• Vendor Incident & Breach Management: Monitor and respond to third-party security incidents. Lead investigation into vendor breaches affecting organizational data. Coordinate remediation and assess impact on compliance posture.
• Continuous Vendor Monitoring: Establish ongoing monitoring of active vendors through automated tools, re-assessments, and public breach intelligence. Maintain audit trails for all vendor risk decisions and remediation activities.
• TPRM Policy & Governance: Author and maintain vendor risk management policies, vendor tiering frameworks, and assessment standards. Ensure alignment with regulatory requirements (SOC2, ISO 27001, GDPR, etc.).
• Cross-functional Collaboration: Partner with DevSecOps, procurement, legal, compliance, and business teams to translate vendor risk findings into business decisions. Drive adoption of vendor risk assessments across the organization.
• Vendor Risk Reporting & Insights: Produce executive reporting on vendor risk trends, concentration risk, and remediation progress. Identify patterns in vendor vulnerabilities to inform procurement strategy.
Qualifications
• 5+ years of experience in Information Security, with at least 3 years focused on Third-Party Risk Management, vendor assessments, or supply chain security.
• Proven experience with security questionnaire frameworks (Panorays, OneTrust, Archer, etc.) and vendor risk scoring methodologies.
• Strong understanding of compliance frameworks (SOC2, ISO 27001, GDPR, HIPAA, etc.) and ability to translate requirements into vendor terms.
• Familiarity with vendor contracts, SLAs, data processing agreements, and security clauses. Comfortable negotiating with legal and procurement.
• Ability to assess complex vendor security postures, identify gaps, and recommend risk mitigation strategies.
• Working knowledge of cloud platforms (AWS, Azure, GCP), SaaS architecture, and common vendor security controls.
Nice to haves
• Experience with high-tech or SaaS companies managing large vendor ecosystems.
• Experience with remote-first or distributed organizations.
• Experience working asynchronously across different time zones and cultures.
• Hands-on experience building or scaling vendor risk management processes from scratch.
• Background in procurement, contract management, or vendor management.
• Familiarity with TPRM tools or GRC platforms (OneTrust, Archer, Nessus, Qualys, etc.).
• Experience with Panorays as a TPRM tool.
Total Rewards
Our workforce deserves fair and competitive pay that meets them where they are. With scalable benefits, rewards, and perks, our total rewards programs reflect our commitment to inclusivity and access for all.
• Our salary range reflects gross base salary. For commercial roles with commission eligibility, this figure represents On-Target Earnings (OTE), inclusive of base salary and target commission.
• Salary ranges are quoted in USD as a consistent global reference. Your offer will be localized to your country's currency using a market-aligned conversion.
• Final pay is based on objective, job-related criteria including experience, skills, and location.
• We don't ask about salary history. Offers are based on the role and what you bring to it.
Some things you'll enjoy
• Stock grant opportunities dependent on your role, employment status and location
• Additional perks and benefits based on your employment status and country
• Optional flexible working office membership, with IWG
At Deel, we're an equal-opportunity employer that values diversity and positively encourage applications from suitably qualified and eligible candidates regardless of race, religion, sex, national origin, gender, sexual orientation, age, marital status, veteran status, disability status, pregnancy or maternity or other applicable legally protected characteristics.
Unless otherwise agreed, we will communicate with job applicants using Deel-specific emails, which include @deel.com and other acquired company emails like @payspace.com and @paygroup.com. You can view the most up-to-date job listings at Deel by visiting our careers page.
Deel welcomes persons with disabilities to apply to any of our open roles. We will provide application and/or interview accommodations on request throughout the recruitment, selection and assessment process for applicants with disabilities or other needs. If you require application and/or interview accommodations, please inform our Talent Acquisition Team via email (recruiting@deel.com) and a team member will be in touch to ensure your equal participation.
As part of our hiring process, we primarily rely on interviews and role-related assessments. In limited cases, we may also consider informal background information relevant to the role, in line with our privacy and fairness obligations.
This application process may utilise Automated Employment Decision Tools (AEDT) and AI systems to assist in evaluating candidates based on experience level, technical skills and qualifications. This processing is conducted in compliance with applicable Data Protection, AI Governance and Labour Laws. We ensure human oversight is maintained in all final hiring decisions. Your personal data is not used to train AI models. For more information on how we process your personal data, please see our Recruitment Privacy Policy.
• For NYC Residents: In accordance with NYC Local Law 144, an independent bias audit has been conducted on AEDT
שאלות על המשרה
- המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
- 5+ years of experience in Information Security, At least 3 years focused on Third-Party Risk Management, vendor assessments, or supply chain security, Experience with security questionnaire frameworks and vendor risk scoring methodologies, Understanding of compliance frameworks (SOC2, ISO 27001, GDPR, HIPAA, etc.) and translating requirements into vendor terms, Familiarity with vendor contracts, SLAs, data processing agreements, and security clauses, including negotiation with legal and procurement