Senior InfoSec Engineer, Vendor Risk (TPRM)
פורסם אתמול · 0 מועמדים
- 5+ years in Information Security, with 3+ years driving third-party risk management, vendor assessments, or supply chain security
- Hands-on experience with AI-powered TPRM tools (Panorays, OneTrust) and automation-driven vendor risk workflows
- Panorays
- OneTrust
- Expertise in security questionnaire frameworks, risk scoring methodologies, and compliance requirement translation (SOC2, ISO 27001, GDPR, HIPAA, etc.)
- Experience scaling vendor risk programs from 0–1 or 1–many using automation
- Background in procurement, contract management, or vendor lifecycle management
- Experience with GRC platforms (Archer, Nessus, Qualys) or security automation platforms
- Familiarity with AI/ML risk assessment or third-party AI vendor evaluation
- Experience with high-tech or SaaS companies managing large vendor ecosystems
חולץ מתיאור המשרה · מתעדכן אוטומטית
תיאור המשרה המלא
המשרה המקורית · נשמר לעיוןWho We Are Is What We Do.
Deel is the all-in-one payroll and HR platform for global teams. Our vision is to unlock global opportunity for every person, team, and business. Built for the way the world works today, Deel combines HRIS, payroll, compliance, benefits, performance, and equipment management into one seamless platform. With AI-powered tools and a fully owned payroll infrastructure, Deel supports every worker type in 150+ countries—helping businesses scale smarter, faster, and more compliantly.
Among the largest globally distributed companies in the world, our team of 7,000 spans more than 100 countries, speaks 74 languages, and brings a connected and dynamic culture that drives continuous learning and innovation for our customers.
Why should you be part of our success story?
As the fastest-growing Software as a Service (SaaS) company in history, Deel is transforming how global talent connects with world-class companies – breaking down borders that have traditionally limited both hiring and career opportunities. We're not just building software; we're creating the infrastructure for the future of work, enabling a more diverse and inclusive global economy. In 2024 alone, we paid $11.2 billion to workers in nearly 100 currencies and provided healthcare and benefits to workers in 109 countries—ensuring people get paid and protected, no matter where they are.
Our momentum is reflected in our achievements and customer satisfaction: CNBC Disruptor 50, Forbes Cloud 100, Deloitte Fast 500, and repeated recognition on Y Combinator's top companies list – all while maintaining a 4.83 average rating from 15,000 reviews across G2, Trustpilot, Captera, Apple and Google.
Your experience at Deel will be a career accelerator. At the forefront of the global work revolution, you'll tackle complex challenges that impact millions of people's working lives. With our momentum—backed by a $17.3 billion valuation and $1 B in Annual Recurring Revenue (ARR) in just over five years—you'll drive meaningful impact while building expertise that makes you a sought-after leader in the transformation of global work.
We're looking for an experienced Information Security Leader to own third-party risk as a strategic security function. You'll design and scale a vendor risk program that combines deep security expertise with AI-driven automation. Your mandate: move vendor security from reactive compliance to proactive risk intelligence—evaluating, monitoring, and remediating third-party risks across our global SaaS, cloud, and AI vendor ecosystem. You'll make critical security decisions that shape procurement strategy and protect our data, systems, and brand.
The ideal candidate combines deep vendor risk expertise with hands-on automation experience, thrives on translating security best practices into scalable processes, and is energized by solving complex problems in a fast-paced, global, high-growth environment.
KEY AREAS OF EXPERTISE
• Third-Party Risk Assessment & Vendor Evaluation
Deep experience conducting security assessments, reviewing certifications (SOC2, ISO 27001, etc.), and evaluating vendor security postures. Proven ability to translate complex vendor security data into clear risk decisions that inform procurement and go/no-go calls.
• AI & Automation in TPRM
Hands-on experience leveraging AI-powered tools (Panorays, OneTrust, etc.) to automate vendor assessment, risk scoring, and continuous monitoring. Proven ability to design workflows that replace manual processes with intelligent automation—questionnaire parsing, anomaly detection, risk trending. Experience building or scaling vendor risk programs using automation to increase assessment velocity without sacrificing security rigor.
• Compliance & Contract Governance
Expertise in translating security and compliance requirements into vendor contracts, SLAs, and audit obligations. Comfortable negotiating security terms with legal, procurement, and vendors. Working understanding of GDPR, SOC2, ISO 27001, HIPAA, and other compliance frameworks.
• SaaS Security Posture & AI Risk Management
Understanding of cloud service security, SaaS-specific vulnerabilities, and emerging AI vendor risks. Ability to assess third-party AI tools for data handling, model security, and supply chain risks. Working knowledge of cloud platforms (AWS, Azure, GCP) and container orchestration.
• TPRM Tools & GRC Platforms
Hands-on proficiency with TPRM software (Panorays, OneTrust, etc.), including configuration, workflow design, and integration. Familiarity with GRC platforms, risk scoring engines, and data visualization for risk reporting.
Responsibilities
• Vendor Risk Assessment & Intake
Design intelligent vendor assessment workflows using AI-powered tools to automate intake, questionnaire parsing, and initial risk scoring. Own the security assessment process end-to-end—translate complex vendor security data into clear risk decisions. Lead deep-dive security reviews of third-party SaaS providers, cloud vendors, and AI services to validate AI-scored risk profiles and inform go/no-go decisions.
• Risk Scoring & Metrics
Architect vendor risk scoring models informed by AI-driven metrics and automation. Configure and tune risk scoring engines (Panorays, etc.) to reflect organizational risk appetite. Establish real-time KRI dashboards that flag material changes in vendor security posture—turning data into actionable intelligence for security and business teams.
• Compliance Questionnaire Management
Own the questionnaire lifecycle—intake, response validation, remediation tracking, and integration into risk decision workflows. Ensure vendor responses are accurate and evidence-backed. Use automation to parse responses, flag inconsistencies, and accelerate review cycles.
• Contract & SLA Negotiation
Partner with procurement and legal to embed security requirements in vendor contracts. Negotiate security clauses, data protection terms, audit rights, and incident notification obligations. Translate vendor risk findings into specific contract language.
• Vendor Incident & Breach Management
Monitor and respond to third-party security incidents. Lead investigation into vendor breaches affecting organizational data. Coordinate remediation and assess impact on compliance posture and risk profile.
• Continuous Vendor Monitoring
Engineer continuous vendor monitoring using AI-powered threat intelligence, automated re-assessments, and breach detection. Design monitoring workflows that scale beyond manual review—catch security degradation, supply chain attacks, and emerging AI-related risks before they impact operations. Maintain audit trails for all vendor risk decisions and remediation activities.
• TPRM Policy & Governance
Author and maintain vendor risk management policies, vendor tiering frameworks, and assessment standards. Ensure alignment with regulatory requirements (SOC2, ISO 27001, GDPR, etc.). Build repeatable processes that scale as the vendor ecosystem grows.
• Cross-functional Collaboration
Partner with DevSecOps, procurement, legal, compliance, and business teams to translate vendor risk findings into business decisions. Drive adoption of vendor risk assessments across the organization. Communicate security risk in language stakeholders understand.
• Vendor Risk Reporting & Insights
Produce executive reporting on vendor risk trends, concentration risk, and remediation progress. Use data and visualization to identify patterns in vendor vulnerabilities and inform procurement strategy. Translate risk metrics into business impact.
Core Qualifications
• 5+ years in Information Security, with 3+ years driving third-party risk management, vendor assessments, or supply chain security.
• Proven hands-on experience with AI-powered TPRM tools (Panorays, OneTrust) and automation-driven vendor risk workflows. Able to configure tools, interpret AI-scored risks, and design automation that scales assessment velocity.
• Expertise in security questionnaire frameworks, risk scoring methodologies, and compliance requirement translation (SOC2, ISO 27001, GDPR, HIPAA, etc.).
• Strong understanding of vendor contracts, SLAs, DPAs, and security negotiation. Comfortable partnering with legal and procurement on security terms.
• Ability to assess complex vendor security postures, interpret security data, and make risk-informed recommendations.
• Working knowledge of cloud platforms (AWS, Azure, GCP), SaaS architecture, and AI vendor risk considerations.
NICE TO HAVES
• Experience scaling vendor risk programs from 0–1 or 1–many using automation.
• Background in procurement, contract management, or vendor lifecycle management.
• Experience with GRC platforms (Archer, Nessus, Qualys) or security automation platforms.
• Familiarity with AI/ML risk assessment or third-party AI vendor evaluation.
• Experience with high-tech or SaaS companies managing large vendor ecosystems.
• Experience working asynchronously across different time zones and cultures in remote-first or distributed organizations.
Total Rewards
Our workforce deserves fair and competitive pay that meets them where they are. With scalable benefits, rewards, and perks, our total rewards programs reflect our commitment to inclusivity and access for all.
• Our salary range reflects gross base salary. For commercial roles with commission eligibility, this figure represents On-Target Earnings (OTE), inclusive of base salary and target commission.
• Salary ranges are quoted in USD as a consistent global reference. Your offer will be localized to your country's currency using a market-aligned conversion.
• Final pay is based on objective, job-related criteria including experience, skills, and location.
• We don't ask about salary history. Offers are based on the role and what you bring to it.
Some things you'll enjoy
• Stock grant opportunities dependent on your role, employment status and location
• Additional perks and benefits based on your employment status and country
• Optional flexible working office membership, with IWG
At Deel, we're an equal-opportunity employer that values diversity and positively encourage applications from suitably qualified and eligible candidates regardless of race, religion, sex, national origin, gender, sexual orientation, age, marital status, veteran status, disability status, pregnancy or maternity or other applicable legally protected characteristics.
Unless otherwise agreed, we will communicate with job applicants using Deel-specific emails, which include @deel.com and other acquired company emails like @payspace.com and @paygroup.com. You can view the most up-to-date job listings at Deel by visiting our careers page.
Deel welcomes persons with disabilities to apply to any of our open roles. We will provide application and/or interview accommodations on request throughout the recruitment, selection and assessment process for applicants with disabilities or other needs. If you require application and/or interview accommodations, please inform our Talent Acquisition Team via email (recruiting@deel.com) and a team member will be in touch to ensure your equal participation.
As part of our hiring process, we primarily rely on interviews and role-related assessments. In limited cases, we may also consider informal background information relevant to the role, in line with our privacy and fairness obligations.
This application process may utilise Automated Employment Decision Tools (AEDT) and AI systems to assist in evaluating candidates based on experience level, technical skills and qualifications. This processing is conducted in compliance with applicable Data Protection, AI Governance and Labour Laws. We ensure human oversight is maintained in all final hiring decisions. Your personal data is not used to train AI models. For more information on how we process your personal data, please see our Recruitment Privacy Policy.
• For NYC Residents: In accordance with NYC Local Law 144, an independent bias audit has been conducted on AEDT
שאלות על המשרה
- המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
- 5+ years in Information Security, with 3+ years driving third-party risk management, vendor assessments, or supply chain security, Hands-on experience with AI-powered TPRM tools (Panorays, OneTrust) and automation-driven vendor risk workflows, Panorays, OneTrust, Expertise in security questionnaire frameworks, risk scoring methodologies, and compliance requirement translation (SOC2, ISO 27001, GDPR, HIPAA, etc.)