Information Security Third Party Risk Management Specialist
This is the employer's own posting, not a copy on a job board.
What we know
Is it still open?
Confirmed still open
Last checked 1h ago — checked against Deel's own job API.
We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.
How old is it?
Posted 1d ago
The date the source published, not the day we noticed it (2026-09-16). Last seen at its source 1h ago.
Is it remote?
The listing says yes
The location field doesn't say remote, so our assessment is based on the title or the description. Read the listing before applying.
Who may apply?
Greece, Germany, Hungary, Estonia, Israel, Oman, Romania, Saudi Arabia, Jordan, Montenegro, North Macedonia, Kosovo, Serbia, Malta, Portugal, Slovenia
The description states no restriction of its own. This is the source's own tag.
Pay not stated
Similar roles pay $120–155/hr
Middle 50% of 15 listings that do state pay — Legal & Compliance · all levels · EMEA · USD/hour. This employer has published no salary; this is what comparable listings we hold disclose, never converted between currencies or periods. How this is calculated.
Skills named in the ad
Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.
Carried by 1 source
-
deel employer's own board first seen 1h ago · last seen 1h ago
The listing
Who we are is what we do. Deel is the all-in-one payroll and HR platform for global teams. Our vision is to unlock global opportunity for every person, team, and business. Built for the way the world works today, Deel combines HRIS, payroll, compliance, benefits, performance, and equipment management into one seamless platform. With AI-powered tools and a fully owned payroll infrastructure, Deel supports every worker type in 150+ countries—helping businesses scale smarter, faster, and more compliantly. Among the largest globally distributed companies in the world, our team of 7,000 spans more than 100 countries, speaks 74 languages, and brings a connected and dynamic culture that drives continuous learning and innovation for our customers. Why should you be part of our success story? As the fastest-growing Software as a Service (SaaS) company in history, Deel is transforming how global talent connects with world-class companies – breaking down borders that have traditionally limited both hiring and career opportunities. We're not just building software; we're creating the infrastructure for the future of work, enabling a more diverse and inclusive global economy. In 2024 alone, we paid $11.2 billion to workers in nearly 100 currencies and provided healthcare and benefits to workers in 109 countries—ensuring people get paid and protected, no matter where they are. Our momentum is reflected in our achievements and customer satisfaction: CNBC Disruptor 50, Forbes Cloud 100, Deloitte Fast 500, and repeated recognition on Y Combinator's top companies list – all while maintaining a 4.83 average rating from 15,000 reviews across G2, Trustpilot, Captera, Apple and Google. Your experience at Deel will be a career accelerator. At the forefront of the global work revolution, you'll tackle complex challenges that impact millions of people's working lives. With our momentum—backed by a $17.3 billion valuation and $1 B in Annual Recurring Revenue (ARR) in just over five years—you'll drive meaningful impact while building expertise that makes you a sought-after leader in the transformation of global work. We are looking for an experienced Information Security Third Party Risk Management (TPRM) Specialist to improve and oversee our vendor risk management program. This role requires deep expertise in security assessments, vendor evaluation frameworks, compliance questionnaire management, and risk lifecycle governance. The ideal candidate will establish and improve current scalable processes to evaluate, monitor, and remediate third-party risks across our growing global ecosystem—including SaaS providers, cloud vendors, AI services, and critical infrastructure partners. You will drive security decision-making, translate compliance requirements into vendor contracts, and maintain audit trails that demonstrate organizational accountability across the third-party landscape. The ideal candidate combines vendor risk expertise with proven independent ability and thrives information security best practices in a fast-paced, global, and high-growth environment. Key Areas of Expertise Third-Party Risk Assessment & Vendor Evaluation: Deep experience conducting security questionnaires, reviewing certifications (SOC2, ISO 27001, etc.), and scoring vendor risk profiles. Compliance & Contract Governance: Expertise in translating security and compliance requirements into vendor contracts, SLAs, and audit requirements. SaaS Security Posture & AI Risk Management: Understanding of cloud service security, SaaS-specific vulnerabilities, and emerging AI vendor risks. Working with TPRM software like Panorays, OneTrust etc. Providing security requirements for implementations of new systems. Responsibilities Vendor Risk Assessment & Intake: Design and manage vendor security assessment workflows. Integrate security questionnaires (Panorays, etc.) into standardized evaluation processes. Conduct deep-dive security reviews of third-party SaaS providers, cloud vendors, and AI services to determine risk profiles. Risk Scoring & Metrics: Develop and maintain vendor risk scoring models aligned with organizational risk appetite. Track key risk indicators (KRIs) for active vendors and escalate material changes in vendor security posture. Compliance Questionnaire Management: Own the questionnaire lifecycle—intake, response validation, remediation tracking, and integration into risk decision workflows. Ensure vendor responses are accurate and evidence-backed. Contract & SLA Negotiation: Partner with procurement and legal to embed security requirements in vendor contracts. Negotiate security clauses, data protection terms, audit rights, and incident notification obligations. Vendor Incident & Breach Management: Monitor and respond to third-party security incidents. Lead investigation into vendor breaches affecting organizational data. Coordinate remediation and assess impact on compliance posture. Continuous Vendor Monitoring: Establish ongoing monitoring of active vendors through automated tools, re-assessments, and public breach intelligence. Maintain audit trails for all vendor risk decisions and remediation activities. TPRM Policy & Governance: Author and maintain vendor risk management policies, vendor tiering frameworks, and assessment standards. Ensure alignment with regulatory requirements (SOC2, ISO 27001, GDPR, etc.). Cross-functional Collaboration: Partner with DevSecOps, procurement, legal, compliance, and business teams to translate vendor risk findings into business decisions. Drive adoption of vendor risk assessments across the organization. Vendor Risk Reporting & Insights: Produce executive reporting on vendor risk trends, concentration risk, and remediation progress. Identify patterns in vendor vulnerabilities to inform procurement strategy. Qualifications 5+ years of experience in Information Security, with at least 3 years focused on Third-Party Risk Management, vendor assessments, or supply chain security. Proven experience with security questionnaire frameworks (Panorays, OneTrust, Archer, etc.) and vendor risk scoring methodologies. Strong understanding of compliance frameworks (SOC2, ISO 27001, GDPR, HIPAA, etc.) and ability to translate requirements into vendor terms. Familiarity with vendor contracts, SLAs, data processing agreements, and security clauses. Comfortable negotiating with legal and procurement. Ability to assess complex vendor security postures, identify gaps, and recommend risk mitigation strategies. Working knowledge of cloud platforms (AWS, Azure, GCP), SaaS architecture, and common vendor security controls. Nice to haves Experience with high-tech or SaaS companies managing large vendor ecosystems. Experience with remote-first or distributed organizations. Experience working asynchronously across different time zones and cultures. Hands-on experience building or scaling vendor risk management processes from scratch. Background in procurement, contract management, or vendor management. Familiarity with TPRM tools or GRC platforms (OneTrust, Archer, Nessus, Qualys, etc.). Experience with Panorays as a TPRM tool. Total Rewards Our workforce deserves fair and competitive pay that meets them where they are. With scalable benefits, rewards, and perks, our total rewards programs reflect our commitment to inclusivity and access for all. Our salary range reflects gross base salary. For commercial roles with commission eligibility, this figure represents On-Target Earnings (OTE), inclusive of base salary and target commission. Salary ranges are quoted in USD as a consistent global reference. Your offer will be localized to your country's currency using a market-aligned conversion. Final pay is based on objective, job-related criteria including experience, skills, and location. We don't ask about salary history. Offers are based on the role and what you bring to it. Some things you'll enjoy Stock grant opportunities dependent on your role, employment status and location Additional perks and benefits based on your employment status and country Optional flexible working office membership, with IWG At Deel, we're an equal-opportunity employer that values diversity and positively encourage applications from suitably qualified and eligible candidates regardless of race, religion, sex, national origin, gender, sexual orientation, age, marital status, veteran status, disability status, pregnancy or maternity or other applicable legally protected characteristics. Unless otherwise agreed, we will communicate with job applicants using Deel-specific emails, which include @ deel.com and other acquired company emails like @ payspace.com and @ paygroup.com. You can view the most up-to-date job listings at Deel by visiting our careers page. Deel welcomes persons with disabilities to apply to any of our open roles. We will provide application and/or interview accommodations on request throughout the recruitment, selection and assessment process for applicants with disabilities or other needs. If you require application and/or interview accommodations, please inform our Talent Acquisition Team via email ( recruiting@deel.com ) and a team member will be in touch to ensure your equal participation. As part of our hiring process, we primarily rely on interviews and role-related assessments. In limited cases, we may also consider informal background information relevant to the role, in line with our privacy and fairness obligations. This application process may utilise Automated Employment Decision Tools (AEDT) and AI systems to assist in evaluating candidates based on experience level, technical skills and qualifications. This processing is conducted in compliance with applicable Data Protection, AI Governance and Labour Laws. We ensure human oversight is maintained in all final hiring decisions. Your personal data is not used to train AI models. For more information on how we process your personal data, please see our Recruitment Privacy Policy. For NYC Residents: In accordance with NYC Local Law 144, an independent bias audit has been conducted on AEDT