Third Party Security Analyst

Full Time
Bengaluru, Karnataka, India
2 months ago

At Deliveroo, it is our mission to build the definitive food company. In order to do that, we’re building a company that is secure and protects the data and money of our customers, employees and investors.   

We are looking for a pragmatic and outcome-driven Third Party Security Analyst to support the design and implementation of Deliveroo’s approach for managing the security risk of third parties. You will work directly with leaders across the business to assess the security risks of suppliers and help devise practical solutions or make informed decisions about the identified risks.

Reporting to the Senior Third Party Security Specialist, this role presents a fantastic opportunity to grow and have a direct impact on how Deliveroo works with hundreds of suppliers and manages its risks. By helping drive sound management of third party security risk across the company you will play a major part in our story.

 

What you’ll be doing. You will:

  • Lead and conduct cyber risk assessments of third-party suppliers 
  • Advise the business on appropriate controls to mitigate third party risks
  • Support the implementation of third party security risk management framework to ensure that third party suppliers comply with security policies and standards
  • Support in keeping the supplier inventory and the supplier security risk register updated
  • Help perform periodic assurance reviews of supplier controls
  • Report and track risks and remediation actions related to third party suppliers  
  • Support the security incident response team in the event of a supplier security incident
  • Contribute to management reporting of third party security risks to relevant committees and stakeholders

 

Requirements. You are or have:

  • Experience in third party security risk management or assurance in a fast paced business
  • Experience in assessing security posture of SaaS providers
  • Supported processes and procedures for managing third party security risk
  • Comfortable interacting with different stakeholders across the business in both technical and non-technical roles
  • Knowledge of security standards such as ISO27001, NIST, CIS and SOC 2

Preferred, but not required:

  • Relevant industry certifications such as CISM, CRISC, CISA, CISSP or ISO 27001/2
  • Working experience with commercial tools for managing supplier security risk

 

Why Deliveroo?

Our mission is to be the definitive food company. We are transforming the way the world eats by making food more convenient and accessible. We give people the opportunity to eat what they want, when and where they want it.

We are a technology-driven company at the forefront of the most rapidly expanding industry in the world. We are still a small team, making a very large impact, seeking to answer some of the most interesting questions out there. We move fast, value autonomy and ownership, and we are always looking for new ideas.

 

Workplace & Diversity

At Deliveroo we know that people are the heart of the business and we prioritise their welfare. We offer a wide range of competitive benefits in areas including health, family, finance, community, convenience, growth and relocation.

We believe a great workplace is one that represents the world we live in and how beautifully diverse it can be. That means we have no judgement when it comes to any one of the things that make you who you are - your gender, race, sexuality, religion or a secret aversion to coriander. All you need is a passion for (most) food and a desire to be part of one of the fastest growing startups in an incredibly exciting space.

Please click here to view our candidate privacy policy.