Staff Security Engineer (Vendor Security Assurance)
Core
Identify, assess, and manage security risks from external vendors, services, and solutions to protect company assets and customer trust.
Role type
Staff Security Engineer (Vendor Security Assurance)
Builds
Third-Party Security Risk Management systems and vendor security evaluation frameworks
Domain
E-commerce, Logistics, Information Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application authentication, authorization, logging, API integration, Information security, IT, infrastructure, network, Privacy & Compliance, Risk management, Governance
Preferred skills
SaaS security posture management (SSPM), Security architecture design, e-Commerce and logistics business knowledge, Regulatory compliance (Information and Communications Network Act, Electronic Financial Transactions Act, Personal Information Protection Act)
Technologies
SaaS, Generative AI, Outsourcing platforms, Privacy-preserving systems
Responsibilities
Evaluate security policies, procedures, and controls for SaaS, Generative AI, outsourcing, and data trustees; Manage security requirement implementation including authentication, authorization, configuration, and monitoring; Identify and mitigate vendor security risks across the lifecycle; Develop and improve methodologies for external vendor security assessments based on emerging threats and regulations
Seniority
Staff, hands-on IC with strategic oversight