Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Third Party Security Analyst image - Rise Careers
Job details

Third Party Security Analyst

At Deliveroo, it is our mission to build the definitive food company. In order to do that, we’re building a company that is secure and protects the data and money of our customers, employees and investors.   

We are looking for a pragmatic and outcome-driven Third Party Security Analyst to support the design and implementation of Deliveroo’s approach for managing the security risk of third parties. You will work directly with leaders across the business to assess the security risks of suppliers and help devise practical solutions or make informed decisions about the identified risks.

Reporting to the Senior Third Party Security Specialist, this role presents a fantastic opportunity to grow and have a direct impact on how Deliveroo works with hundreds of suppliers and manages its risks. By helping drive sound management of third party security risk across the company you will play a major part in our story.

 

What you’ll be doing. You will:

  • Lead and conduct cyber risk assessments of third-party suppliers 

  • Advise the business on appropriate controls to mitigate third party risks

  • Support the implementation of third party security risk management framework to ensure that third party suppliers comply with security policies and standards

  • Support in keeping the supplier inventory and the supplier security risk register updated

  • Help perform periodic assurance reviews of supplier controls

  • Report and track risks and remediation actions related to third party suppliers  

  • Support the security incident response team in the event of a supplier security incident

  • Contribute to management reporting of third party security risks to relevant committees and stakeholders

 

Requirements. You are or have:

  • Experience in third party security risk management or assurance in a fast paced business

  • Experience in assessing security posture of SaaS providers

  • Supported processes and procedures for managing third party security risk

  • Comfortable interacting with different stakeholders across the business in both technical and non-technical roles

  • Knowledge of security standards such as ISO27001, NIST, CIS and SOC 2

Preferred, but not required:

  • Relevant industry certifications such as CISM, CRISC, CISA, CISSP or ISO 27001/2

  • Working experience with commercial tools for managing supplier security risk

 

Why Deliveroo?

Our mission is to be the definitive food company. We are transforming the way the world eats by making food more convenient and accessible. We give people the opportunity to eat what they want, when and where they want it.

We are a technology-driven company at the forefront of the most rapidly expanding industry in the world. We are still a small team, making a very large impact, seeking to answer some of the most interesting questions out there. We move fast, value autonomy and ownership, and we are always looking for new ideas.

 

Workplace & Diversity

At Deliveroo we know that people are the heart of the business and we prioritise their welfare. We offer a wide range of competitive benefits in areas including health, family, finance, community, convenience, growth and relocation.

We believe a great workplace is one that represents the world we live in and how beautifully diverse it can be. That means we have no judgement when it comes to any one of the things that make you who you are - your gender, race, sexuality, religion or a secret aversion to coriander. All you need is a passion for (most) food and a desire to be part of one of the fastest growing startups in an incredibly exciting space.

Deliveroo Glassdoor Company Review
3.8 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Deliveroo DE&I Review
4.0 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
CEO of Deliveroo
Deliveroo CEO photo
Will Shu
Approve of CEO

Average salary estimate

$70000 / YEARLY (est.)
min
max
$60000K
$80000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Third Party Security Analyst, Deliveroo

At Deliveroo, we’re on a mission to revolutionize the food industry, and we know that achieving this requires not just delicious meals but a secure, trustworthy foundation. That's why we are seeking a skilled Third Party Security Analyst to join our team. In this role, you will play a vital part in shaping Deliveroo’s strategy for managing security risks associated with our key suppliers. You’ll work closely with various leaders within the organization to assess the security postures of third-party vendors and develop pragmatic solutions to any risks identified. It’s an exciting opportunity to make a tangible difference, supporting the implementation of our third-party security risk management framework and ensuring our suppliers adhere to stringent security policies. Your responsibilities will include leading cyber risk assessments, advising on appropriate risk mitigation controls, and maintaining our supplier security inventory. You will also assist during security incidents involving suppliers and contribute to vital management reports on third-party security risks. If you have a passion for security and a knack for connecting with diverse stakeholders, this role at Deliveroo could be your chance to have a significant impact as we strive to build the definitive food company that prioritizes the security of our customers and business alike.

Frequently Asked Questions (FAQs) for Third Party Security Analyst Role at Deliveroo
What are the responsibilities of a Third Party Security Analyst at Deliveroo?

As a Third Party Security Analyst at Deliveroo, your main responsibilities will include leading cyber risk assessments, advising the business on risk mitigation controls, and helping implement a third-party security risk management framework. You'll also maintain an updated supplier inventory and risk register, support assurance reviews of supplier controls, and contribute to management reporting on security risks.

Join Rise to see the full answer
What qualifications do I need to be a Third Party Security Analyst at Deliveroo?

To be a successful Third Party Security Analyst at Deliveroo, you should have experience in third-party security risk management or assurance, particularly in fast-paced environments. Familiarity with security standards like ISO27001, NIST, and SOC 2 is essential. Industry certifications such as CISM, CRISC, or CISSP are preferred but not required.

Join Rise to see the full answer
How does Deliveroo's Third Party Security Analyst role support business goals?

The Third Party Security Analyst at Deliveroo directly supports our business goals by ensuring that we effectively manage the security risks associated with our suppliers. By performing risk assessments and advising on security controls, you will help mitigate risks that could affect our operations and consumer trust, ultimately contributing to Deliveroo’s mission of being the definitive food company.

Join Rise to see the full answer
What skills are vital for a Third Party Security Analyst at Deliveroo?

Key skills required for a Third Party Security Analyst at Deliveroo include strong analytical abilities to conduct risk assessments, excellent communication skills to interact with diverse stakeholders, and in-depth knowledge of security best practices. Additionally, being proactive and comfortable navigating both technical and non-technical discussions is important.

Join Rise to see the full answer
How does Deliveroo value diversity in its Third Party Security Analyst team?

At Deliveroo, we prioritize creating a diverse and inclusive workplace, particularly in our Third Party Security Analyst team. We believe that a diverse workforce brings varied perspectives that enhance our problem-solving capabilities and innovation. We welcome candidates from all backgrounds and encourage applications from individuals who share our commitment to building a secure and representative company.

Join Rise to see the full answer
Common Interview Questions for Third Party Security Analyst
Can you describe your experience with third-party security risk management?

When answering this question, provide specific examples from your past roles where you managed third-party security risks. Highlight your methodologies for conducting assessments, identifying risks, and implementing mitigation strategies.

Join Rise to see the full answer
How familiar are you with security standards such as ISO27001 and NIST?

Discuss your familiarity with these standards and share experiences where you applied them in your previous roles. Emphasize your understanding of their importance in managing third-party security risks.

Join Rise to see the full answer
What processes do you recommend for assessing suppliers' security postures?

In your response, outline a systematic approach you would take, such as conducting regular risk assessments, employing checklists based on security frameworks, and engaging with suppliers to evaluate their controls and practices.

Join Rise to see the full answer
How would you communicate security risks to non-technical stakeholders?

Approach this question by illustrating how you would simplify technical jargon into business-friendly language. Highlight your interpersonal skills and give examples of past experiences explaining complex security concepts to non-technical teams.

Join Rise to see the full answer
What steps would you take if a third-party supplier experiences a security incident?

Detail a clear plan of action that includes immediate notification procedures, risk assessment protocols, and steps to work with the supplier for remediation. Discuss the importance of communication and collaboration during the incident response.

Join Rise to see the full answer
How do you prioritize third-party risks when assessing multiple suppliers?

Share your criteria for prioritization, such as the suppliers' access to sensitive data, historical performance, and their compliance with established security standards. Discuss how you would categorize risks based on their potential impact.

Join Rise to see the full answer
Can you provide an example of a successful risk mitigation strategy you implemented?

Answering this question with a specific example will illustrate your capabilities. Provide context, explain the strategy you employed, and share the successful outcomes that resulted from your actions.

Join Rise to see the full answer
What tools or methodologies have you used for managing supplier security risk?

Discuss specific tools you have used, such as risk assessment software or project management tools, as well as any methodologies you are comfortable with, like Fair Market Value (FMV) assessments, that were effective in your previous roles.

Join Rise to see the full answer
How do you stay updated on the latest security threats related to third-party risks?

Explain your approach to staying informed, which may include following industry news, participating in webinars, and engaging with professional networks. Highlight your commitment to continuous learning in the field.

Join Rise to see the full answer
What do you see as the biggest challenges in third-party security risk management?

Provide a thoughtful perspective on the challenges you have faced, such as dealing with diverse supplier practices, compliance discrepancies, or evolving regulatory landscapes. Share how you have addressed or would approach these challenges.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Performance Bonus
Paid Holidays

Deliveroo seeks an experienced Account Manager to drive success for their strategic accounts and enhance profitability in a fast-paced environment.

Photo of the Rise User
Performance Bonus
Paid Holidays
Photo of the Rise User
Posted 7 days ago
Photo of the Rise User
HealthPartners Remote Bloomington, Minnesota, United States
Posted 8 days ago
Photo of the Rise User
LLNL Remote Livermore, CA, USA
Posted yesterday

We are looking for a skilled Gen AI Engineer to join Lawrence Livermore National Laboratory and help shape the future of AI technology.

CACI Hybrid US VT Williston
Posted 8 days ago
Photo of the Rise User
Posted 12 days ago

To create the best food delivery experience in the world.

190 jobs
MATCH
Calculating your matching score...
BENEFITS & PERKS
Performance Bonus
Paid Holidays
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
February 26, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!