Deel
Muscat, OmanPosted 1 weeks ago
Who We Are Is What We Do. Deel is the all-in-one payroll and HR platform for global teams. Our vision is to unlock global opportunity for every person, team, and business. Built for the way the world works today, Deel combines HRIS, payroll, compliance, benefits, performance, and equipment management into one seamless platform. With AI-powered tools and a fully owned payroll infrastructure, Deel supports every worker type in 150+ countries—helping businesses scale smarter, faster, and more compliantly. Among the largest globally distributed companies in the world, our team of 7,000 spans more than 100 countries, speaks 74 languages, and brings a connected and dynamic culture that drives continuous learning and innovation for our customers. Why should you be part of our success story? As the fastest-growing Software as a Service (SaaS) company in history, Deel is transforming how global talent connects with world-class companies – breaking down borders that have traditionally limited both hiring and career opportunities. We're not just building software; we're creating the infrastructure for the future of work, enabling a more diverse and inclusive global economy. In 2024 alone, we paid $11.2 billion to workers in nearly 100 currencies and provided healthcare and benefits to workers in 109 countries—ensuring people get paid and protected, no matter where they are. Our momentum is reflected in our achievements and customer satisfaction: CNBC Disruptor 50, Forbes Cloud 100, Deloitte Fast 500, and repeated recognition on Y Combinator's top companies list – all while maintaining a 4.83 average rating from 15,000 reviews across G2, Trustpilot, Captera, Apple and Google. Your experience at Deel will be a career accelerator. At the forefront of the global work revolution, you'll tackle complex challenges that impact millions of people's working lives. With our momentum—backed by a $17.3 billion valuation and $1 B in Annual Recurring Revenue (ARR) in just over five years—you'll drive meaningful impact while building expertise that makes you a sought-after leader in the transformation of global work. We are looking for an experienced Information Security Third Party Risk Management (TPRM) Specialist to improve and oversee our vendor risk management program. This role requires deep expertise in security assessments, vendor evaluation frameworks, compliance questionnaire management, and risk lifecycle governance. The ideal candidate will establish and improve current scalable processes to evaluate, monitor, and remediate third-party risks across our growing global ecosystem—including SaaS providers, cloud vendors, AI services, and critical infrastructure partners. You will drive security decision-making, translate compliance requirements into vendor contracts, and maintain audit trails that demonstrate organizational accountability across the third-party landscape. The ideal candidate combines vendor risk expertise with proven independent ability and thrives information security best practices in a fast-paced, global, and high-growth environment. Key Areas of Expertise • Third-Party Risk Assessment & Vendor Evaluation: Deep experience conducting security questionnaires, reviewing certifications (SOC2, ISO 27001, etc.), and scoring vendor risk profiles. • Hands on experience and AI automation: This role includes a responsibility of automation the processes that you are working on • Compliance & Contract Governance: Expertise in translating security and compliance requirements into vendor contracts, SLAs, and audit requirements. • SaaS Security Posture & AI Risk Management: Understanding of cloud service security, SaaS-specific vulnerabilities, and emerging AI vendor risks. • Working with TPRM software like Panorays, OneTrust etc. • Providing security requirements for implementations of new systems. Responsibilities • Vendor Risk Assessment & Intake: Design and manage vendor security assessment workflows. Integrate security questionnaires (Panorays, etc.) into standardized evaluation processes. Conduct deep-dive security reviews of third-party SaaS providers, cloud vendors, and AI services to determine risk profiles. • Risk Scoring & Metrics: Develop and maintain vendor risk scoring models aligned with organizational risk appetite. Track key risk indicators (KRIs) for active vendors and escalate material changes in vendor security posture. • Compliance Questionnaire Management: Own the questionnaire lifecycle—intake, response validation, remediation tracking, and integration into risk decision workflows. Ensure vendor responses are accurate and evidence-backed. • Contract & SLA Negotiation: Partner with procurement and legal to embed security requirements in vendor contracts. Negotiate security clauses, data protection terms, audit rights, and incident notification obligations. • Vendor Incident & Breach Management: Monitor and respond to third-party security incidents. Lead investigation into vendor breaches affecting organizational data. Coordinate remediation and assess impact on compliance posture. • Continuous Vendor Monitoring: Establish ongoing monitoring of active vendors through automated tools, re-assessments, and public breach intelligence. Maintain audit trails for all vendor risk decisions and remediation activities. • TPRM Policy & Governance: Author and maintain vendor risk management policies, vendor tiering frameworks, and assessment standards. Ensure alignment with regulatory requirements (SOC2, ISO 27001, GDPR, etc.). • Cross-functional Collaboration: Partner with DevSecOps, procurement, legal, compliance, and business teams to translate vendor risk findings into business decisions. Drive adoption of vendor risk assessments across the organization. • Vendor Risk Reporting & Insights: Produce executive reporting on vendor risk trends, concentration risk, and remediation progress. Identify patterns in vendor vulnerabilities to inform procurement strategy. Qualifications • 5+ years of experience in Information Security, with at least 3 years focused on Third-Party Risk Management, vendor assessments, or supply chain security. • Technical Literacy: Working knowledge of AI automation (Gemini & Claude) SaaS architecture, and common vendor security controls. • Assessment & Questionnaire Expertise: Proven experience with security questionnaire frameworks (Panorays, OneTrust, Archer, etc.) and vendor risk scoring methodologies. • Compliance Knowledge: Strong understanding of compliance frameworks (SOC2, ISO 27001, GDPR, HIPAA, etc.) and ability to translate requirements into vendor terms. • Contract & Legal Acumen: Familiarity with vendor contracts, SLAs, data processing agreements, and security clauses. Comfortable negotiating with legal and procurement. • Analytical Mindset: Ability to assess complex vendor security postures, identify gaps, and recommend risk mitigation strategies. Nice to Haves • Experience with high-tech or SaaS companies managing large vendor ecosystems. • Experience with remote-first or distributed organizations. • Experience working asynchronously across different time zones and cultures. • Hands-on experience building or scaling vendor risk management processes from scratch. • Background in procurement, contract management,
5+ years of experience in Information Security, with at least 3 years focused on Third-Party Risk Management, vendor assessments, or supply chain security. Technical Literacy: Working knowledge of AI automation (Gemini & Claude) SaaS architecture, and common vendor security controls. Assessment & Questionnaire Expertise: Proven experience with security questionnaire frameworks (Panorays, OneTrust, Archer, etc.) and vendor risk scoring methodologies. Compliance Knowledge: Strong understanding of compliance frameworks (SOC2, ISO 27001, GDPR, HIPAA, etc.) and ability to translate requirements into vendor terms. Contract & Legal Acumen: Familiarity with vendor contracts, SLAs, data processing agreements, and security clauses. Analytical Mindset: Ability to assess complex vendor security postures, identify gaps, and recommend risk mitigation strategies.
Vendor Risk Assessment & Intake: Design and manage vendor security assessment workflows. Integrate security questionnaires (Panorays, etc.) into standardized evaluation processes. Conduct deep-dive security reviews of third-party SaaS providers, cloud vendors, and AI services to determine risk profiles. Risk Scoring & Metrics: Develop and maintain vendor risk scoring models aligned with organizational risk appetite. Track key risk indicators (KRIs) for active vendors and escalate material changes in vendor security posture. Compliance Questionnaire Management: Own the questionnaire lifecycle—intake, response validation, remediation tracking, and integration into risk decision workflows. Ensure vendor responses are accurate and evidence-backed. Contract & SLA Negotiation: Partner with procurement and legal to embed security requirements in vendor contracts. Negotiate security clauses, data protection terms, audit rights, and incident notification obligations. Vendor Incident & Breach Management: Monitor and respond to third-party security incidents. Lead investigation into vendor breaches affecting organizational data. Coordinate remediation and assess impact on compliance posture. Continuous Vendor Monitoring: Establish ongoing monitoring of active vendors through automated tools, re-assessments, and public breach intelligence. Maintain audit trails for all vendor risk decisions and remediation activities. TPRM Policy & Governance: Author and maintain vendor risk management policies, vendor tiering frameworks, and assessment standards. Ensure alignment with regulatory requirements (SOC2, ISO 27001, GDPR, etc.). Cross-functional Collaboration: Partner with DevSecOps, procurement, legal, compliance, and business teams to translate vendor risk findings into business decisions. Drive adoption of vendor risk assessments across the organization. Vendor Risk Reporting & Insights: Produce executive reporting on vendor risk trends, concentration risk, and remediation progress. Identify patterns in vendor vulnerabilities to inform procurement strategy.
Not sure you fit this role?
Upload your CV and see how you score against Deel and every other live job. It's free.
Get my free matchesAED 17k–40k a month· est.