Supply Chain Manager helping scale a world-class Security Vendor Risk Management program at Webflow. Transforming third-party risk management into a proactive, data-informed capability.
Responsibilities
Own and lead the end-to-end Security Supply Chain Risk Management program, including strategy, governance, tooling, and continuous improvement across third-party, software, and vendor ecosystems.
Perform detailed third-party security risk assessments aligned with industry frameworks (e.g. SOC, ISO 27001, NIST), evaluating control effectiveness, data handling practices, and supply chain security risks.
Drive cross-functional alignment across Security, IT, Legal, and Procurement serving as the subject matter expert on external supply chain risk and ensuring comprehensive risk visibility and coverage.
Train and educate employees on supply chain security best practices and ensure awareness throughout the organization
Establish automation, metrics, and threat monitoring capabilities to proactively identify emerging supply chain risks, quantify exposure, and continuously strengthen the organization’s third-party and software security posture.
Contribute to the development and maintenance of security vendor risk management policies and procedures
Requirements
BA/BS degree or equivalent experience
7+ experience in Security Supply Chain, Vendor Risk Manager, Vendor Due Diligence or relevant work experience.
Knowledgeable in security supply chain fundamentals, including common frameworks & privacy regulations
Benefits
Ownership in what you help build. Every permanent Webflower receives equity (RSUs) in our growing, privately held company.
Health coverage that actually covers you. Comprehensive medical, dental, and vision plans for full-time employees and their dependents, with Webflow covering most premiums.
Support for every stage of family life. 12 weeks of paid parental leave for all parents and 6+ weeks of additional paid leave for birthing parents. Plus inclusive care for family planning, menopause, and midlife transitions.
Time off that’s actually off. Flexible vacation, paid holidays, and a sabbatical program to help you recharge and come back inspired.
Wellness for the whole you. Access to mental health resources, therapy and coaching.
Invest in your future. A 401(k) with 100% employer match (up to $6,000/year) in the U.S., and support for retirement savings globally.
Monthly stipends that flex with your life. Localized support for work and wellness expenses — from Wi-Fi to workouts.
Bonus for building together. All full-time, permanent, non-commission employees are eligible for our annual WIN bonus program.
Bilingual Security Agent ensuring the safety of people and property for OPENLANE. Responsibilities include surveillance, access control, and customer service at the facility.
Staff Product Security Engineer ensuring security throughout the product development lifecycle at Affirm. Collaborating closely with product and engineering teams to improve security in financial products.
Agent de projets de sécurité pour l'Administration de la Chambre des communes. Mener des évaluations de sécurité et gérer plusieurs projets partout au Canada.
Information Security Advisor ensuring risk assessment and compliance for Sun Life business groups. Conducting risk assessments and advising on information security best practices.
Senior Hardware Security Engineer at Lime focusing on hardware security architecture and assessments. Collaborate with teams on product security across embedded systems and firmware.
Compliance Manager overseeing compliance processes and frameworks for Data Security Services at Entrust. Ensuring DSS products meet or exceed industry standards and mitigate compliance risks.
Product Security Engineer improving security of Lattice’s applications and services through engineering partnerships and security operations. Contributing to secure coding practices and AI/LLM security assessments.
Presales Security Expert at Fortinet developing secure platform solutions for Major Accounts. Seeking to safeguard people, devices, and data through innovative cybersecurity solutions
IT Security Specialist responsible for day - to - day support of Hudbay’s IT security program and monitoring security risks. Collaborating on various projects to ensure security best practices are followed across the organization.