Security Assurance Analyst

Cloudflare
Hybrid; In-OfficePosted 24 February 2026

Job Description

<div class="content-intro"><div><strong>About Us</strong></div> <div> <p>At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company. </p> <p><span style="font-weight: 400;">We realize people do not fit into neat boxes. We are looking for curious and empathetic individuals who are committed to developing themselves and learning new skills, and we are ready to help you do that. We cannot complete our mission without building a diverse and inclusive team. We hire the best people based on an evaluation of their potential and support them throughout their time at Cloudflare. Come join us! </span></p> </div></div><p><strong>Location(s) Available:</strong> Bangalore, India<br><br><strong>About The Team</strong><br><br>Join Cloudflare’s Security Architecture Team with the following with the foll focus areas : </p> <ul> <li>Strategic Alignment: Translates the Organisations Cyber risk tolerance into specific technical blueprints and implements controls/prescriptive policies in mitigation/managing or remediating these risks</li> <li>Preventative Focus: Focuses on "shifting left" to fix architectural flaws before they become bigger risks or costs </li> <li>Technical Consulting: Acts as internal subject matter experts for Procurement (TPRM) and Engineering teams.</li> </ul> <p><strong>About the role/</strong><strong>What You’ll Do</strong></p> <ul> <li>Provide input on technical security requirements for new infrastructure and engineering initiatives.</li> <li>Assist with documentation and maintenance of the corporate security architecture blueprints.</li> <li>You will be on the Third-Party Risk Management (TPRM) program, assessing the security posture of vendors, suppliers, and external partners. This involves performing complex security due diligence, managing risk remediation plans, and ensuring contractual security clauses are enforced throughout the vendor lifecycle.</li> <li>Conduct in-depth technical security assessments of new software, hardware, and services by evaluating system architecture, data flows, and infrastructure controls.</li> <li>Review external vulnerability scans and security configuration evidence provided by vendors to identify potential exposure points prior to procurement.</li> <li>Audit SaaS-to-SaaS and API-based integrations to ensure they follow the principle of least privilege and do not utilize over-privileged scopes or insecure authentication methods.</li> <li>Advanced knowledge with hands-on in Cloud Architecture, Data Encryption,Application Security and IAM Architecture</li> <li>Establish and enforce baseline security requirements for new software installations, covering encryption standards, multi-factor authentication (MFA), automated user provisioning/deprovisioning (SCIM), and SSO integration.</li> <li>Perform periodic reviews of existing implementations to detect and remediate "configuration drift," such as unauthorized public data shares or legacy administrative accounts.</li> <li>Utilize automated discovery tools to identify unmanaged SaaS applications (Shadow IT) and evaluate their security posture against corporate standards.</li> <li>Partner with internal business owners and vendors to track identified security gaps and ensure technical remediation occurs wit ... (truncated, view full listing at source)