This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We’re looking for a curious and detail-oriented individual to join Shopify’s Third Party Security team as a Technical Security Analyst. As a Technical Security Analyst, you’ll leverage your technical skills and security fundamentals—along with your growing knowledge of Shopify’s products, applications, and infrastructure—to help understand, assess, and manage third-party vendor risk. You’ll support and operate technical controls, follow and improve team playbooks, and work cross-functionally to help Shopifolk get shit done while keeping security top of mind.
Job Responsibility:
Support third-party/vendor security reviews by collecting evidence, validating responses, and recording outcomes
Use established frameworks and playbooks to identify control gaps and flag risks for review/escalation
Support implementation and day-to-day operation of technical controls that reduce third-party security risk
Use automation and available tools to reduce toil and improve consistency in repeatable workflows
Partner with internal teams to understand intended vendor/tool usage and gather required security context
Maintain clear systems-of-record documentation (artifacts, notes, decisions, and rationale) with strong attention to detail
Track recurring risk themes and basic metrics (cycle time, common findings, exceptions) to help improve how the team works
Contribute to team knowledge by updating playbooks/runbooks and sharing learnings from completed reviews
Requirements:
Clear, friendly written communication skills and comfort explaining technical details to non-technical partners
Working knowledge of security fundamentals (risk concepts, controls, privacy/compliance basics)
Strong attention to detail and proven ability to produce accurate, audit-friendly documentation
Ability to solve problems quickly, follow through, and escalate appropriately when something is unclear or high risk
Experience following structured processes/playbooks and suggesting improvements when friction or gaps are found
Comfort working across multiple tools/systems (tickets, docs, spreadsheets) to manage work end-to-end
Familiarity with automation or scripting/workflow tools (or strong interest in learning and applying them)