Vendor security at production scale.
- Role
- UX Design Lead
- Client
- Netflix InfoSec
- Platform
- Web, Hawkins design system
- Year
- 2020 to 2021
Context
Every Netflix production involves dozens of outside vendors: casting agencies, post houses, camera crews. Every vendor is a potential leak vector for unreleased titles, talent contracts, and release dates. InfoSec was managing all of it in spreadsheets and email threads.
The problem
Build the system of record for vendor risk. Two audiences with opposite needs: InfoSec admins who live in the tool, and employees who drop in once to check whether they can send a vendor a script.
What I did
Two views, one product. The vendor profile reads differently depending on who opens it. Admins see edit affordances and the full evaluation history. Employees see a single risk picture, a feedback channel to InfoSec, and nothing else.
The risk picture. The hardest call was reducing a multi-dimensional evaluation into one summary an employee can act on in five seconds. As much an editorial judgment as a visualization problem.
Search and top concerns. Multi-tag filtering on top of Hawkins so admins could pivot from all unevaluated post-production vendors in EMEA to vendors blocked in the last 30 days without leaving the page.
Evaluations. InfoSec can build a security survey from scratch or a template, send it to a vendor, score the answers, and have the result archived to the vendor profile automatically. The spreadsheet-and-email loop became a workflow.

Outcome
Shipped as Netflix's centralized vendor security platform, replacing the spreadsheet-and-email workflow InfoSec had run for years. Saved 100+ hours per quarter on vendor vetting.
Built on React and Next.js with GraphQL and PostgreSQL, wired into Netflix services over gRPC and REST, with Netflix OAuth deciding who sees the admin view.
Next
Facebook →