
Vendor Security Program Manager
OpenAI
full-time
Posted on:
Location Type: Hybrid
Location: San Francisco • California • District of Columbia • United States
Visit company websiteExplore more
Salary
💰 $207,000 - $355,000 per year
Tech Stack
About the role
- Be the interface for Security to the rest of the organization for vendors.
- Own vendor security risk decisions and escalation paths, including clearly documenting risk acceptance, mitigation plans, and executive-level trade-offs when security requirements cannot be fully met.
- Conduct deep, evidence-based security assessments of third parties, including review of architectures, configurations, controls, logs, and operational practices - moving beyond questionnaires and attestations to validate real-world security posture of vendors.
- Assess and manage security risk across a diverse vendor landscape, including SaaS providers, cloud and infrastructure partners, hardware manufacturers, chip suppliers, and other strategic or high-impact suppliers.
- Develop, build, and continuously improve the vendor security program and security supply chain risk management function at OpenAI.
- Develop, propose, and implement effective controls to mitigate identified vendor risks.
- Build and maintain collaborative partnerships with key internal stakeholders including Infrastructure Security, Product, Engineering, Legal, Procurement, and Threat Intelligence to ensure comprehensive security coverage of the vendor and third-party supply chain.
- Streamline and automate vendor and supply chain security processes to increase efficiency and reduce manual overhead.
Requirements
- Proven experience conducting third-party or supply chain security assessments, including building and scaling a vendor management security program.
- An in-depth understanding of information security principles and controls, including data protection, access management, proactive and reactive security measures, and application security.
- Comfort operating in ambiguity, with the ability to form defensible security opinions even when information is incomplete, timelines are compressed, or business pressure is high.
- Strong technical and analytical skills, with a demonstrated ability to identify and assess risks from external incidents and industry breaches.
- Familiarity with workflow optimization tools such as Zip and OneTrust.
- A passion for integrating new AI technologies into your solutions.
- Exceptional verbal and written communication skills with the capability to clearly articulate complex security concepts to diverse audiences.
- A proactive mindset and desire to own and drive security initiatives within a fast-paced environment.
- Knowledge of key security frameworks and standards such as ISO-27001, NIST 800-53, SOC 2, and understanding of key regulatory requirements such as the Trade Agreement Act (TAA).
Benefits
- 📊 Check your resume score for this job Improve your chances of getting an interview by checking your resume score before you apply. Check Resume Score
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
vendor security risk managementthird-party security assessmentsinformation security principlesdata protectionaccess managementapplication securityrisk assessmentsecurity controlsworkflow optimizationsecurity frameworks
Soft Skills
analytical skillscommunication skillsproactive mindsetability to operate in ambiguitycollaborative partnershipsproblem-solvinginitiativeadaptabilityattention to detailstakeholder engagement
Certifications
ISO-27001NIST 800-53SOC 2