OpenAI

Vendor Security Program Manager

OpenAI

full-time

Posted on:

Location Type: Hybrid

Location: San FranciscoCaliforniaDistrict of ColumbiaUnited States

Visit company website

Explore more

AI Apply
Apply

Salary

💰 $207,000 - $355,000 per year

Tech Stack

About the role

  • Be the interface for Security to the rest of the organization for vendors.
  • Own vendor security risk decisions and escalation paths, including clearly documenting risk acceptance, mitigation plans, and executive-level trade-offs when security requirements cannot be fully met.
  • Conduct deep, evidence-based security assessments of third parties, including review of architectures, configurations, controls, logs, and operational practices - moving beyond questionnaires and attestations to validate real-world security posture of vendors.
  • Assess and manage security risk across a diverse vendor landscape, including SaaS providers, cloud and infrastructure partners, hardware manufacturers, chip suppliers, and other strategic or high-impact suppliers.
  • Develop, build, and continuously improve the vendor security program and security supply chain risk management function at OpenAI.
  • Develop, propose, and implement effective controls to mitigate identified vendor risks.
  • Build and maintain collaborative partnerships with key internal stakeholders including Infrastructure Security, Product, Engineering, Legal, Procurement, and Threat Intelligence to ensure comprehensive security coverage of the vendor and third-party supply chain.
  • Streamline and automate vendor and supply chain security processes to increase efficiency and reduce manual overhead.

Requirements

  • Proven experience conducting third-party or supply chain security assessments, including building and scaling a vendor management security program.
  • An in-depth understanding of information security principles and controls, including data protection, access management, proactive and reactive security measures, and application security.
  • Comfort operating in ambiguity, with the ability to form defensible security opinions even when information is incomplete, timelines are compressed, or business pressure is high.
  • Strong technical and analytical skills, with a demonstrated ability to identify and assess risks from external incidents and industry breaches.
  • Familiarity with workflow optimization tools such as Zip and OneTrust.
  • A passion for integrating new AI technologies into your solutions.
  • Exceptional verbal and written communication skills with the capability to clearly articulate complex security concepts to diverse audiences.
  • A proactive mindset and desire to own and drive security initiatives within a fast-paced environment.
  • Knowledge of key security frameworks and standards such as ISO-27001, NIST 800-53, SOC 2, and understanding of key regulatory requirements such as the Trade Agreement Act (TAA).
Benefits
  • 📊 Check your resume score for this job Improve your chances of getting an interview by checking your resume score before you apply. Check Resume Score
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills & Tools
vendor security risk managementthird-party security assessmentsinformation security principlesdata protectionaccess managementapplication securityrisk assessmentsecurity controlsworkflow optimizationsecurity frameworks
Soft Skills
analytical skillscommunication skillsproactive mindsetability to operate in ambiguitycollaborative partnershipsproblem-solvinginitiativeadaptabilityattention to detailstakeholder engagement
Certifications
ISO-27001NIST 800-53SOC 2