Lead third-party risk assessments and due-diligence activities across operational, financial, trade, supply-chain, legal, and other risk domains.
Own end-to-end vendor lifecycle workflows—onboarding, monitoring, incident response, and off-boarding.
Coordinate investigations of third-party incidents to ensure timely resolution.
Build dashboards, scorecards, and reporting to give leadership real-time visibility into vendor risk posture.
Partner with the Head of TPRM to refine frameworks, policies, and methodologies that scale with OpenAI’s rapid growth.
Lead implementation of the operating model, cross-functional expansion, and automation initiatives.Identify gaps and propose enhancements to processes, tooling, and reporting.
Drive adoption of risk accountability across Security, Legal, Compliance, Finance, and Procurement.
Monitor industry developments and regulatory changes to keep OpenAI ahead of external expectations.
Act as delegate for the Head of TPRM in cross-functional discussions, risk reviews, and senior-level briefings.
Deliver training and awareness programs to promote risk ownership across the business.
Communicate risk insights clearly to audiences ranging from technical teams to executive leadership.
Requirements
7+ years in third-party risk management, vendor risk, or a related field (high-growth tech preferred). Hands-on assessment and workflow execution required; leadership of projects or initiatives strongly desired.
A strong grasp of privacy, cyber risk, data security, operational resilience, and financial/vendor risk principles.
The proven ability to manage complex processes and deliver results in a fast-paced environment.
Exceptional communication and can influence, educate, and collaborate across functions.
Analyzed risk data, identified trends, and produced actionable reporting.
A CISA, CTPRP, CRISC, or similar credentials preferred.
Ability to work from our San Francisco office three days per week.