Vendor Security Technical Program Manager
OpenAI · US - Remote
About this role
**Vendor Security Technical Program Manager** **About the Team** OpenAI's Vendor Security team helps internal teams work securely with external products, services, and partners. We build programs and products that help teams understand vendor risk and implement effective safeguards. **About the Role** We're seeking a Vendor Security Technical Program Manager to lead vendor-security engagements independently—from understanding business needs through assessment, decision-making, and verification of safeguards. **Key Responsibilities** • Own vendor security engagements end-to-end: scoping, assessment, decision, treatment, and reassessment • Understand vendor use cases, data flows, identities, access, and supply-chain dependencies • Assess architectures, configurations, controls, and operational practices • Develop practical treatments and drive implementation with responsible owners • Build reusable security patterns with clear applicability and evidence requirements • Collaborate with Legal, Procurement, and vendors on security terms • Define requirements, roadmaps, and success measures for bounded programs • Use AI-assisted tools to improve scoping, evidence checks, and decision tracking • Lead cross-functional delivery and translate goals into technical requirements **You Might Thrive If You** • Have independently assessed third-party or supply-chain security risks • Understand security principles: data protection, access management, application security, detection, and response • Know ISO 27001, NIST 800-53, SOC 2, and can apply them to real engagements • Have translated security findings into practical contractual positions • Have delivered products or workflow improvements and owned performance post-launch • Can use AI-assisted development tools to build and test solutions • Have delivered cross-functional programs and adapted priorities for measurable outcomes • Build constructive relationships across Security, Engineering, Product, Legal, and business teams • Communicate complex security issues clearly with supporting evidence and tradeoffs • Question assumptions and revise judgment when new evidence emerges
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.