Vendor Security Program Manager

OpenAIWashington, DC
2dHybrid

About The Position

As a Program Manager within the Vendor Security team, you will play a crucial role in protecting our organization against external risks posed by suppliers, vendors, partners, and hardware manufacturers. Your responsibilities will include conducting comprehensive security assessments, building a program to manage global supply chain and vendor risks, and driving security initiatives across all of our third-party relationships. You will be analytical, detail-oriented, and proactive, capable of translating complex security evaluations into clear, actionable strategies. The role is expected to operate with a strong point of view on risk. You will be responsible not only for identifying and documenting vendor and supply-chain risk, but for helping the company make informed trade-offs between speed, scale, and security. This role requires exceptional organizational skills, the ability to effectively communicate across different business functions, and a strong commitment to operational excellence in a dynamic environment. This role may be based out of one of our US offices (San Francisco, Seattle, NYC or DC.) We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees.

Requirements

  • Proven experience conducting third-party or supply chain security assessments, including building and scaling a vendor management security program.
  • An in-depth understanding of information security principles and controls, including data protection, access management, proactive and reactive security measures, and application security.
  • Comfort operating in ambiguity, with the ability to form defensible security opinions even when information is incomplete, timelines are compressed, or business pressure is high.
  • Strong technical and analytical skills, with a demonstrated ability to identify and assess risks from external incidents and industry breaches.
  • Exceptional verbal and written communication skills with the capability to clearly articulate complex security concepts to diverse audiences.
  • A proactive mindset and desire to own and drive security initiatives within a fast-paced environment.
  • Knowledge of key security frameworks and standards such as ISO-27001, NIST 800-53, SOC 2, and understanding of key regulatory requirements such as the Trade Agreement Act (TAA).

Nice To Haves

  • Familiarity with workflow optimization tools such as Zip and OneTrust.
  • A passion for integrating new AI technologies into your solutions.

Responsibilities

  • Be the interface for Security to the rest of the organization for vendors.
  • Own vendor security risk decisions and escalation paths, including clearly documenting risk acceptance, mitigation plans, and executive-level trade-offs when security requirements cannot be fully met.
  • Conduct deep, evidence-based security assessments of third parties, including review of architectures, configurations, controls, logs, and operational practices - moving beyond questionnaires and attestations to validate real-world security posture of vendors.
  • Assess and manage security risk across a diverse vendor landscape, including SaaS providers, cloud and infrastructure partners, hardware manufacturers, chip suppliers, and other strategic or high-impact suppliers.
  • Develop, build, and continuously improve the vendor security program and security supply chain risk management function at OpenAI.
  • Develop, propose, and implement effective controls to mitigate identified vendor risks.
  • Build and maintain collaborative partnerships with key internal stakeholders including Infrastructure Security, Product, Engineering, Legal, Procurement, and Threat Intelligence to ensure comprehensive security coverage of the vendor and third-party supply chain.
  • Streamline and automate vendor and supply chain security processes to increase efficiency and reduce manual overhead.

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Manager

Education Level

No Education Listed

Number of Employees

1,001-5,000 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service