Skip to content
All jobs

This job comes from OpenAI careers page, not from an Interstack member. You apply on their site, so Interstack can't track your application or tell you when it has been seen.

O

Vendor Security Technical Program Manager

OpenAI · US - Remote

Full time Remote $231.3K – $256.5K • Offers Equity Security Posted 1 week ago

Skills this job asks for

Procurement

About the role

About the Team OpenAI's Vendor Security team helps internal teams work securely with external products, services, and partners. Our work spans software, infrastructure, hardware, professional and managed services, vendor-provided workforces, data, and research. We build the programs and products that help teams understand vendor risk and put effective safeguards in place, protecting our customers, employees, and the company. About the Role We are looking for a Vendor Security Technical Program Manager who can make sound security decisions and turn recurring vendor-security problems into tools and practices that work. You will independently lead vendor-security engagements: understand the business need, investigate the actual data and access, recommend a practical path, and work with the responsible owners until the safeguards are verified. You will also use what you learn to build and improve bounded tools and workflows, with priorities agreed with the Vendor Security lead. This is an individual-contributor role for someone who combines technical judgment with useful delivery. You should be comfortable taking a position, explaining the tradeoff, and changing your mind when the evidence changes. Success means internal teams can use vendors securely, reuse work that still applies, and understand what needs to happen next. In this role, you will: - Own vendor security engagements from understanding the business need through scoping, assessment, decision, treatment, and reassessment when material facts change. Make assessment decisions independently and use judgment about when to involve peers, specialists, or leadership. Route formal exceptions and risk acceptance to the appropriate decision owners. - Understand vendor use cases, workflows, user journeys, data flows, identities, access, integrations, and supply-chain dependencies. Identify plausible attack paths and their consequences for OpenAI. - Assess relevant architectures, configurations, controls, logs, and operational practices. Test whether the evidence supports the security claims that matter to the engagement, and make gaps and uncertainty clear. - Develop practical treatments, including changes to the operating model, data exposure, access, architecture, vendor choice, controls, or containment. Drive implementation with the responsible owners and verify that the treatment works. - Build reusable security patterns with clear applicability, safeguards, evidence requirements, exceptions, and review triggers. - Work with Legal, Procurement, and vendors on security addenda. Evaluate proposed terms and deviations against the engagement, explain their security implications, and develop workable positions with the appropriate decision owners. Legal leads wording and negotiation. - Learn from internal customers, agree priorities with the Vendor Security lead, and define the requirements, roadmap, and success measures for the bounded programs, products, and services you own. - Use Codex or compara...

A summary from the original listing. Read the full details on their site.

Apply on OpenAI's site

Opens in a new tab.

Similar jobs