Vendor Security Technical Program Manager
United States · Remote · Full-time
- Posted 1w ago
- From OpenAI’s careers page
- Location
- United States
- Work mode
- Remote
- Type
- Full-time
- Department
- Other
Opens the listing on jobs.ashbyhq.com
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
About the Team
OpenAI's Vendor Security team helps internal teams work securely with external products, services, and partners. Our work spans software, infrastructure, hardware, professional and managed services, vendor-provided workforces, data, and research. We build the programs and products that help teams understand vendor risk and put effective safeguards in place, protecting our customers, employees, and the company.
About the Role
We are looking for a Vendor Security Technical Program Manager who can make sound security decisions and turn recurring vendor-security problems into tools and practices that work.
In this role, you will:
-
Own vendor security engagements from understanding the business need through scoping, assessment, decision, treatment, and reassessment when material facts change. Make assessment decisions independently and use judgment about when to involve peers, specialists, or leadership. Route formal exceptions and risk acceptance to the appropriate decision owners.
-
Understand vendor use cases, workflows, user journeys, data flows, identities, access, integrations, and supply-chain dependencies. Identify plausible attack paths and their consequences for OpenAI.
-
Assess relevant architectures, configurations, controls, logs, and operational practices. Test whether the evidence supports the security claims that matter to the engagement, and make gaps and uncertainty clear.
-
Develop practical treatments, including changes to the operating model, data exposure, access, architecture, vendor choice, controls, or containment. Drive implementation with the responsible owners and verify that the treatment works.
-
Build reusable security patterns with clear applicability, safeguards, evidence requirements, exceptions, and review triggers.
-
Work with Legal, Procurement, and vendors on security addenda. Evaluate proposed terms and deviations against the engagement, explain their security implications, and develop workable positions with the appropriate decision owners. Legal leads wording and negotiation.
-
Learn from internal customers, agree priorities with the Vendor Security lead, and define the requirements, roadmap, and success measures for the bounded programs, products, and services you own.
-
Use Codex or comparable AI-assisted tools to build, inspect, test, and maintain practical improvements to scoping, evidence checks, routing, decision reuse, or treatment tracking. Investigate failures and own the result through adoption, continued operation, and explicit handoff or retirement.
-
Lead delivery across Security and partner teams. Translate goals into technical requirements, milestones, and delivery plans; influence implementation choices; identify systemic risks; resolve dependencies and disagreements; and carry commitments through completion.
-
Use casework, incidents, threat information, and customer feedback to improve decisions and the program. As priorities change, recommend what to do next and explain the tradeoffs and effects on existing commitments.
You might thrive in this role if you:
-
Have independently assessed consequential third-party, supply-chain, or comparable security risks, and can apply that judgment to unfamiliar vendor technologies and operating models.
-
Understand security principles and controls, including data protection, access management, application security, prevention, detection, and response. Can reason about architecture, identity, APIs, data flows, logging, integrations, and whether controls work.
-
Know relevant frameworks and standards, including ISO 27001, NIST 800-53, and SOC 2, and can use them to inform an assessment of the actual engagement.
-
Have translated security findings and requirements into practical contractual positions with Legal, Procurement, and vendor representatives.
-
Have delivered useful products or workflow improvements, tested expected behavior and failure cases, learned from users, and owned performance after launch.
-
Can use Codex or comparable AI-assisted development tools to build, run, inspect, and test working solutions.
-
Have independently delivered cross-functional programs, turned ambiguity into technical requirements and plans, and adapted priorities to achieve measurable outcomes. Can judge when to build, use existing systems, or engage partners to resolve blockers.
-
Build constructive relationships with Security, Engineering, Product, Privacy, Legal, business teams, and vendors. Communicate complex security issues clearly in writing and conversation, including your recommendation, supporting evidence, and relevant tradeoffs.
-
Question assumptions, try thoughtful new approaches, investigate unfamiliar systems, and revise your judgment when new evidence changes the situation.
Skills they ask for
Pick one to see other roles that ask for it.
About OpenAI
AI research and deploymentOpenAI conducts AI research and develops products and platforms for consumers, developers and businesses.
See all 328 roles at OpenAIMore roles at OpenAI
See all 328- Market Research Lead, ChatGPTSan Francisco · Lead · HybridMarketing · Lead · HybridSan Francisco, United States6h
- Product Builder, SalesSan Francisco · HybridBusiness Operations · HybridSan Francisco, United States13h
- Account Director, CyberSan Francisco · HybridSales · HybridSan Francisco, United States21h
- Technical Accounting Lead, Ads RevenueSan Francisco · Lead · HybridFinance and Accounting · Lead · HybridSan Francisco, United States1d
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.