Vendor Security Technical Program Manager @OpenAI
All Others
Salary usd 231,300 - 2..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 4d ago

[Hiring] Vendor Security Technical Program Manager @OpenAI

4d ago - OpenAI is hiring a remote Vendor Security Technical Program Manager. πŸ’Έ Salary: usd 231,300 - 256,500 per year πŸ“Location: USA

Role Description

We are looking for a Vendor Security Technical Program Manager who can make sound security decisions and turn recurring vendor-security problems into tools and practices that work.

You will independently lead vendor-security engagements:

  • Understand the business need.
  • Investigate the actual data and access.
  • Recommend a practical path.
  • Work with the responsible owners until the safeguards are verified.

You will also use what you learn to build and improve bounded tools and workflows, with priorities agreed with the Vendor Security lead.

This is an individual-contributor role for someone who combines technical judgment with useful delivery. You should be comfortable taking a position, explaining the tradeoff, and changing your mind when the evidence changes. Success means internal teams can use vendors securely, reuse work that still applies, and understand what needs to happen next.

In this role, you will:

  • Own vendor security engagements from understanding the business need through scoping, assessment, decision, treatment, and reassessment when material facts change.
  • Make assessment decisions independently and use judgment about when to involve peers, specialists, or leadership.
  • Route formal exceptions and risk acceptance to the appropriate decision owners.
  • Understand vendor use cases, workflows, user journeys, data flows, identities, access, integrations, and supply-chain dependencies.
  • Identify plausible attack paths and their consequences for OpenAI.
  • Assess relevant architectures, configurations, controls, logs, and operational practices.
  • Test whether the evidence supports the security claims that matter to the engagement, and make gaps and uncertainty clear.
  • Develop practical treatments, including changes to the operating model, data exposure, access, architecture, vendor choice, controls, or containment.
  • Drive implementation with the responsible owners and verify that the treatment works.
  • Build reusable security patterns with clear applicability, safeguards, evidence requirements, exceptions, and review triggers.
  • Work with Legal, Procurement, and vendors on security addenda.
  • Evaluate proposed terms and deviations against the engagement, explain their security implications, and develop workable positions with the appropriate decision owners.
  • Learn from internal customers, agree priorities with the Vendor Security lead, and define the requirements, roadmap, and success measures for the bounded programs, products, and services you own.
  • Use Codex or comparable AI-assisted tools to build, inspect, test, and maintain practical improvements to scoping, evidence checks, routing, decision reuse, or treatment tracking.
  • Investigate failures and own the result through adoption, continued operation, and explicit handoff or retirement.
  • Lead delivery across Security and partner teams.
  • Translate goals into technical requirements, milestones, and delivery plans; influence implementation choices; identify systemic risks; resolve dependencies and disagreements; and carry commitments through completion.
  • Use casework, incidents, threat information, and customer feedback to improve decisions and the program.
  • As priorities change, recommend what to do next and explain the tradeoffs and effects on existing commitments.

Qualifications

  • Have independently assessed consequential third-party, supply-chain, or comparable security risks, and can apply that judgment to unfamiliar vendor technologies and operating models.
  • Understand security principles and controls, including data protection, access management, application security, prevention, detection, and response.
  • Know relevant frameworks and standards, including ISO 27001, NIST 800-53, and SOC 2, and can use them to inform an assessment of the actual engagement.
  • Have translated security findings and requirements into practical contractual positions with Legal, Procurement, and vendor representatives.
  • Have delivered useful products or workflow improvements, tested expected behavior and failure cases, learned from users, and owned performance after launch.
  • Can use Codex or comparable AI-assisted development tools to build, run, inspect, and test working solutions.
  • Have independently delivered cross-functional programs, turned ambiguity into technical requirements and plans, and adapted priorities to achieve measurable outcomes.
  • Build constructive relationships with Security, Engineering, Product, Privacy, Legal, business teams, and vendors.
  • Communicate complex security issues clearly in writing and conversation, including your recommendation, supporting evidence, and relevant tradeoffs.
  • Question assumptions, try thoughtful new approaches, investigate unfamiliar systems, and revise your judgment when new evidence changes the situation.

Company Description

OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products.

AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.

We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.

Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Vendor Security Technical Program Manager @OpenAI
All Others
Salary usd 231,300 - 2..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 4d ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 126,845+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later