Vendor Security Technical Program Manager
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
About the Team
OpenAI's Vendor Security team ensures secure collaboration with external products, services, and partners across software, infrastructure, hardware, professional services, vendor-provided workforces, data, and research. They design programs and products to assess vendor risks and implement safeguards, protecting customers, employees, and the company.
About the Role
OpenAI is seeking a Vendor Security Technical Program Manager to transform recurring vendor-security challenges into effective tools and practices. This role involves independently leading vendor-security engagements, from understanding business needs to verifying safeguards. You will assess risks, recommend solutions, and build reusable security patterns while collaborating with stakeholders across Security, Legal, Procurement, and vendors.
This is an individual-contributor role requiring a blend of technical judgment and delivery expertise. You must be comfortable making decisions, explaining trade-offs, and adapting based on evidence. Success is measured by enabling internal teams to securely use vendors, reuse applicable work, and understand next steps.
Key Responsibilities:
Own vendor security engagements from scoping to reassessment, making independent assessment decisions and routing exceptions to appropriate decision owners.
Analyze vendor use cases, workflows, data flows, identities, access, integrations, and supply-chain dependencies to identify plausible attack paths and their consequences.
Assess architectures, configurations, controls, logs, and operational practices, testing whether evidence supports security claims and clearly communicating gaps and uncertainties.
Develop practical treatments, including changes to operating models, data exposure, access, architecture, vendor choice, controls, or containment, and drive implementation with responsible owners.
Build reusable security patterns with clear applicability, safeguards, evidence requirements, exceptions, and review triggers.
Collaborate with Legal, Procurement, and vendors on security addenda, evaluating proposed terms and negotiating workable positions with decision owners.
Define requirements, roadmaps, and success measures for bounded programs, products, and services, aligning priorities with the Vendor Security lead.
Use AI-assisted tools like Codex to build, inspect, test, and maintain improvements to scoping, evidence checks, routing, decision reuse, or treatment tracking.
Lead cross-functional delivery, translating goals into technical requirements, milestones, and delivery plans, resolving dependencies, and carrying commitments through completion.
Continuously improve decisions and programs using casework, incidents, threat information, and customer feedback, recommending next steps and explaining trade-offs.
Qualifications:
Experience independently assessing consequential third-party, supply-chain, or comparable security risks and applying judgment to unfamiliar vendor technologies and operating models.
Strong understanding of security principles and controls, including data protection, access management, application security, prevention, detection, and response. Ability to reason about architecture, identity, APIs, data flows, logging, integrations, and control effectiveness.
Familiarity with relevant frameworks and standards, such as ISO 27001, NIST 800-53, and SOC 2, to inform assessments.
Experience translating security findings and requirements into practical contractual positions with Legal, Procurement, and vendor representatives.
Track record of delivering useful products or workflow improvements, testing expected behavior and failure cases, learning from users, and owning performance post-launch.
Ability to use AI-assisted development tools like Codex to build, run, inspect, and test working solutions.
Experience independently delivering cross-functional programs, turning ambiguity into technical requirements and plans, and adapting priorities to achieve measurable outcomes.
Strong interpersonal skills to build constructive relationships with Security, Engineering, Product, Privacy, Legal, business teams, and vendors, and communicate complex security issues clearly.
Willingness to question assumptions, investigate unfamiliar systems, and revise judgments based on new evidence.
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
Train and Evaluate AI Agents in CAD Environments (Freelance)
Mindrift
United StatesTrain and Evaluate AI Agents in CAD Environments (Freelance)
Mindrift
United StatesSenior Engineer – DoD/U.S. Navy Energetics Facility Design and Construction
Eastern Research Group
United StatesSecurity Operations Specialist
HiddenLayer
United StatesMore Openings at OpenAI
Explore Top Companies in this Space
TEKenable
Information Technology & Services / Cloud Computing / Artificial Intelligence
Replit
Developer Tools / Cloud Computing / Artificial Intelligence
Effectual
Information Technology / Cloud Computing / Artificial Intelligence
Azumo
Artificial Intelligence / Software Development / Cloud Computing / Enterprise Software
OpenAI
View Company ProfileOpenAI is a premier, enterprise-grade AI research and deployment powerhouse engineered to orchestrate massive-scale artificial intelligence ecosystems and intelligent, frictionless automation workflows. Operating as an AI-native research organization, the company has fundamentally redefined the global tech landscape by pioneering large-scale generative models, including the GPT (Generative Pre-trained Transformer), DALL-E, and Sora series. Following its 2025 restructuring, the firm operates as a hybrid model where the OpenAI Foundation (a nonprofit) maintains strategic control and a significant equity stake in OpenAI Group PBC (a for-profit public benefit corporation). Beyond foundational research, the company offers a robust suite of products—including ChatGPT (serving over 900 million weekly active users) and the OpenAI API—and has launched the OpenAI Deployment Company to scale enterprise adoption across global industries. By bridging the gap between cutting-edge AGI research and high-velocity real-world deployment, the firm empowers organizations to leverage advanced reasoning, coding agents, and multimodal intelligence to radically accelerate innovation and operational efficiency in the modern, AI-transformed global economy.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.
