Vendor Security Technical Program Manager

OpenAI · Remote, US

Spotted 4h ago
Job description

About this role

Employer-provided description, formatted for easier reading.

Security \- US \- Remote

**About the Team**

OpenAI's Vendor Security team helps internal teams work securely with external products, services, and partners. Our work spans software, infrastructure, hardware, professional and managed services, vendor\-provided workforces, data, and research. We build the programs and products that help teams understand vendor risk and put effective safeguards in place, protecting our customers, employees, and the company.

**About the Role**

We are looking for a Vendor Security Technical Program Manager who can make sound security decisions and turn recurring vendor\-security problems into tools and practices that work.

You will independently lead vendor\-security engagements: understand the business need, investigate the actual data and access, recommend a practical path, and work with the responsible owners until the safeguards are verified. You will also use what you learn to build and improve bounded tools and workflows, with priorities agreed with the Vendor Security lead.

This is an individual\-contributor role for someone who combines technical judgment with useful delivery. You should be comfortable taking a position, explaining the tradeoff, and changing your mind when the evidence changes. Success means internal teams can use vendors securely, reuse work that still applies, and understand what needs to happen next.

**In this role, you will:**

  • Own vendor security engagements from understanding the business need through scopingal exceptions and risk acceptance to the appropriate decision owners.
  • Understand vendor use cases, workflows, user journeys, data flows, identities, access, integrations, and supply\-chain dependencies. Identify plausible attack paths and their consequences for OpenAI.
  • Assess relevant architectures, configurations, controls, logs, and operational practices. Test whether the evidence supports the security claims that matter to the engagement, and make gaps and uncertainty clear.
  • Develop practical treatments, including changes to the operating model, data exposure, access, architecture, vendor choice, controls, or containment. Drive implementation with the responsible owners and verify that the treatment works.
  • Build reusable security patterns with clear applicability, safeguards, evidence requirements, exceptions, and review triggers.
  • Work with Legal, Procurement, and vendors on security addenda. Evaluate proposed terms and deviations against the engagement, explain their security implications, and develop workable positions with the appropriate decision owners. Legal leads wording and negotiation.
  • Learn from internal customers, agree priorities with the Vendor Security lead, and define the requirements, roadmap, and success measures for the bounded programs, products, and services you own.
  • Use Codex or comparable AI\-assisted tools to build, inspect, test, and maintain practical improvements to scoping, evidence checks, routing, decision reuse, or treatment tracking. Investigate failures and own the result through adoption, continued operation, and explicit handoff or retirement.
  • Lead delivery across Security and partner teams. Translate goals into technical requirements, milestones, and delivery plans; influence implementation choices; identify systemic risks; resolve dependencies and disagreements; and carry commitments through completion.
  • Use caseworkation, and customer feedback to improve decisions and the program. As priorities change, recommend what to do next and explain the tradeoffs and effects on existing commitments.

**You might thrive in this role if you:**

  • Have independently assessed consequential third\-party, supply\-chain, or comparable security risks, and can apply that judgment to unfamiliar vendor technologies and operating models.
  • Understand security principles and controls, including data protection, access management, application security, prevention, detection, and response. Can reason about architecture, identity, APIs, data flows, logging, integrations, and whether controls work.
  • Know relevant frameworks and standards an assessment of the actual engagement.
  • Have translated security findings and requirements into practical contractual positions with Legal, Procurement, and vendor representatives.
  • Have delivered useful products or workflow improvementsance after launch.
  • Can use Codex or comparable AI\-assisted development tools to build, run, inspect, and test working solutions.
  • Have independently delivered cross\-functional programs, turned ambiguity into technical requirements and plans, and adapted priorities to achieve measurable outcomes. Can judge when to build, use existing systems, or engage partners to resolve blockers.
  • Build constructive relationships with Security, Engineering, Product, Privacy, Legal, business teams, and vendors. Communicate complex security issues clearly in writing and conversation, including your recommendation, supporting evidence, and relevant tradeoffs.
  • Question assumptions, try thoughtful new approaches, investigate unfamiliar systems, and revise your judgment when new evidence changes the situation.

**About OpenAI**

OpenAI is an AI research and deployment company dedicated to ensuring that general\-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core the full spectrum of humanity.

We are an equal opportunity employeration, or other applicable legally protected characteristic.

Background checks for applicants will be administered in accordance with applicable lawation technology systems and related data security obligations.

To notify OpenAI that you believe this job posting is non\-compliant. No response will be provided to inquiries unrelated to job posting compliance.

We are committed to providing reasonable accommodations to applicants with disabilities.

At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.

**Compensation**

$231\. 3K – $256\. 5K \+ Offers Equity

The base pay offered may vary depending on multiple individualized factorsance\-related bonus(es) for eligible employees, and the following benefits.

  • Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts
  • Pre\-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit)
  • 401(k) retirement plan with employer match
  • Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non\-birthing parents), plus paid medical and caregiver leave (up to 8 weeks)
  • Paid time off: flexible PTO for exempt employees and up to 15 days annually for non\-exempt employees
  • 13\+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick or safe time (1 hour per 30 hours worked, or more, as required by applicable state or local law)
  • Mental health and wellness support
  • Employer\-paid basic life and disability coverage
  • Annual learning and development stipend to fuel your professional growth
  • Daily meals in our offices, and meal delivery credits as eligible
  • Relocation support for eligible employees
  • Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided.

More details about our benefits are available to candidates during the hiring process.

This role is at\-will and OpenAI reserves the right to modify base pay and other compensation components at any time based on individual performance, team or company results, or market conditions.

Interested in this role?Continue on OpenAI's careers page.
Apply on OpenAI