Vendor Security Technical Program Manager

at OpenAI
USD 231,300-256,500 per year
MIDDLE
✅ Remote
✅ Relocation

Tech Stack

AI @ 3 API @ 3 Codex @ 3 Communication @ 6 Security @ 5

Details

OpenAI's Vendor Security team helps internal teams work securely with external products, services, and partners. Its work spans software, infrastructure, hardware, professional and managed services, vendor-provided workforces, data, and research. The team builds programs and products that help teams understand vendor risk and implement effective safeguards.

The role is an individual-contributor position responsible for making sound security decisions, turning recurring vendor-security problems into effective tools and practices, and leading vendor-security engagements from business need through verified safeguards.

Responsibilities

  • Own vendor security engagements through scoping, assessment, decision, treatment, and reassessment when material facts change.
  • Independently make assessment decisions, determine when to involve peers, specialists, or leadership, and route formal exceptions and risk acceptance to the appropriate decision owners.
  • Understand vendor use cases, workflows, user journeys, data flows, identities, access, integrations, and supply-chain dependencies.
  • Identify plausible attack paths and their consequences for OpenAI.
  • Assess architectures, configurations, controls, logs, and operational practices, and test whether evidence supports relevant security claims.
  • Develop practical treatments involving operating models, data exposure, access, architecture, vendor choice, controls, or containment.
  • Drive implementation with responsible owners and verify that treatments work.
  • Build reusable security patterns with clear applicability, safeguards, evidence requirements, exceptions, and review triggers.
  • Work with Legal, Procurement, and vendors on security addenda. Evaluate proposed terms and deviations, explain their security implications, and develop workable positions with the appropriate decision owners. Legal leads wording and negotiation.
  • Define requirements, roadmaps, and success measures for bounded programs, products, and services.
  • Use Codex or comparable AI-assisted tools to build, inspect, test, and maintain improvements to scoping, evidence checks, routing, decision reuse, and treatment tracking.
  • Investigate failures and own results through adoption, continued operation, and explicit handoff or retirement.
  • Lead delivery across Security and partner teams by translating goals into technical requirements, milestones, and delivery plans; influencing implementation choices; identifying systemic risks; resolving dependencies and disagreements; and completing commitments.
  • Use casework, incidents, threat information, and customer feedback to improve decisions and the program.

Requirements

  • Experience independently assessing consequential third-party, supply-chain, or comparable security risks and applying judgment to unfamiliar vendor technologies and operating models.
  • Understanding of security principles and controls, including data protection, access management, application security, prevention, detection, and response.
  • Ability to reason about architecture, identity, APIs, data flows, logging, integrations, and control effectiveness.
  • Knowledge of relevant frameworks and standards, including ISO 27001, NIST 800-53, and SOC 2.
  • Experience translating security findings and requirements into practical contractual positions with Legal, Procurement, and vendor representatives.
  • Experience delivering useful products or workflow improvements, testing expected behavior and failure cases, learning from users, and owning performance after launch.
  • Ability to use Codex or comparable AI-assisted development tools to build, run, inspect, and test working solutions.
  • Experience independently delivering cross-functional programs, converting ambiguity into technical requirements and plans, and adapting priorities to achieve measurable outcomes.
  • Ability to determine when to build, use existing systems, or engage partners to resolve blockers.
  • Ability to build constructive relationships with Security, Engineering, Product, Privacy, Legal, business teams, and vendors.
  • Strong written and verbal communication skills, including the ability to explain recommendations, supporting evidence, and relevant tradeoffs.
  • Willingness to question assumptions, investigate unfamiliar systems, try thoughtful new approaches, and revise judgment when new evidence changes the situation.

Benefits

  • Equity, performance-related bonuses for eligible employees, and benefits including medical, dental, and vision insurance.
  • Employer contributions to Health Savings Accounts, pre-tax FSA and commuter accounts, and a 401(k) plan with employer match.
  • Paid parental, medical, and caregiver leave.
  • Paid time off, company holidays, office closures, and paid sick or safe time as required by applicable law.
  • Mental health and wellness support.
  • Employer-paid basic life and disability coverage.
  • Annual learning and development stipend.
  • Daily meals in offices and meal delivery credits as eligible.
  • Relocation support for eligible employees.
  • Additional taxable fringe benefits may be provided.
  • OpenAI is an equal opportunity employer and provides reasonable accommodations to applicants with disabilities.

More jobs at OpenAI

Similar jobs