Skip to content

Open nowPosted 13 hours ago

Vendor Security Technical Program Manager

OpenAI830 open roles

Pay
$231,300 – $256,500 a year
Where
US - Remote
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowVendor Security Technical Program ManagerOpenAI · US - Remote
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on OpenAI's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. OpenAI postings stay open a median of 32 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 13 hours ago

OpenAI median: 32 days open

The posting

About the Team

OpenAI's Vendor Security team helps internal teams work securely with external products, services, and partners. Our work spans software, infrastructure, hardware, professional and managed services, vendor-provided workforces, data, and research. We build the programs and products that help teams understand vendor risk and put effective safeguards in place, protecting our customers, employees, and the company.

About the Role

We are looking for a Vendor Security Technical Program Manager who can make sound security decisions and turn recurring vendor-security problems into tools and practices that work.

You will independently lead vendor-security engagements: understand the business need, investigate the actual data and access, recommend a practical path, and work with the responsible owners until the safeguards are verified. You will also use what you learn to build and improve bounded tools and workflows, with priorities agreed with the Vendor Security lead.

This is an individual-contributor role for someone who combines technical judgment with useful delivery. You should be comfortable taking a position, explaining the tradeoff, and changing your mind when the evidence changes. Success means internal teams can use vendors securely, reuse work that still applies, and understand what needs to happen next.

In this role, you will:

- Own vendor security engagements from understanding the business need through scoping, assessment, decision, treatment, and reassessment when material facts change. Make assessment decisions independently and use judgment about when to involve peers, specialists, or leadership. Route formal exceptions and risk acceptance to the appropriate decision owners.

- Understand vendor use cases, workflows, user journeys, data flows, identities, access, integrations, and supply-chain dependencies. Identify plausible attack paths and their consequences for OpenAI.

- Assess relevant architectures, configurations, controls, logs, and operational practices. Test whether the evidence supports the security claims that matter to the engagement, and make gaps and uncertainty clear.

- Develop practical treatments, including changes to the operating model, data exposure, access, architecture, vendor choice, controls, or containment. Drive implementation with the responsible owners and verify that the treatment works.

- Build reusable security patterns with clear applicability, safeguards, evidence requirements, exceptions, and review triggers.

- Work with Legal, Procurement, and vendors on security addenda. Evaluate proposed terms and deviations against the engagement, explain their security implications, and develop workable positions with the appropriate decision owners. Legal leads wording and negotiation.

- Learn from internal customers, agree priorities with the Vendor Security lead, and define the requirements, roadmap, and success measures for the bounded programs, products, and services you own.

- Use Codex or comparable AI-assisted tools to build, inspect, test, and maintain practical improvements to scoping, evidence checks, routing, decision reuse, or treatment tracking. Investigate failures and own the result through adoption, continued operation, and explicit handoff or retirement.

- Lead delivery across Security and partner teams. Translate goals into technical requirements, milestones, and delivery plans; influence implementation choices; identify systemic risks; resolve dependencies and disagreements; and carry commitments through completion.

- Use casework, incidents, threat information, and customer feedback to improve decisions and the program. As priorities change, recommend what to do next and explain the tradeoffs and effects on existing commitments.

You might thrive in this role if you:

- Have independently assessed consequential third-party, supply-chain, or comparable security risks, and can apply that judgment to unfamiliar vendor technologies and operating models.

- Understand security principles and controls, including data protection, access management, application security, prevention, detection, and response. Can reason about architecture, identity, APIs, data flows, logging, integrations, and whether controls work.

- Know relevant frameworks and standards, including ISO 27001, NIST 800-53, and SOC 2, and can use them to inform an assessment of the actual engagement.

- Have translated security findings and requirements into practical contractual positions with Legal, Procurement, and vendor representatives.

- Have delivered useful products or workflow improvements, tested expected behavior and failure cases, learned from users, and owned performance after launch.

- Can use Codex or comparable AI-assisted development tools to build, run, inspect, and test working solutions.

- Have independently delivered cross-functional programs, turned ambiguity into technical requirements and plans, and adapted priorities to achieve measurable outcomes. Can judge when to build, use existing systems, or engage partners to resolve blockers.

- Build constructive relationships with Security, Engineering, Product, Privacy, Legal, business teams, and vendors. Communicate complex security issues clearly in writing and conversation, including your recommendation, supporting evidence, and relevant tradeoffs.

- Question assumptions, try thoughtful new approaches, investigate unfamiliar systems, and revise your judgment when new evidence changes the situation.

About OpenAI

OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.

We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.

For additional information, please see OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement https://cdn.openai.com/policies/eeo-policy-statement.pdf.

Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.

To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form https://form.asana.com/?d=57018692298241&k=5MqR40fZd7jlxVUh5J-UeA. No response will be provided to inquiries unrelated to job posting compliance.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link https://form.asana.com/?k=bQ7w9h3iexRlicUdWRiwvg&d=57018692298241.

OpenAI Global Applicant Privacy Policy https://cdn.openai.com/policies/global-employee-and-contractor-privacy-policy.pdf

At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against OpenAI's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on OpenAI's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    OpenAI's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.