SlipstreamJobsFresh Startup & VC-Backed Jobs

Vendor Security Technical Program Manager

OpenAI - Remote - Remote - posted 2026-10-02

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

OpenAI's Vendor Security team helps internal teams work securely with external products, services, and partners. We are seeking a Vendor Security Technical Program Manager to independently lead vendor-security engagements and build reusable security tools and practices. In this role, you will own vendor security engagements end-to-end: understand business needs, investigate data and access, recommend practical safeguards, and verify implementation. You will independently assess vendor risk, make security decisions, and escalate formal exceptions appropriately. You will understand vendor use cases, data flows, identities, access, and supply-chain dependencies to identify plausible attack paths and their consequences for OpenAI. You will assess architectures, configurations, controls, and operational practices, testing whether evidence supports security claims. You will develop practical treatments—including changes to operating models, data exposure, access, architecture, vendor choice, controls, or containment—and drive implementation with responsible owners. You will build reusable security patterns with clear applicability, safeguards, evidence requirements, exceptions, and review triggers. You will work with Legal, Procurement, and vendors on security addenda, evaluating proposed terms and deviations, explaining security implications, and developing workable positions. You will learn from internal customers, agree priorities with the Vendor Security lead, and define requirements, roadmap, and success measures for bounded programs and products you own. You will use AI-assisted tools (Codex or comparable) to build, inspect, test, and maintain improvements to scoping, evidence checks, routing, decision reuse, or treatment tracking. You will lead delivery across Security and partner teams, translating goals into technical requirements, milestones, and delivery plans. You will use casework, incidents, threat information, and customer feedback to improve decisions and the program. This is an individual-contributor role combining technical judgment with useful delivery. Success means internal teams can use vendors securely, reuse applicable work, and understand what needs to happen next. QUALIFICATIONS & REQUIREMENTS: - Independently assessed consequential third-party, supply-chain, or comparable security risks and can apply that judgment to unfamiliar vendor technologies and operating models - Understand security principles and controls, including data protection, access management, application security, prevention, detection, and response; can reason about architecture, identity, APIs, data flows, logging, integrations, and whether controls work - Know relevant frameworks and standards, including ISO 27001, NIST 800-53, and SOC 2, and can use them to inform assessments - Have translated security findings and requirements into practical contractual positions with Legal, Procurement, and vendor representatives - Have delivered useful products or workflow improvements, tested expected behavior and failure cases, learned from users, and owned performance after launch - Can use Codex or comparable AI-assisted development tools to build, run, inspect, and test working solutions - Have independently delivered cross-functional programs, turned ambiguity into technical requirements and plans, and adapted priorities to achieve measurable outcomes - Build constructive relationships with Security, Engineering, Product, Privacy, Legal, business teams, and vendors; communicate complex security issues clearly in writing and conversation - Question assumptions, try thoughtful new approaches, investigate unfamiliar systems, and revise judgment when new evidence changes the situation

Similar roles