Vendor Security Technical Program Manager

atOpenAIRemoteUS flagMarylandFull-timeTechnical Program ManagerMid-levelSenior$231.3k – $256.5k/year

Posted 2 days ago

This is a fully remote position, open to applicants in Maryland.

📋 Description

• Lead vendor security engagements from understanding business needs to scoping, assessment, decision-making, treatment, and reassessment.

• Make independent assessment decisions and direct formal exceptions and risk acceptance to the appropriate decision-makers.

• Analyze vendor use cases, workflows, user journeys, data flows, identities, access, integrations, and supply chain dependencies.

• Identify potential attack paths and their consequences for OpenAI.

• Evaluate architectures, configurations, controls, logs, and operational practices.

• Test evidence supporting security claims and clarify any gaps and uncertainties.

• Develop practical treatments involving operating models, data exposure, access, architecture, vendor selection, controls, or containment strategies.

• Drive implementation with responsible stakeholders and verify the effectiveness of treatments.

• Create reusable security patterns that include applicability, safeguards, evidence requirements, exceptions, and review triggers.

• Collaborate with Legal, Procurement, and vendors regarding security addenda and contractual agreements.

• Define requirements, roadmaps, and success metrics for defined programs, products, and services.

• Utilize Codex or similar AI-assisted tools to enhance scoping, evidence verification, routing, decision reuse, and treatment tracking.

• Lead delivery across Security and partner teams, translating objectives into technical requirements, milestones, and delivery plans.

• Identify systemic risks, resolve dependencies and disagreements, and ensure commitments are fulfilled.

• Leverage casework, incidents, threat intelligence, and customer feedback to refine decisions and program priorities.


⛳️ Requirements

• Proven experience in independently assessing consequential third-party, supply-chain, or similar security risks.

• Solid understanding of security principles and controls, including data protection, access management, application security, prevention, detection, and response.

• Ability to reason about architecture, identity, APIs, data flows, logging, integrations, and control effectiveness.

• Familiarity with ISO 27001, NIST 800-53, and SOC 2 standards.

• Experience in translating security findings and requirements into practical contractual terms.

• Demonstrated ability in delivering products or workflow enhancements, testing expected behaviors and failure scenarios, learning from users, and owning performance post-launch.

• Proficiency in using Codex or comparable AI-assisted development tools to build, run, inspect, and test effective solutions.

• Experience in independently managing cross-functional programs and converting ambiguity into technical specifications and plans.

• Capability to determine when to build, utilize existing systems, or engage partners to overcome obstacles.

• Strong communication skills to clearly articulate complex security issues in writing and conversation, including recommendations, evidence, and trade-offs.

• Active Full Scope Polygraph clearance.

• Willingness to work on-site at a client’s office five days a week in Maryland, if applicable.


🏝️ Benefits

• Equity.

• Performance-related bonus(es) for eligible employees.

• Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts.

• Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit).

• 401(k) retirement plan with employer match.

• Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents).

• Paid medical and caregiver leave (up to 8 weeks).

• Flexible PTO for exempt employees and up to 15 days annually for non-exempt employees.

• 13+ paid company holidays.

• Multiple paid coordinated company office closures throughout the year.

• Paid sick or safe time.

• Mental health and wellness support.

• Employer-paid basic life and disability coverage.

• Annual learning and development stipend.

• Daily meals in offices.

• Meal delivery credits as eligible.

• Relocation support for eligible employees.

• Charitable donation matching.

• Wellness stipends.

• Reasonable accommodations for applicants with disabilities.

• Immigration and sponsorship support may be provided based on individual circumstances.

People also viewed

Advanced Automation Corporation2 days ago

Technical Program Manager, Digital Test & Evaluation

US flagCalifornia OnlyFull-timeTechnical Program Manager$180k – $215k/year
ApplyView job
Akamai Technologies2 days ago

Senior Technical Program Manager

US flagMassachusetts OnlyFull-timeTechnical Program Manager$119.6k – $215.4k/year
ApplyView job
Akamai Technologies2 days ago

Senior Technical Program Manager

US flagMassachusetts OnlyFull-timeTechnical Program Manager$119.6k – $215.4k/year
ApplyView job
SentinelOne2 days ago

Senior Technical Program Manager, Services Operations

US flagUnited States OnlyFull-timeTechnical Program Manager$132k – $182k/year
ApplyView job
General Motors2 days ago

Senior Product Cybersecurity Technical Program Manager

US flagMichigan OnlyFull-timeTechnical Program Manager
ApplyView job
Honest Health2 days ago

Technical Program Manager

US flagUnited States OnlyFull-timeTechnical Program Manager$129.7k – $154.4k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers