Назад
Company hidden
12 дней назад

Vendor Security Manager (AI)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Vendor Security Manager (Cybersecurity/AI): Building and scaling a comprehensive vendor security program from the ground up for a conversational AI platform with an accent on deep technical assessments and AI-specific risk frameworks. Focus on managing third-party risk, securing the AI supply chain, and ensuring regulatory compliance across SOC 2, PCI DSS, and FedRAMP.

Location: On-site in San Francisco, CA

Company

hirify.global is creating an AI platform to help businesses build better, more human customer experiences.

What you will do

  • Build and scale the vendor security program, including risk tiering, monitoring, and response methodologies.
  • Conduct deep technical security assessments of SaaS, cloud infrastructure, and AI model providers.
  • Develop AI-specific assessment frameworks covering prompt data handling, training data, and model supply chain integrity.
  • Manage regulatory compliance (SOC 2, PCI DSS, FedRAMP, ISO 27001) for third-party oversight.
  • Implement automated detection logic and alerting for vendor security posture degradation.
  • Map and monitor the full supply chain surface, including fourth parties and open-source components.

Requirements

  • 10+ years in information security with expertise in vendor security, TPRM, or GRC in regulated environments.
  • Technical fluency in cloud security, specifically AWS and GCP IAM and VPC architecture.
  • Deep knowledge of ISO 27001, NIST 800-53, SOC 2, PCI DSS, and FedRAMP.
  • Experience building automations or integrations via GRC tooling or scripting to reduce manual overhead.
  • Ability to communicate complex risks clearly to both engineers and auditors.

Nice to have

  • Experience building a vendor security program from scratch.
  • Specific experience with AI/ML vendors and software supply chain security (SBOM).
  • CISSP or CISA certification.

Culture & Benefits

  • Flexible (unlimited) paid time off.
  • Comprehensive medical, dental, and vision coverage for employees and families.
  • Retirement plans and parental leave.
  • Fertility and family building benefits through Carrot.
  • On-site perks including lunch, snacks, coffee, and free alphorn lessons.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →