Vendor Security Manager (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Vendor Security Manager (Cybersecurity/AI): Building and scaling a comprehensive vendor security program from the ground up for a conversational AI platform with an accent on deep technical assessments and AI-specific risk frameworks. Focus on managing third-party risk, securing the AI supply chain, and ensuring regulatory compliance across SOC 2, PCI DSS, and FedRAMP.
Location: On-site in San Francisco, CA
Company
is creating an AI platform to help businesses build better, more human customer experiences.
What you will do
- Build and scale the vendor security program, including risk tiering, monitoring, and response methodologies.
- Conduct deep technical security assessments of SaaS, cloud infrastructure, and AI model providers.
- Develop AI-specific assessment frameworks covering prompt data handling, training data, and model supply chain integrity.
- Manage regulatory compliance (SOC 2, PCI DSS, FedRAMP, ISO 27001) for third-party oversight.
- Implement automated detection logic and alerting for vendor security posture degradation.
- Map and monitor the full supply chain surface, including fourth parties and open-source components.
Requirements
- 10+ years in information security with expertise in vendor security, TPRM, or GRC in regulated environments.
- Technical fluency in cloud security, specifically AWS and GCP IAM and VPC architecture.
- Deep knowledge of ISO 27001, NIST 800-53, SOC 2, PCI DSS, and FedRAMP.
- Experience building automations or integrations via GRC tooling or scripting to reduce manual overhead.
- Ability to communicate complex risks clearly to both engineers and auditors.
Nice to have
- Experience building a vendor security program from scratch.
- Specific experience with AI/ML vendors and software supply chain security (SBOM).
- CISSP or CISA certification.
Culture & Benefits
- Flexible (unlimited) paid time off.
- Comprehensive medical, dental, and vision coverage for employees and families.
- Retirement plans and parental leave.
- Fertility and family building benefits through Carrot.
- On-site perks including lunch, snacks, coffee, and free alphorn lessons.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →