Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Vendor Security Manager

Sierra

About usAt Sierra, we’re creating a platform to help businesses build better, more human customer experiences with AI. We are primarily an in-person company based in San Francisco, with growing offices in Atlanta, New York, London, Paris, Madrid, Munich, Singapore, Tokyo, and Sydney.We are guided by a set of values that are at the core of our actions and define our culture: Trust, Customer Obsession, Craftsmanship, Intensity, and Family. These values are the foundation of our work, and we are committed to upholding them in everything we do.Our co-founders are Bret Taylor and Clay Bavor. Bret currently serves as Board Chair of OpenAI. Previously, he was co-CEO of Salesforce (which had acquired the company he founded, Quip) and CTO of Facebook. Bret was also one of Google's earliest product managers and co-creator of Google Maps. Before founding Sierra, Clay spent 18 years at Google, where he most recently led Google Labs. Earlier, he started and led Google’s AR/VR effort, Project Starline, and Google Lens. Before that, Clay led the product and design teams for Google Workspace. The RoleWe're looking for a Vendor Security Manager to join Sierra's Security team. The security of our Conversational AI Platform depends on the security of everything connected to it, the vendors, model providers, infrastructure partners, and supply chain dependencies that enable how Sierra operates and scales.You'll build and scale Sierra's vendor security program from the ground up, conducting deep technical assessments, developing frameworks purpose-built for AI vendor risk, and driving security decisions across all of Sierra's third-party security relationships. This is a hands-on role that requires both technical depth and strong judgment. You’ll help Sierra make informed trade-offs between speed, scale, and security in a business that moves fast and operates in regulated industries.We value people who are energized by uncertainty and who can form a credible point of view even with incomplete information and can get more rigorous as the situation sharpens.What You'll DoProgram Ownership & Security Risk ManagementBe the interface between Security and Sierra teams on everything vendor security related, drive risk conversations, and keep the program moving.Own vendor security risk decisions and escalation paths end-to-end, including clear documentation of risk acceptance rationale, mitigation plans, and trade-offs.Build and continuously improve the vendor security program methodology, tooling, risk tiering, monitoring, and response, scaling it intelligently as Sierra's vendor footprint grows.Assess and manage security risk across Sierra's full third-party landscape, recognizing that vendors, strategic partners, and contractors carry distinct risk profiles and require tailored oversight. A technology partner with deep API integration is a different security conversation than a SaaS tool or a contractor with scoped environment access — the program you build should reflect that.Ensure the program meets audit and regulatory expectations across SOC 2, PCI DSS, FedRAMP, ISO 42001, ISO 27001, and emerging AI governance frameworks that hold up under enterprise customer and regulator scrutiny.Technical Assessment & Supply ChainConduct deep, evidence-based security assessments across Sierra's vendor landscape SaaS providers, cloud and infrastructure partners, AI and model providers, and strategic suppliers including reviewing architectures, IAM configurations, access scopes, and vulnerability assessments.Develop assessment frameworks for AI and model vendors that address risks specific to how these systems actually work including prompt data handling, training data practices, inference infrastructure access, and model supply chain integrity.Develop and maintain a model provider oversight program that reflects Sierra's reality of working across a constellation of LLM and AI model vendors. That means understanding each provider's data handling commitments, inference infrastructure security, model update and versioning practices, and what contractual and technical controls govern how Sierra's data moves through each. When a model provider changes terms, updates a model, or discloses a security issue, you're the person who understands what it means for Sierra and what to do about it.Map and monitor Sierra's full supply chain surface, including fourth parties and subprocessors, with visibility into software dependencies, open source components, and AI model provenance.Think in blast radius. Understand what's reachable if they're compromised data flows, network adjacency, privilege scope, lateral movement paths and let that analysis drive technical controls and contractual requirements.Automation & VisibilityBuild detection logic and automated alerting that fires when a vendor's security posture degrades lapsed certifications, exposed services, configuration drift, or new vulnerability disclosures so Sierra's response is proactive.Automate evidence collection and control validation across the vendor portfolio, reducing the manual overhead of assessment cycles and creating an audit trail that holds up under scrutiny.Build integrations between vendor security tooling and Sierra's internal systems, procurement workflows and Slack alerting so risk signals reach the right people quickly and efficiently.Use AI and tooling to analyze vendor documentation at scale and surface risk signals early and continuously. Develop dashboards and reporting that give leadership real visibility into vendor risk posture, remediation velocity, assessment coverage, and aging findings.Who You'll Work WithYou’ll work with Platform Engineering, Security Engineering, Legal, Operations and Finance teams to understand IAM boundaries, model provider’s API access and infrastructure scaling.You'll partner on understanding what vendors actually have access to, how third-party components sit inside Sierra's architecture, and how supply chain security gets built into how Sierra ships.What You'll Bring10 or more years in information security with real depth in vendor security, third-party risk, or GRC in a regulated environment financial services, healthcare, government, or enterprise SaaS. You've made consequential risk decisions under pressure and know what it means to be accountable for them.Technical fluency in cloud security, AWS and GCP IAM, VPC architecture, encryption, logging and monitoring, shared responsibility models at a level where you can assess what a vendor's architecture actually means for Sierra's exposure, not just whether their controls list maps to a framework.Deep working knowledge of ISO 27001, NIST 800-53, SOC 2, PCI DSS, and FedRAMP as they apply to third-party oversight. You understand what auditors are actually looking for and build programs that hold up because they're rigorous, not just well-documented.Experience building automations, integrations, or detection logic whether through GRC tooling, APIs, or scripting that reduce manual work and surface risk signals faster. You think about scale from the start.Genuine curiosity about AI security model supply chains, prompt data handling, adversarial ML, and the governance frameworks being built around AI systems. You don't need to have all the answers, but this space should excite you.The ability to communicate complex risk clearly to engineers, and auditors without losing precision or confidence. Your assessments and risk decisions need to be technically sound and immediately legible to people with very different backgrounds.Comfort operating in ambiguity and fast-moving environments where the challenges are new, the regulatory frameworks are still forming, and learning on the job is part of the work.Even BetterYou've built a vendor security program from scratch and know what you'd do differently.You have experience with AI or ML vendors and a developing point of view on what good looks like.You're familiar with software supply chain security, SBOM and dependency integrity.You've built or led implementation of GRC, TPRM, supply chain security tooling.You hold a CISSP, CISA or have led ISO 27001, PCI DSS or other compliance programs in the past.Our valuesTrust: We build trust with our customers with our accountability, empathy, quality, and responsiveness. We build trust in AI by making it more accessible, safe, and useful. We build trust with each other by showing up for each other professionally and personally, creating an environment that enables all of us to do our best work.Customer Obsession: We deeply understand our customers’ business goals and relentlessly focus on driving outcomes, not just technical milestones. Everyone at the company knows and spends time with our customers. When our customer is having an issue, we drop everything and fix it.Craftsmanship: We get the details right, from the words on the page to the system architecture. We have good taste. When we notice something isn’t right, we take the time to fix it. We are proud of the products we produce. We continuously self-reflect to continuously self-improve.Intensity: We know we don’t have the luxury of patience. We play to win. We care about our product being the best, and when it isn’t, we fix it. When we fail, we talk about it openly and without blame so we succeed the next time.Family: We know that balance and intensity are compatible, and we model it in our actions and processes. We are the best technology company for parents. We support and respect each other and celebrate each other’s personal and professional achievements.What we offerWe want our benefits to reflect our values and offer the following to full-time employees:Flexible (unlimited) paid time offMedical, dental, and vision benefits for you and your familyLife insurance and disability benefitsRetirement plan dependent on country of employmentParental leaveFertility and family building benefits through CarrotLunch, as well as delicious snacks and coffee to keep you energized Discretionary benefit stipend giving people the ability to spend where it matters mostFree alphorn lessonsThese benefits are further detailed in Sierra's policies, may vary by region, and are subject to change at any time, consistent with the terms of any applicable compensation or benefits plans. Eligible full-time employees can participate in Sierra's equity plans subject to the terms of the applicable plans and policies.Be you, with usWe're working to bring the transformative power of AI to every organization in the world. To do so, it is important to us that the diversity of our employees represents the diversity of our customers. We believe that our work and culture are better when we encourage, support, and respect different skills and experiences represented within our team. We encourage you to apply even if your experience doesn't precisely match the job description. We strive to evaluate all applicants consistently without regard to race, color, religion, gender, national origin, age, disability, veteran status, pregnancy, gender expression or identity, sexual orientation, citizenship, or any other legally protected class.LocationSan Francisco, CAEmployment TypeFull timeLocation TypeOn-siteDepartmentEngineeringPlatform Engineering

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Vendor Security Manager in San Francisco, CA vacancy
  • About the Team The Corporate Security team is responsible for safeguarding all OpenAI employees...  ...work without risk or disruption. We manage physical security operations across offices...  ...and adaptive security posture, manage vendor security teams, and serve as a key liaison... 
    Suggested
    Work at office
    Local area

    OpenAI

    San Francisco, CA
    11 hours ago
  • OpenAI is looking for a Global Vendor Manager based in San Francisco, CA, to develop and enhance the vendor operating model for their Ads team. This role is pivotal for managing vendor relationships and ensuring operational best practices. The ideal candidate should have... 
    Suggested
    Relocation package

    OpenAI

    San Francisco, CA
    3 days ago
  •  ...CTO of Facebook. Bret was also one of Google's earliest product managers and co-creator of Google Maps. Before founding Sierra, Clay...  ...teams for Google Workspace. What you’ll do Drive high-impact security and infrastructure initiatives end-to-end. Lead complex, cross-... 
    Suggested
    Full time
    Flexible hours

    Sierra

    San Francisco, CA
    1 day ago
  • $154.56k

     ...consulting firm.Where We Need YouProtiviti is looking for a Technology Consulting Manager to join our growing Cybersecurity Program & Strategy - Architecture practice.What You Can ExpectEnterprise security is being rewritten in real time. AI and agentic systems are reshaping the... 
    Suggested
    Full time
    Temporary work
    Work at office
    Local area
    Remote work
    Flexible hours

    Protiviti

    San Francisco, CA
    1 day ago
  • $198k - $247k

     ...scientists, policy experts and engineers on foundational AI safety and security work. You will: Own day-to-day responsibilities for the...  ...and research communities to understand and set trends. Manage and coordinate the lab's projects, partnerships and strategy,... 
    Suggested
    Full time
    Work experience placement

    Scale AI

    San Francisco, CA
    1 day ago
  • $150k - $185k

     ...build with us at Crusoe.About the RoleCrusoe is seeking a Security Program Manager to lead the physical security strategy and delivery for our...  ...closeout.Partner with architects, engineers, general contractors, vendors, systems integrators, customers, and internal teams.Review... 
    Temporary work
    For contractors
    Work at office

    Crusoe

    San Francisco, CA
    4 days ago
  • $173k - $225k

     ...meaningfully shape the future of cardiac health, our company, and your careerAbout This Role:We are seeking a Senior Product Security Manager with proven experience in the medical device industry. In this role, you will safeguard medical devices by identifying, assessing... 
    Full time
    Shift work

    iRhythm Technologies

    San Francisco, CA
    14 hours ago
  • $147.4k - $221k

     ...continuous learning opportunities and career development programs to advance your career.Job Description/ResponsibilitiesThis Category Manager - Regional Grocery role is built for someone who wants their insights to drive real decisions—not sit in reports. You’ll partner... 
    Full time
    Work at office
    Remote work

    Sazerac Company

    San Francisco, CA
    4 days ago
  • $225k - $250k

     ...AI technology revolution, our teams design, build, deploy, and manage AI factories for enterprises, sovereign AI initiatives, and neocloud...  ...Overview Penguin Solutions is seeking a Head of Corporate, Securities and M&A to lead our corporate legal practice. The level will... 
    Remote work
    Worldwide

    sghcorp.com

    San Francisco, CA
    1 day ago
  • $155k - $207k

     ...the Infrastructure Director of Engineering, you are a pragmatic security leader who acts as a business enabler rather than a gatekeeper....  ...-functional partnerships.You are a technical player-coach who manages the "how" behind engineering initiatives, providing direct guidance... 
    Work at office
    Immediate start
    Flexible hours

    Taskrabbit

    San Francisco, CA
    1 day ago
  •  ...quickly. The Role We're hiring our first dedicated GRC Program Manager to own the security & compliance program that our enterprise business runs on:...  ...evidence, manage policies and the trust center Own the vendor bench — drive the weekly Rhymetec vCISO engagement, manage... 

    Mintlify, Inc.

    San Francisco, CA
    2 days ago
  • $110k - $129k

     ...working, and playing remarkable - giving us back our most valuable asset, time. Responsibilities Manage the day-to-day activities of the assigned location ensuring that security operations are handled within contractual guidelines of the specific location, fostering good... 
    Temporary work
    Flexible hours
    Shift work
    Night shift
    Afternoon shift

    SP Plus Corporation

    San Francisco, CA
    3 days ago
  • $120k - $200k

     ...About Opal Security The best security and engineering teams use Opal Security, the AI-native...  .... The Role We're hiring a Security Manager to own Opal's internal security program....  ...security operations, compliance posture, vendor risk, incident response, and security tooling... 
    Work at office

    Opal Security

    San Francisco, CA
    4 days ago
  •  ...Develop and implement an effective global security strategy and program to mitigate risk,...  ...operations. Responsible for the day to day management of all Physical Security software/...  ...BSC and security system and application vendors. Interface with monitoring staff on all... 
    Work experience placement
    Local area
    Remote work

    B Capital

    San Francisco, CA
    1 day ago
  •  ...employment Visa sponsorship. Corporate Security Specialist Department: Real Estate, Workplace...  ...To: Corporate Safety and Security Manager (located in Scottsdale, AZ) Position Summary...  ...coordinating onsite workplace services, vendors, and facility related activities.... 
    Temporary work
    For contractors
    Visa sponsorship
    Work visa

    PVH (Tommy Hilfiger/Calvin Klein)

    San Francisco, CA
    3 days ago
  •  ...You just "drive in and drive out." The San Francisco location is part of a large network across North America and Europe. As Security Manager, you will oversee the day-to-day security operations, manage staff, and ensure safety while maintaining professional client relations... 

    SP+

    San Francisco, CA
    4 days ago
  •  ...our GRC program, owning SOC 2/ISO audits, policy library, and vendor risk. You will lead the team, report to the General Counsel, and partner with Security, HR, Sales, and other leaders to embed risk management across the business. The role is based in San Francisco or... 

    Doist

    San Francisco, CA
    3 days ago
  • $99k - $232k

     ...SectorNot ApplicableSpecialismOracleManagement LevelManagerJob Description & SummaryThe OpportunityAs an Oracle Application Security & Controls Manager, you will engage with clients to optimize operational efficiency through specialized consulting services within our... 
    Full time
    H1b

    PwC

    San Francisco, CA
    14 hours ago
  • $200k - $225k

     ...SalaryJob Description Summary:The Director of Security and Compliance leads the design and...  ...RESPONSIBILITIES AND DUTIESRisk Management: Sets the mission, vision, and strategy...  ...up on trends and share lessons learned.Vendor & Third‑Party Management:Lead vendor management... 
    Full time
    Temporary work
    Flexible hours

    Swinerton

    San Francisco, CA
    3 days ago
  • $138k - $156k

     ...native company, and that only works if our security posture keeps pace. As the Security TPM,...  ...and delivery of Gusto's vulnerability management and security operations programs across...  ...detection and alerting across systems and vendors, impersonation and privileged-access... 
    Full time
    Work at office
    Local area
    2 days per week
    3 days per week

    Gusto

    San Francisco, CA
    1 day ago
  •  ...rare opportunity to build and lead the Security organization at one of healthcare's fastest...  ..., penetration testing, vulnerability management, and application security initiatives. Define...  ..., standards, and governance. Own vendor risk management and third-party security... 
    Full time
    Work at office
    Remote work
    Flexible hours
    2 days per week

    RXinsider

    San Francisco, CA
    3 days ago
  •  ...reimbursement journey. About the role We're hiring Pivotal's Head of Security, a senior leader who will own the company's security program...  ...) including control design, audit preparation, and ongoing management Comfortable representing security externally to customers,... 
    Remote work
    Flexible hours

    Pivotal Health

    San Francisco, CA
    4 days ago
  • $300 per month

     ...performing team that believes in each other, come build with us at Crusoe. About This Role: Crusoe is looking for a Strategic Category Manager responsible for building, owning, and executing a sourcing strategy for HR and People. You will manage the end-to-end procurement... 
    Contract work
    Temporary work

    Crusoe Energy Systems

    San Francisco, CA
    2 days ago
  •  ...company is scaling fast in one of the most sensitive, compliance-heavy sectors in tech. They're now looking to bring on a Head of Security to own the security function end-to-end, a foundational leadership hire with direct access to the executive team and the mandate to... 

    Frey Consulting Group

    San Francisco, CA
    2 days ago
  •  ...CTO of Facebook. Bret was also one of Google's earliest product managers and co-creator of Google Maps. Before founding Sierra, Clay...  ...inference and data platforms. Build a centralized and evolving security controls library mapped to compliance, regulatory and customer... 
    Full time
    Flexible hours

    Sierra

    San Francisco, CA
    4 days ago
  • $164k - $218k

     ...Director, Security Channels - North America As the Director of Security Channels you will drive incremental revenue for Datadog by building...  ...partner community. In this role, you will be responsible for managing Sr. Partner Managers & Principal Partner Managers (individual... 
    Work at office

    Datadog

    San Francisco, CA
    2 days ago
  • $100k - $110k

     ...Director of Security Four Seasons is powered by our people. We are a collective of individuals...  ...responsible for the implementation and management of the Residential Security operations,...  ...a rapport with all residents, various vendors, and fellow colleagues in other hotels &... 
    For contractors
    Local area
    Worldwide
    All shifts
    Night shift

    Four Seasons Hotels

    San Francisco, CA
    3 days ago
  •  ...Security Project Manager San Francisco, CA 24+ months Mandatory Qualifications: Over 5 years of experience managing multiple medium...  ...expectations are understood and met. Communicate with contracted vendors, trial court personnel, justice partners, and management... 
    Local area
    Remote work

    WATI

    San Francisco, CA
    1 day ago
  • $146.4k - $235.38k

     ...business and simplify people’s lives. With intelligent agreement management, Docusign unleashes business-critical data that is trapped...  ...management (CLM).What you'll doDocusign is looking for a Senior Security Risk Manager to join our Security Governance, Risk &... 
    Contract work
    Work at office
    Local area
    Remote work
    2 days per week

    DocuSign

    San Francisco, CA
    3 days ago
  • $134.5k - $265.1k

     ...ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate...  ...resilience, grow with confidence, and proactively manage to secure success. Recruiting for this role ends on 12/31/2026. Work you'... 
    Local area
    Visa sponsorship

    Deloitte

    San Francisco, CA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Vendor Security Manager. Be the first to apply!