Vendor Security Manager
Sierra
The Role We're looking for a Vendor Security Manager to join Sierra's Security team. The security of our Conversational AI Platform depends on the security of everything connected to it, the vendors, model providers, infrastructure partners, and supply chain dependencies that enable how Sierra operates and scales. You’ll build and scale Sierra's vendor security program from the ground up, conducting deep technical assessments, developing frameworks purpose-built for AI vendor risk, and driving security decisions across all of Sierra's third‑party security relationships. This is a hands‑on role that requires both technical depth and strong judgment. You’ll help Sierra make informed trade‑offs between speed, scale, and security in a business that moves fast and operates in regulated industries. We value people who are energized by uncertainty and who can form a credible point of view even with incomplete information and can get more rigorous as the situation sharpens. What You’ll Do Program Ownership & Security Risk Management Be the interface between Security and Sierra teams on everything vendor security related, drive risk conversations, and keep the program moving. Own vendor security risk decisions and escalation paths end-to-end, including clear documentation of risk acceptance rationale, mitigation plans, and trade‑offs. Build and continuously improve the vendor security program methodology, tooling, risk tiering, monitoring, and response, scaling it intelligently as Sierra's vendor footprint grows. Assess and manage security risk across Sierra's full third‑party landscape, recognizing that vendors, strategic partners, and contractors carry distinct risk profiles and require tailored oversight. A technology partner with deep API integration is a different security conversation than a SaaS tool or a contractor with scoped environment access — the program you build should reflect that. Ensure the program meets audit and regulatory expectations across SOC 2, PCI DSS, FedRAMP, ISO 42001, ISO 27001, and emerging AI governance frameworks that hold up under enterprise customer and regulator scrutiny. Technical Assessment & Supply Chain Conduct deep, evidence‑based security assessments across Sierra's vendor landscape SaaS providers, cloud and infrastructure partners, AI and model vendors, and strategic suppliers including reviewing architectures, IAM configurations, access scopes, and vulnerability assessments. Develop assessment frameworks for AI and model vendors that address risks specific to how these systems actually work including prompt data handling, training data practices, inference infrastructure access, and model supply chain integrity. Develop and maintain a model provider oversight program that reflects Sierra's reality of working across a constellation of LLM and AI model vendors. That means understanding each provider's data handling commitments, inference infrastructure security, model update and versioning practices, and what contractual and technical controls govern how Sierra's data moves through each. When a model provider changes terms, updates a model, or discloses a security issue, you're the person who understands what it means for Sierra and what to do about it. Map and monitor Sierra's full supply chain surface, including fourth parties and subprocessors, with visibility into software dependencies, open source components, and AI model provenance. Think in blast radius. Understand what's reachable if they're compromised data flows, network adjacency, privilege scope, lateral movement paths and let that analysis drive technical controls and contractual requirements. Automation & Visibility Build detection logic and automated alerting that fires when a vendor's security posture degrades lapsed certifications, exposed services, configuration drift, or new vulnerability disclosures so Sierra's response is proactive. Automate evidence collection and control validation across the vendor portfolio, reducing the manual overhead of assessment cycles and creating an audit trail that holds up under scrutiny. Build integrations between vendor security tooling and Sierra's internal systems, procurement workflows and Slack alerting so risk signals reach the right people quickly and efficiently. Use AI and tooling to analyze vendor documentation at scale and surface risk signals early and continuously. Develop dashboards and reporting that give leadership real visibility into vendor risk posture, remediation velocity, assessment coverage, and aging findings. Who You’ll Work With You’ll work with Platform Engineering, Security Engineering, Legal, Operations and Finance teams to understand IAM boundaries, model provider’s API access and infrastructure scaling. You'll partner on understanding what vendors actually have access to, how third‑party components sit inside Sierra's architecture, and how supply chain security gets built into how Sierra ships. What You’ll Bring 10 or more years in information security with real depth in vendor security, third‑party risk, or GRC in a regulated environment financial services, healthcare, government, or enterprise SaaS. You've made consequential risk decisions under pressure and know what it means to be accountable for them. Technical fluency in cloud security, AWS and GCP IAM, VPC architecture, encryption, logging and monitoring, shared responsibility models at a level where you can assess what a vendor's architecture actually means for Sierra's exposure, not just whether their controls list maps to a framework. Deep working knowledge of ISO 27001, NIST 800-53, SOC 2, PCI DSS, and FedRAMP as they apply to third‑party oversight. You understand what auditors are actually looking for and build programs that hold up because they're rigorous, not just well‑documented. Experience building automations, integrations, or detection logic whether through GRC tooling, APIs, or scripting that reduce manual work and surface risk signals faster. You think about scale from the start. Genuine curiosity about AI security model supply chains, prompt data handling, adversarial ML, and the governance frameworks being built around AI systems. You don't need to have all the answers, but this space should excite you. The ability to communicate complex risk clearly to engineers, and auditors without losing precision or confidence. Your assessments and risk decisions need to be technically sound and immediately legible to people with very different backgrounds. Comfort operating in ambiguity and fast‑moving environments where the challenges are new, the regulatory frameworks are still forming, and learning on the job is part of the work. Even Better You've built a vendor security program from scratch and know what you'd do differently. You have experience with AI or ML vendors and a developing point of view on what good looks like. You're familiar with software supply chain security, SBOM and dependency integrity. You've built or led implementation of GRC, TPRM, supply chain security tooling. You hold a CISSP, CISA or have led ISO 27001, PCI DSS or other compliance programs in the past. What we offer Flexible (unlimited) paid time off Medical, dental, and vision benefits for you and your family Life insurance and disability benefits Retirement plan dependent on country of employment Parental leave Fertility and family building benefits through Carrot Lunch, as well as delicious snacks and coffee to keep you energized Discretionary benefit stipend giving people the ability to spend where it matters most Free alphorn lessons These benefits are further detailed in Sierra's policies, may vary by region, and are subject to change at any time, consistent with the terms of any applicable compensation or benefits plans. Eligible full‑time employees can participate in Sierra's equity plans subject to the terms of the applicable plans and policies. Be you, with us We're working to bring the transformative power of AI to every organization in the world. To do so, it is important to us that the diversity of our employees represents the diversity of our customers. We believe that our work and culture are better when we encourage, support, and respect different skills and experiences represented within our team. We encourage you to apply even if your experience doesn't precisely match the job description. We strive to evaluate all applicants consistently without regard to race, color, religion, gender, national origin, age, disability, veteran status, pregnancy, gender expression or identity, sexual orientation, citizenship, or any other legally protected class. #J-18808-Ljbffr Sierra
- ...Vendor Manager - IT Work Type: Hybrid This position is hybrid, working from your remote office and your assigned work location based on business need. Job Level: Individual Contributor The IT Vendor Manager, Expert will report directly to Director Position Summary The...SuggestedContract workWork at officeLocal areaRemote work
- ...exceptional customer experiences. About the Role We are hiring a Global Vendor Manager to build and scale the vendor operating model that powers our... ...public information. In addition, job duties require access to secure and protected information technology systems and related data...SuggestedWork at officeRelocation package
- ...Job Description Job Description Vendor Performance Manager Duties: Performance Management & Reporting KPI & SLA Oversight: Own the... ...vendors strictly comply with all contractual agreements, security requirements, and policy updates. Risk Mitigation: Proactively...SuggestedContract workTemporary work
$159k - $196k
...and operations platform. From component sourcing to end customer management, we enable and create value for Waymo through scaled and... ...the primary escalation lead by driving end-to-end resolution of vendor issues, utilizing a centralized tracker to identify root causes...SuggestedPermanent employmentFull timeRemote work$114k
...opportunity to accelerate the outcomes of our True North Strategy and deliver for our customers. Position Summary The IT Vendor Manager, Expert will play a pivotal role in PG&E’s Propel program, overseeing the lifecycle of multiple strategic 3rd party contracts....SuggestedContract workWork at officeLocal areaRemote work- ...Role Telnyx operates a global private network spanning datacenters and colocation facilities across dozens of markets. The Vendor Relations team manages the infrastructure vendor relationships that make this possible. We're looking for a Vendor Relations Associate to...Contract workInternship
$132k
...Requisition ID # 165270 Job Category: Legal Job Level: Manager/Principal Business Unit: Engineering, Planning & Strategy... ...and deliver for our customers. Position Summary The IT Vendor Manager, Principal will play a pivotal role in PG&E’s Propel program...Contract workWork at officeRemote work$190k - $270k
About the Role As an AI Infrastructure Engineer at Together, you are responsible for keeping all user-facing services and production systems running smoothly. You are a blend of a pragmatic operator and a software engineer that applies sound engineering principles, operational...Full timeWork experience placement- ...leading technology company located in San Francisco is seeking a passionate Vendor Relations Associate. This role focuses on supporting the Vendor Relations team, involving vendor record management, onboarding coordination, and assisting with RFQ processes. Ideal...
- ...Sedaa Corporation is seeking a Vendor Manager – IT in San Francisco. This critical position combines hybrid work with responsibilities in managing vendor relationships and compliance issues on complex contracts. The ideal candidate will ensure adherence to contract terms...Contract work
- ...About the Team The Corporate Security team is responsible for safeguarding all OpenAI employees... ...work without risk or disruption. We manage physical security operations across offices... ...and adaptive security posture, manage vendor security teams, and serve as a key liaison...Work at officeLocal area
$172.1k - $238.3k
...Upstart is seeking a Senior Manager in Vendor Management to lead the vendor oversight function for secured lending. The role demands significant experience in third-party risk management and vendor oversight in financial services. This position requires collaboration...Remote work- ...PwC South Africa is looking for a Manager to lead Workday security assessments and implementations. Responsibilities include supervising a team, managing client service accounts, and ensuring compliance with risk and control standards. The ideal candidate holds a Bachelor...
$144k - $162k
Legal Vendor Program Manager Discord is looking for a Legal Vendor Program Manager to join our growing legal team. In this role, you will own... ...including collaborating with internal teams on conflict and security review and troubleshooting setup and access issues Develop,...Full timeContract workWork at office2 days per week$165k - $175k
...passionate about intelligence, risk analysis, threat management, executive protection, security operations, or business resiliency, Concentric may be... ...expectations. This position will manage several small groups of vendors, ad hoc services, or employees, and embedded services,...Contract workCurrently hiringLocal areaImmediate startRemote workRelocationOverseasVisa sponsorshipShift work$195k - $263k
...Director of Security & IT Operations San Francisco, CA The Role Pilot is looking for a Director of Security to establish a... ...controls (e.g., MFA, SSO, endpoint protection, identity & access management). Compliance and customer trust Ownership over...Full timeTemporary workPart timeFlexible hours$245k - $285k
A leading AI research organization is seeking a Vendor and Contract Manager to oversee vendor relationships, contract negotiations, and budget management. The role involves managing the entire lifecycle of vendor partnerships and requires expertise in vendor management...Contract work$245k - $285k
...together to build beneficial AI systems. About The Role As the Vendor and Contract Manager on the Safeguards team, you will own the end-to-end... ...evaluation. Conduct vendor due diligence and coordinate security and data governance reviews for vendors handling sensitive...Contract workWork at officeVisa sponsorshipFlexible hours$217k - $300k
...Flourish Ventures is seeking an Associate General Counsel in San Francisco to lead the Privacy & Security team. This role involves managing the privacy program in compliance with laws and advising on AI governance. The individual will work cross-functionally with various...- ...A leading fitness application company in San Francisco is looking for a Senior Technical Program Manager to oversee complex security programs. This role requires the ability to partner with various teams, ensuring clear communication and organized execution of security...3 days per week
$148k - $175k
...Alumni Ventures seeks a Senior Technical Program Manager to lead complex security programs at their San Francisco office. In this role, you will drive security initiatives across various departments, ensuring effective execution and communication. The ideal candidate...Work at office- ...CTO of Facebook. Bret was also one of Google’s earliest product managers and co‑creator of Google Maps. Before founding Sierra, Clay... ...a seasoned Customer Trust Enablement professional to join the Security Foundations and GRC team. This is a role for someone with 10+ years...Full timeContract workFlexible hours
$83.66k - $104.56k
...Meaningful and rewarding work Vi at Palo Alto is located at 620 Sand Hill Road, Palo Alto CA 94304 Responsibilities: Security and Safety Manager An opportunity exists on our highly accomplished resident services team to manage the security personnel. The selected...- ...CTO of Facebook. Bret was also one of Google's earliest product managers and co-creator of Google Maps. Before founding Sierra, Clay... ...inference and data platforms. Build a centralized and evolving security controls library mapped to compliance, regulatory and customer...Full timeFlexible hours
$140k - $180k
...Security Compliance Manager We are looking for a highly motivated Security Compliance Manager with a deep security and compliance background... ...compliance requirements, including both internal requirements for vendors as well as external requirements placed on Hive Report...- Autodesk is hiring a Manager of Security Incident Response Operations in San Francisco, CA. This role involves leading a talented team of security analysts to manage high-impact investigations and drive operational excellence in incident response. The candidate should have...
$182k - $295k
About the role Hex is looking for our first Security GRC Manager to build, scale, and own our security and privacy compliance programs. This... ...Management Own Hex’s third‑party risk management program, including vendor assessments, reviews, and ongoing monitoring. Build a...Flexible hours$80k - $83k
Hilton San Francisco Union Square and Parc 55 is looking for a Complex Security Manager. Located just two blocks from Union Square and Westfield San Francisco Centre. Our Hilton Union Square property is the largest in the Bay Area with 1,921 rooms, over 150,000 square...Local areaWorldwide- Crisis24, based in San Francisco, is looking for an Embedded Security Manager (ESM) to oversee Executive Protective Operations. In this role, you'll develop security strategies, create emergency response plans, and manage key performance indicators for security operations...
$1,000 per month
...Develop, maintain, and enforce information security policies, standards, and procedures... ...leadership and board-level visibility Risk Management Lead enterprise risk assessments,... ...ensure continuous compliance Third-Party & Vendor Risk Implement and manage third-party risk...Temporary workWork at officeImmediate startRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vendor Security Manager. Be the first to apply!
- category manager beauty San Francisco, CA
- category manager San Francisco, CA
- global category manager San Francisco, CA
- vendor manager San Francisco, CA
- category manager packaging San Francisco, CA
- security systems manager San Francisco, CA
- senior security manager San Francisco, CA
- security manager San Francisco, CA
- security engineering manager San Francisco, CA
- product security manager San Francisco, CA


