The opportunity
OpenAI's Vendor Security team helps internal teams work securely with external products, services, and partners. Our work spans software, infrastructure, hardware, professional and managed services, vendor-provided workforces, data, and research.
What you'll do
Own vendor security engagements from understanding the business need through: scoping, assessment, decision, treatment, and reassessment when material facts change. Make assessment decisions independently and use judgment about when to involve peers, specialists, or leadership. Route formal exceptions and risk acceptance to the appropriate decision owners.
Understand vendor use cases, workflows, user journeys, data flows,: identities, access, integrations, and supply-chain dependencies. Identify plausible attack paths and their consequences for OpenAI.
Assess relevant architectures, configurations, controls, logs, and: operational practices. Test whether the evidence supports the security claims that matter to the engagement, and make gaps and uncertainty clear.
Develop practical treatments, including changes to the operating model, data: exposure, access, architecture, vendor choice, controls, or containment. Drive implementation with the responsible owners and verify that the treatment works.
Build reusable security patterns with clear applicability, safeguards,: evidence requirements, exceptions, and review triggers.
Work with Legal, Procurement, and vendors on security addenda. Evaluate: proposed terms and deviations against the engagement, explain their security implications, and develop workable positions with the appropriate decision owners. Legal leads wording and negotiation.
What they're looking for
- Learn from internal customers, agree priorities with the Vendor Security: lead, and define the requirements, roadmap, and success measures for the bounded programs, products, and services you own.
- Use Codex or comparable AI-assisted tools to build, inspect, test, and: maintain practical improvements to scoping, evidence checks, routing, decision reuse, or treatment tracking. Investigate failures and own the result through adoption, continued operation, and explicit handoff or retirement.
- Lead delivery across Security and partner teams. Translate goals into: technical requirements, milestones, and delivery plans; influence implementation choices; identify systemic risks; resolve dependencies and disagreements; and carry commitments through completion.
- Use casework, incidents, threat information, and customer feedback to improve: decisions and the program. As priorities change, recommend what to do next and explain the tradeoffs and effects on existing commitments.