Talent.com
Sierra
Vendor Security ManagerSierra • San Francisco, CA, United States
Vendor Security Manager

Vendor Security Manager

Sierra • San Francisco, CA, United States
7 hours ago
Job type
  • Full-time
Job description

Vendor Security Manager

We're looking for a Vendor Security Manager to join Sierra's Security team. The security of our Conversational AI Platform depends on the security of everything connected to it, the vendors, model providers, infrastructure partners, and supply chain dependencies that enable how Sierra operates and scales.

You'll build and scale Sierra's vendor security program from the ground up, conducting deep technical assessments, developing frameworks purpose-built for AI vendor risk, and driving security decisions across all of Sierra's third-party security relationships. This is a hands-on role that requires both technical depth and strong judgment. You'll help Sierra make informed trade-offs between speed, scale, and security in a business that moves fast and operates in regulated industries.

We value people who are energized by uncertainty and who can form a credible point of view even with incomplete information and can get more rigorous as the situation sharpens.

Program Ownership & Security Risk Management

Be the interface between Security and Sierra teams on everything vendor security related, drive risk conversations, and keep the program moving.

Own vendor security risk decisions and escalation paths end-to-end, including clear documentation of risk acceptance rationale, mitigation plans, and trade-offs.

Build and continuously improve the vendor security program methodology, tooling, risk tiering, monitoring, and response, scaling it intelligently as Sierra's vendor footprint grows.

Assess and manage security risk across Sierra's full third-party landscape, recognizing that vendors, strategic partners, and contractors carry distinct risk profiles and require tailored oversight. A technology partner with deep API integration is a different security conversation than a SaaS tool or a contractor with scoped environment access the program you build should reflect that.

Ensure the program meets audit and regulatory expectations across SOC 2, PCI DSS, FedRAMP, ISO 42001, ISO 27001, and emerging AI governance frameworks that hold up under enterprise customer and regulator scrutiny.

Technical Assessment & Supply Chain

Conduct deep, evidence-based security assessments across Sierra's vendor landscape SaaS providers, cloud and infrastructure partners, AI and model providers, and strategic suppliers including reviewing architectures, IAM configurations, access scopes, and vulnerability assessments.

Develop assessment frameworks for AI and model vendors that address risks specific to how these systems actually work including prompt data handling, training data practices, inference infrastructure access, and model supply chain integrity.

Develop and maintain a model provider oversight program that reflects Sierra's reality of working across a constellation of LLM and AI model vendors. That means understanding each provider's data handling commitments, inference infrastructure security, model update and versioning practices, and what contractual and technical controls govern how Sierra's data moves through each. When a model provider changes terms, updates a model, or discloses a security issue, you're the person who understands what it means for Sierra and what to do about it.

Map and monitor Sierra's full supply chain surface, including fourth parties and subprocessors, with visibility into software dependencies, open source components, and AI model provenance.

Think in blast radius. Understand what's reachable if they're compromised data flows, network adjacency, privilege scope, lateral movement paths and let that analysis drive technical controls and contractual requirements.

Automation & Visibility

Build detection logic and automated alerting that fires when a vendor's security posture degrades lapsed certifications, exposed services, configuration drift, or new vulnerability disclosures so Sierra's response is proactive.

Automate evidence collection and control validation across the vendor portfolio, reducing the manual overhead of assessment cycles and creating an audit trail that holds up under scrutiny.

Build integrations between vendor security tooling and Sierra's internal systems, procurement workflows and Slack alerting so risk signals reach the right people quickly and efficiently.

Use AI and tooling to analyze vendor documentation at scale and surface risk signals early and continuously. Develop dashboards and reporting that give leadership real visibility into vendor risk posture, remediation velocity, assessment coverage, and aging findings.

Who You'll Work With

You'll work with Platform Engineering, Security Engineering, Legal, Operations and Finance teams to understand IAM boundaries, model provider's API access and infrastructure scaling.

You'll partner on understanding what vendors actually have access to, how third-party components sit inside Sierra's architecture, and how supply chain security gets built into how Sierra ships.

What You'll Bring

  • 10 or more years in information security with real depth in vendor security, third-party risk, or GRC in a regulated environment financial services, healthcare, government, or enterprise SaaS. You've made consequential risk decisions under pressure and know what it means to be accountable for them.

  • Technical fluency in cloud security, AWS and GCP IAM, VPC architecture, encryption, logging and monitoring, shared responsibility models at a level where you can assess what a vendor's architecture actually means for Sierra's exposure, not just whether their controls list maps to a framework.

  • Deep working knowledge of ISO 27001, NIST 800-53, SOC 2, PCI DSS, and FedRAMP as they apply to third-party oversight. You understand what auditors are actually looking for and build programs that hold up because they're rigorous, not just well-documented.

  • Experience building automations, integrations, or detection logic whether through GRC tooling, APIs, or scripting that reduce manual work and surface risk signals faster. You think about scale from the start.

  • Genuine curiosity about AI security model supply chains, prompt data handling, adversarial ML, and the governance frameworks being built around AI systems. You don't need to have all the answers, but this space should excite you.

  • The ability to communicate complex risk clearly to engineers, and auditors without losing precision or confidence. Your assessments and risk decisions need to be technically sound and immediately legible to people with very different backgrounds.

  • Comfort operating in ambiguity and fast-moving environments where the challenges are new, the regulatory frameworks are still forming, and learning on the job is part of the work.

Even Better

  • You've built a vendor security program from scratch and know what you'd do differently.

  • You have experience with AI or ML vendors and a developing point of view on what good looks like.

  • You're familiar with software supply chain security, SBOM and dependency integrity.

  • You've built or led implementation of GRC, TPRM, supply chain security tooling.

  • You hold a CISSP, CISA or have led ISO 27001, PCI DSS or other compliance programs in the past.

Our Values

  • Trust: We build trust with our customers with our accountability, empathy, quality, and responsiveness. We build trust in AI by making it more accessible, safe, and useful. We build trust with each other by showing up for each other professionally and personally, creating an environment that enables all of us to do our best work.

  • Customer Obsession: We deeply understand our customers' business goals and relentlessly focus on driving outcomes, not just technical milestones. Everyone at the company knows and spends time with our customers. When our customer is having an issue, we drop everything and fix it.

  • Craftsmanship: We get the details right, from the words on the page to the system architecture. We have good taste. When we notice something isn't right, we take the time to fix it. We are proud of the products we produce. We continuously self-reflect to continuously self-improve.

  • Intensity: We know we don't have the luxury of patience. We play to win. We care about our product being the best, and when it isn't, we fix it. When we fail, we talk about it openly and without blame so we succeed the next time.

  • Family: We know that balance and intensity are compatible, and we model it in our actions and processes. We are the best technology company for parents. We support and respect each other and celebrate each other's personal and professional achievements.

What We Offer

We want our benefits to reflect our values and offer the

Create a job alert for this search

Vendor Security Manager • San Francisco, CA, United States

Similar jobs

Security and Safety Manager - Onsite, San Francisco

BlackbirdSan Francisco, CA, United States
Full-time

Join the Team Redefining How the World Experiences Design.Hello, hey, g'day, mabuhay, kia ora, hallo, vtejte!.We know job hunting can be a little time consuming and you're probably keen to find out... Show more

 • Promoted

Software Security Engineering Manager, Secure Frameworks

AnthropicSan Francisco, CA, United States
Full-time

Software Security Engineering Manager, Secure Frameworks.San Francisco, CA | Seattle, WA.Anthropic's mission is to create reliable, interpretable, and steerable AI systems.We want AI to be safe and... Show more

 • Promoted

Manager, Enterprise Security

TuroSan Francisco, CA, United States
Full-time

Turo is searching for a highly motivated and strategic Manager, Enterprise Security to lead and mentor a team of Security Engineers in securing enterprise systems and data through the definition, e... Show more

 • Promoted

Senior Security Architect

TradeJobsWorkForce94706 Albany, CA, US
Full-time

Senior Security Architect Job Duties: Enhances security team accomplishments and competence by planning deliver... Show more

 • Promoted

Director, National Security-Trade Controls

Alvarez & MarsalSan Francisco, CA, United States
Part-time

National Security Risk Analyst.Alvarez & Marsal (A&M) is a global consulting firm with over 10,000 entrepreneurial, action and results-oriented professionals in over 40 countries.We take a hands-on... Show more

 • Promoted

Security Project Manager

WATISan Francisco, CA, United States
Full-time

Over 5 years of experience managing multiple medium to large complex projects.Demonstrated experience in developing project approach, plans and schedules.Proven track record in leading, organizing,... Show more

 • Promoted

Staff Product Manager - Security

LambdaSan Francisco, CA, United States
Full-time

Lambda, The Superintelligence Cloud, is a leader in AI cloud infrastructure serving tens of thousands of customers.Our customers range from AI researchers to enterprises and hyperscalers.Lambda's m... Show more

 • Promoted

Director of Global Security

VerkadaSan Mateo, CA, United States
Full-time

Verkada is transforming how organizations protect their people and places with an integrated, privacy-sensitive AI-powered platform that includes solutions for video security, access control, air q... Show more

 • Promoted

Sr. Product Manager (Device Security)

Palo Alto NetworksSan Francisco, CA, United States
Full-time

At Palo Alto Networks, we're united by a shared missionto protect our digital way of life.We thrive at the intersection of innovation and impact, solving real-world problems with cutting-edge techn... Show more

 • Promoted

Senior Director, Security Engineering

RippleSan Francisco, CA, United States
Full-time

For positions that will be based in CA, the annual salary range for this position is below.Actual salaries may vary based on numerous factors including, among other things, an individual applicant'... Show more

 • Promoted

Engineering Manager, Anti-Abuse & Security

ReplitSan Mateo, CA, United States
Full-time

Engineering Manager, Anti-Abuse Team.Replit is the agentic software creation platform that enables anyone to build applications using natural language.With millions of users worldwide, Replit is de... Show more

 • Promoted

Director, Ecosystem Product Security

Stellar Development FoundationSan Francisco, CA, United States
Full-time

Director, Ecosystem & Product Security.Interested in working on cutting-edge blockchain technology and creating equitable access to the global financial system? Since 2014, the mission-driven team ... Show more

 • Promoted

Security Manager

Rodbat ManagementSan Mateo, CA, United States
Full-time

Security Account ManagerRMI International, Inc.RMI) is a leading-edge security organization, committed to providing the consistent quality security officer and related services utilized by a wide r... Show more

 • Promoted

Director, Corporate Security

ZooxSan Mateo, CA, United States
Full-time

The Director, Corporate Security is a leadership role responsible for the development and implementation of physical security programs to help the company keep all Zoox personnel and property safe ... Show more

 • Promoted

Infrastructure Vendor Manager

falSan Francisco, CA, United States
Full-time

Fal Generative Media Ecosystem.Fal is the generative media ecosystem powering the next generation of AI products.We build the infrastructure, tools, and model access that teams need to move from id... Show more

 • Promoted

Senior Technical Program Manager II, Security

StravaSan Francisco, CA, United States
Full-time

Senior Technical Program Manager.We are seeking a Senior Technical Program Manager to lead complex, high-priority security programs that span Engineering, Infrastructure Product, Legal, Operations,... Show more

 • Promoted

Director, Physical Security

VaxcyteSan Carlos, CA, United States
Full-time

Join our Mission to Protect Humankind!.Vaxcyte is a clinical-stage vaccine innovation company engineering high-fidelity vaccines to protect humankind from the consequences of bacterial diseases, wh... Show more

 • Promoted • New!

Engineering Manager, Agent & Product Security

AnysphereSan Francisco, CA, United States
Full-time

Engineering Manager, Agent & Product Security.Our mission is to automate coding.The first step in our journey is to build the best tool for professional programmers, using a combination of inventiv... Show more

 • Promoted

Security Technical Program Manager

GustoSan Francisco, CA, United States
Full-time

Security Technical Program Manager.At Gusto, we're on a mission to grow the small business economy.We handle the hard stuff payroll, health insurance, 401(k)s, and HR so owners can focus on their... Show more

 • Promoted • New!

Business Program Manager (Cyber Security)

Netpace IncSan Mateo, CA, United States
Full-time

Business Program Manager (Cyber Security / Infra).Location = Foster City, CA Duration: long term contract.Our client is looking for a strong Business Program Manager with expertise in Infrastructur... Show more