Vendor Security Manager

Sierra Technologies Inc

San Francisco, CA

JOB DETAILS
SKILLS
Accounts Receivable, Aging Analysis, Alliance/Partner Marketing, Amazon Web Services (AWS), Analysis Skills, Application Programming Interface (API), Artificial Intelligence (AI), Automation, CISA - Certified Information Systems Auditor, CISSP - Certified Information Systems Security Professional, Cloud Computing, Communication Skills, Compensation and Benefits, Computer Security, Continuous Improvement, Contract Requirements, Cryptography, Customer Experience, Diversity, Documentation, Facebook, Finance, Financial Services, GCP (Good Clinical Practices), Google Maps, Government, Healthcare, Home Automation, ISO (International Organization for Standardization), Information/Data Security (InfoSec), Leadership, Legal, Machine Tool, Open Source, PCI-DSS, Product Design, Programming Methodologies, Purchasing/Procurement, Regulations, Reporting Dashboards, Risk, Risk Analysis, Risk Management, Salesforce.com, Scripting (Scripting Languages), Security Analysis, Security Monitoring, Slack, Software as a Service (SaaS), Supply Chain, Technical Analysis, U.S. National Institute of Standards and Technology (NIST), Vendor/Supplier Evaluation, Vendor/Supplier Planning
LOCATION
San Francisco, CA
POSTED
1 day ago

About us

  • At Sierra, we're creating a platform to help businesses build better, more human customer experiences with AI. We are primarily an in-person company based in San Francisco, with growing offices in Atlanta, New York, London, Paris, Madrid, Munich, Singapore, Japan, and Sydney.

  • We are guided by a set of values that are at the core of our actions and define our culture: Trust, Customer Obsession, Craftsmanship, Intensity, and Family. These values are the foundation of our work, and we are committed to upholding them in everything we do.

  • Our co-founders are Bret Taylor and Clay Bavor. Bret currently serves as Board Chair of OpenAI. Previously, he was co-CEO of Salesforce (which had acquired the company he founded, Quip) and CTO of Facebook. Bret was also one of Googles earliest product managers and co-creator of Google Maps. Before founding Sierra, Clay spent 18 years at Google, where he most recently led Google Labs. Earlier, he started and led Google's AR/VR effort, Project Starline, and Google Lens. Before that, Clay led the product and design teams for Google Workspace.

The Role

Were looking for a Vendor Security Manager to join Sierras Security team. The security of our Conversational AI Platform depends on the security of everything connected to it, the vendors, model providers, infrastructure partners, and supply chain dependencies that enable how Sierra operates and scales.

Youll build and scale Sierras vendor security program from the ground up, conducting deep technical assessments, developing frameworks purpose-built for AI vendor risk, and driving security decisions across all of Sierras third-party security relationships. This is a hands-on role that requires both technical depth and strong judgment. You'll help Sierra make informed trade-offs between speed, scale, and security in a business that moves fast and operates in regulated industries.

We value people who are energized by uncertainty and who can form a credible point of view even with incomplete information and can get more rigorous as the situation sharpens.

What Youll Do

Program Ownership & Security Risk Management

Be the interface between Security and Sierra teams on everything vendor security related, drive risk conversations, and keep the program moving.

Own vendor security risk decisions and escalation paths end-to-end, including clear documentation of risk acceptance rationale, mitigation plans, and trade-offs.

Build and continuously improve the vendor security program methodology, tooling, risk tiering, monitoring, and response, scaling it intelligently as Sierras vendor footprint grows.

Assess and manage security risk across Sierras full third-party landscape, recognizing that vendors, strategic partners, and contractors carry distinct risk profiles and require tailored oversight. A technology partner with deep API integration is a different security conversation than a SaaS tool or a contractor with scoped environment access - the program you build should reflect that.

Ensure the program meets audit and regulatory expectations across SOC 2, PCI DSS, FedRAMP, ISO 42001, ISO 27001, and emerging AI governance frameworks that hold up under enterprise customer and regulator scrutiny.

Technical Assessment & Supply Chain

Conduct deep, evidence-based security assessments across Sierras vendor landscape SaaS providers, cloud and infrastructure partners, AI and model providers, and strategic suppliers including reviewing architectures, IAM configurations, access scopes, and vulnerability assessments.

Develop assessment frameworks for AI and model vendors that address risks specific to how these systems actually work including prompt data handling, training data practices, inference infrastructure access, and model supply chain integrity.

Develop and maintain a model provider oversight program that reflects Sierras reality of working across a constellation of LLM and AI model vendors. That means understanding each providers data handling commitments, inference infrastructure security, model update and versioning practices, and what contractual and technical controls govern how Sierras data moves through each. When a model provider changes terms, updates a model, or discloses a security issue, youre the person who understands what it means for Sierra and what to do about it.

Map and monitor Sierras full supply chain surface, including fourth parties and subprocessors, with visibility into software dependencies, open source components, and AI model provenance.

Think in blast radius. Understand whats reachable if theyre compromised data flows, network adjacency, privilege scope, lateral movement paths and let that analysis drive technical controls and contractual requirements.

Automation & Visibility

Build detection logic and automated alerting that fires when a vendors security posture degrades lapsed certifications, exposed services, configuration drift, or new vulnerability disclosures so Sierras response is proactive.

Automate evidence collection and control validation across the vendor portfolio, reducing the manual overhead of assessment cycles and creating an audit trail that holds up under scrutiny.

Build integrations between vendor security tooling and Sierras internal systems, procurement workflows and Slack alerting so risk signals reach the right people quickly and efficiently.

Use AI and tooling to analyze vendor documentation at scale and surface risk signals early and continuously. Develop dashboards and reporting that give leadership real visibility into vendor risk posture, remediation velocity, assessment coverage, and aging findings.

Who Youll Work With

You'll work with Platform Engineering, Security Engineering, Legal, Operations and Finance teams to understand IAM boundaries, model provider's API access and infrastructure scaling.

Youll partner on understanding what vendors actually have access to, how third-party components sit inside Sierras architecture, and how supply chain security gets built into how Sierra ships.

What Youll Bring

  • 10 or more years in information security with real depth in vendor security, third-party risk, or GRC in a regulated environment financial services, healthcare, government, or enterprise SaaS. Youve made consequential risk decisions under pressure and know what it means to be accountable for them.

  • Technical fluency in cloud security, AWS and GCP IAM, VPC architecture, encryption, logging and monitoring, shared responsibility models at a level where you can assess what a vendors architecture actually means for Sierras exposure, not just whether their controls list maps to a framework.

  • Deep working knowledge of ISO 27001, NIST 800-53, SOC 2, PCI DSS, and FedRAMP as they apply to third-party oversight. You understand what auditors are actually looking for and build programs that hold up because theyre rigorous, not just well-documented.

  • Experience building automations, integrations, or detection logic whether through GRC tooling, APIs, or scripting that reduce manual work and surface risk signals faster. You think about scale from the start.

  • Genuine curiosity about AI security model supply chains, prompt data handling, adversarial ML, and the governance frameworks being built around AI systems. You dont need to have all the answers, but this space should excite you.

  • The ability to communicate complex risk clearly to engineers, and auditors without losing precision or confidence. Your assessments and risk decisions need to be technically sound and immediately legible to people with very different backgrounds.

  • Comfort operating in ambiguity and fast-moving environments where the challenges are new, the regulatory frameworks are still forming, and learning on the job is part of the work.

Even Better

  • Youve built a vendor security program from scratch and know what youd do differently.

  • You have experience with AI or ML vendors and a developing point of view on what good looks like.

  • Youre familiar with software supply chain security, SBOM and dependency integrity.

  • Youve built or led implementation of GRC, TPRM, supply chain security tooling.

  • You hold a CISSP, CISA or have led ISO 27001, PCI DSS or other compliance programs in the past.

Our values

  • Trust: We build trust with our customers with our accountability, empathy, quality, and responsiveness. We build trust in AI by making it more accessible, safe, and useful. We build trust with each other by showing up for each other professionally and personally, creating an environment that enables all of us to do our best work.

  • Customer Obsession: We deeply understand our customers' business goals and relentlessly focus on driving outcomes, not just technical milestones. Everyone at the company knows and spends time with our customers. When our customer is having an issue, we drop everything and fix it.

  • Craftsmanship: We get the details right, from the words on the page to the system architecture. We have good taste. When we notice something isn't right, we take the time to fix it. We are proud of the products we produce. We continuously self-reflect to continuously self-improve.

  • Intensity: We know we don't have the luxury of patience. We play to win. We care about our product being the best, and when it isn't, we fix it. When we fail, we talk about it openly and without blame so we succeed the next time.

  • Family: We know that balance and intensity are compatible, and we model it in our actions and processes. We are the best technology company for parents. We support and respect each other and celebrate each other's personal and professional achievements.

What we offer

We want our benefits to reflect our values and offer the following to full-time employees:

  • Flexible (unlimited) paid time off

  • Medical, dental, and vision benefits for you and your family

  • Life insurance and disability benefits

  • Retirement plan dependent on country of employment

  • Parental leave

  • Fertility and family building benefits through Carrot

  • Lunch, as well as delicious snacks and coffee to keep you energized

  • Discretionary benefit stipend giving people the ability to spend where it matters most

  • Free alphorn lessons

These benefits are further detailed in Sierras policies, may vary by region, and are subject to change at any time, consistent with the terms of any applicable compensation or benefits plans. Eligible full-time employees can participate in Sierras equity plans subject to the terms of the applicable plans and policies.

Be you, with us

Were working to bring the transformative power of AI to every organization in the world. To do so, it is important to us that the diversity of our employees represents the diversity of our customers. We believe that our work and culture are better when we encourage, support, and respect different skills and experiences represented within our team. We encourage you to apply even if your experience doesnt precisely match the job description. We strive to evaluate all applicants consistently without regard to race, color, religion, gender, national origin, age, disability, veteran status, pregnancy, gender expression or identity, sexual orientation, citizenship, or any other legally protected class.

About the Company

S

Sierra Technologies Inc