Vendor Security Manager
Listed on 2026-06-07
-
IT/Tech
Cybersecurity, Data Security, Information Security
The Role
We're looking for a Vendor Security Manager to join Sierra's Security team. The security of our Conversational AI Platform depends on the security of everything connected to it, the vendors, model providers, infrastructure partners, and supply chain dependencies that enable how Sierra operates and scales.
You’ll build and scale Sierra's vendor security program from the ground up, conducting deep technical assessments, developing frameworks purpose-built for AI vendor risk, and driving security decisions across all of Sierra's third‑party security relationships. This is a hands‑on role that requires both technical depth and strong judgment. You’ll help Sierra make informed trade‑offs between speed, scale, and security in a business that moves fast and operates in regulated industries.
We value people who are energized by uncertainty and who can form a credible point of view even with incomplete information and can get more rigorous as the situation sharpens.
What You’ll Do Program Ownership & Security Risk ManagementBe the interface between Security and Sierra teams on everything vendor security related, drive risk conversations, and keep the program moving.
Own vendor security risk decisions and escalation paths end-to-end, including clear documentation of risk acceptance rationale, mitigation plans, and trade‑offs.
Build and continuously improve the vendor security program methodology, tooling, risk tiering, monitoring, and response, scaling it intelligently as Sierra's vendor footprint grows.
Assess and manage security risk across Sierra's full third‑party landscape, recognizing that vendors, strategic partners, and contractors carry distinct risk profiles and require tailored oversight. A technology partner with deep API integration is a different security conversation than a SaaS tool or a contractor with scoped environment access — the program you build should reflect that.
Ensure the program meets audit and regulatory expectations across SOC 2, PCI DSS, FedRAMP, ISO 42001, ISO 27001, and emerging AI governance frameworks that hold up under enterprise customer and regulator scrutiny.
Technical Assessment & Supply ChainConduct deep, evidence‑based security assessments across Sierra's vendor landscape SaaS providers, cloud and infrastructure partners, AI and model vendors, and strategic suppliers including reviewing architectures, IAM configurations, access scopes, and vulnerability assessments.
Develop assessment frameworks for AI and model vendors that address risks specific to how these systems actually work including prompt data handling, training data practices, inference infrastructure access, and model supply chain integrity.
Develop and maintain a model provider oversight program that reflects Sierra's reality of working across a constellation of LLM and AI model vendors. That means understanding each provider's data handling commitments, inference infrastructure security, model update and versioning practices, and what contractual and technical controls govern how Sierra's data moves through each. When a model provider changes terms, updates a model, or discloses a security issue, you're the person who understands what it means for Sierra and what to do about it.
Map and monitor Sierra's full supply chain surface, including fourth parties and subprocessors, with visibility into software dependencies, open source components, and AI model provenance.
Think in blast radius. Understand what's reachable if they're compromised data flows, network adjacency, privilege scope, lateral movement paths and let that analysis drive technical controls and contractual requirements.
Automation & VisibilityBuild detection logic and automated alerting that fires when a vendor's security posture degrades lapsed certifications, exposed services, configuration drift, or new vulnerability disclosures so Sierra's response is proactive.
Automate evidence collection and control validation across the vendor portfolio, reducing the manual overhead of assessment cycles and creating an audit trail that holds up under scrutiny.
Build integrations between vendor security tooling and Sierra's internal systems,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).