Senior Manager, Vendor Security

Adobe Adobe · Enterprise · San Jose, CA

This role leads a team responsible for vendor security assessments, risk management, and ensuring security requirements are integrated into contracts. It involves evaluating third-party security postures, identifying risks, and collaborating with various internal teams and external vendors.

What you'd actually do

  1. Lead a team of analysts and engineers to build, develop, and continually improve Adobe’s framework for managing security risks associated with vendors.
  2. Serve as the main interface between the Security team and the broader organization on matters related to vendors.
  3. Perform comprehensive, evidence-based security assessments of third parties, including evaluation of architectures, configurations, controls, and operational practices to validate vendors’ real-time security posture.
  4. Assess and manage security risks across a diverse vendor landscape, including SaaS providers, cloud and infrastructure partners, and other strategic or high-impact suppliers.
  5. Clearly communicate identified gaps and recommend solutions or compensating controls to business owners and various leadership stakeholders.

Skills

Required

  • Leadership
  • Vendor security assessment
  • Risk management
  • Security principles and controls
  • Data protection
  • Access management
  • Application security
  • Identity and access management
  • Technical and analytical skills
  • Risk assessment from external incidents and breaches
  • Compliance frameworks (SOC 2, ISO 27001, PCI DSS)

Nice to have

  • AI technologies integration

What the JD emphasized

  • Minimum 10 years of security experience with at least 3 years in a leadership role
  • Demonstrable ability to conduct third-party/vendor security assessments, including building and scaling vendor management programs.
  • Experience with compliance frameworks like SOC 2, ISO 27001, and PCI DSS.