Sr Vendor Security Compliance Program Manager

Uber Uber · Consumer · New York, NY +1 · Community Operations

This role focuses on managing vendor security compliance within Uber's global vendor network. It involves overseeing identity and access management, policy development and exception handling, incident management, and providing advisory support for technology solutions. A key responsibility is partnering to build and manage an AI Governance program for business process outsourcing (BPO) vendors and contributing to risk management initiatives like vendor scorecards. The role also includes audit and compliance oversight, driving automation, and collaborating with internal security, compliance, and legal teams to ensure alignment with evolving regulatory requirements and internal security policies. The ideal candidate will have a strong understanding of security and compliance governance, data analysis, risk assessment, and cross-functional collaboration skills.

What you'd actually do

  1. Lead the building of a BPO Security policy program, including development and governance ensuring alignment with evolving regulatory and business requirements as well as internal security policies.
  2. Partner with the Head of Vendor Security Compliance to build and manage and AI Governance program across the BPO universe
  3. Oversee and contribute to Risk Management initiatives such as the risk register, and a Vendor Security Scorecard
  4. Oversee virtual and physical site audits, vendor self-audits, and compliance reviews (e.g., IP allowlisting, OneLogin, MFA/VDI access, active site rosters, and insurance compliance).
  5. Drive automation initiatives to increase efficiency across all Vendor Security Compliance programs.

Skills

Required

  • security and compliance governance
  • data analysis
  • risk assessment
  • reporting
  • cross-functional collaboration
  • presentation skills
  • documentation skills
  • storytelling skills
  • 7+ years of experience in security, compliance, or risk management
  • 1+ years of people management experience
  • 5+ years of experience in security compliance, risk frameworks, and regulatory requirements

Nice to have

  • CRISC
  • CISM
  • CISA
  • navigating complex matrixed environments
  • translating security data into business-impacting insights
  • Self-motivated problem-solving mindset with the resilience to challenge established processes

What the JD emphasized

  • AI Governance
  • Vendor Security Scorecard
  • security and compliance governance
  • data analysis, risk assessment, and reporting
  • security, compliance, and technology teams