Vendor Security Analyst

Pinterest Pinterest · Consumer · Chicago, IL · Security

This role is for a Vendor Security Analyst at Pinterest. The primary responsibilities include performing vendor security assessments, maintaining and improving the vendor security program, and ensuring vendor security issues are identified and remediated. The role also involves acting as a Subject Matter Expert (SME) for high priority vendor security reviews, including those related to AI tooling, and supporting the broader Security Governance, Risk & Compliance program. While the company mentions AI as a partner and the role will review AI tooling, the core function of the role is security risk analysis and compliance, not AI/ML development.

What you'd actually do

  1. Perform vendor security assessments in order to minimize risk from third-party services
  2. Support the Vendor Security lead to Maintain and improve the vendor security program while working closely with Security, Legal, IT and other internal stakeholders
  3. Ensure vendor security issues are identified, communicated, and remediated to an acceptable level of risk
  4. Act as the SME for High Priority Vendor Security Reviews (e.g. AI related tooling)
  5. Interface with other teams and take a leadership role in driving vendor security initiatives

Skills

Required

  • 3+ years experience performing vendor security risk analysis for new and existing vendors
  • Experience supporting the design, management, and building of security programs and best practices
  • Familiarity with compliance frameworks (e.g. PCI, GDPR, SOC2, ISO27001, NIST CSF)
  • Good understanding of various security domains
  • Strong sense of ownership and comfortable with autonomy and ambiguity
  • Great communicator who is comfortable leading meetings and audit type interviews with vendors
  • Bachelor’s degree in a relevant field such as Computer Science, Engineering, or other cognitive function, or equivalent experience
  • thorough understanding of security concepts

Nice to have

  • coding experience

What the JD emphasized

  • thorough understanding of security concepts
  • AI related tooling