Vendor Security Manager

Sierra Sierra · AI Frontier · San Francisco, CA · Compliance

Sierra is seeking a Vendor Security Manager to build and scale their vendor security program for their Conversational AI Platform. This role involves conducting technical assessments, developing AI-specific vendor risk frameworks, and managing security decisions for third-party relationships. The position requires technical depth, strong judgment, and the ability to operate in regulated industries. The manager will be responsible for program ownership, risk management, technical assessment of AI and model providers, supply chain monitoring, and building automation for detection and visibility. The role collaborates with various internal teams and external partners.

What you'd actually do

  1. Be the interface between Security and Sierra teams on everything vendor security related, drive risk conversations, and keep the program moving.
  2. Own vendor security risk decisions and escalation paths end-to-end, including clear documentation of risk acceptance rationale, mitigation plans, and trade-offs.
  3. Build and continuously improve the vendor security program methodology, tooling, risk tiering, monitoring, and response, scaling it intelligently as Sierra's vendor footprint grows.
  4. Assess and manage security risk across Sierra's full third-party landscape, recognizing that vendors, strategic partners, and contractors carry distinct risk profiles and require tailored oversight.
  5. Ensure the program meets audit and regulatory expectations across SOC 2, PCI DSS, FedRAMP, ISO 42001, ISO 27001, and emerging AI governance frameworks that hold up under enterprise customer and regulator scrutiny.

Skills

Required

  • Vendor security program management
  • Technical security assessments
  • Risk management
  • Framework development
  • AI vendor risk assessment
  • Supply chain security
  • Automation and alerting
  • SOC 2
  • PCI DSS
  • FedRAMP
  • ISO 42001
  • ISO 27001

Nice to have

  • Experience with AI/ML specific vendor risks
  • Experience with LLM and AI model vendors
  • Experience with prompt data handling, training data practices, inference infrastructure access, and model supply chain integrity
  • Experience with fourth parties and subprocessors
  • Experience with AI and tooling for documentation analysis

What the JD emphasized

  • build and scale Sierra's vendor security program from the ground up
  • developing frameworks purpose-built for AI vendor risk
  • deep technical assessments
  • strong judgment
  • regulated industries
  • AI and model vendors
  • emerging AI governance frameworks