How to apply for Vendor Security Technical Program Manager

OpenAI

About OpenAI

OpenAI is a frontier AI research and product company with teams working on alignment, policy, and security. It posts specific opportunities it thinks may be high impact, and it does not necessarily recommend working at other positions at OpenAI. Candidates should also read the 80,000 Hours career review on working at an AI lab to weigh concerns about doing harm.

About the role

This is an individual-contributor role on OpenAI's Vendor Security team, which helps internal teams work securely with external products, services, partners, and vendor-provided workforces. You will independently lead vendor-security engagements: understand the business need, investigate the actual data and access, recommend a practical path, and work with owners until safeguards are verified. You will also turn recurring vendor-security problems into bounded tools and workflows, with priorities agreed with the Vendor Security lead.

A typical day

A typical day may include scoping a new vendor engagement, investigating the actual data and access involved, and recommending a practical path to the responsible owner. You may also work on a bounded tool or workflow that addresses a recurring vendor-security problem, with priorities agreed with the Vendor Security lead. The posting does not describe a fixed daily routine, so ask the hiring team how work is scheduled and how priorities are set.

Who OpenAI is looking for

  • Can make sound security decisions independently and take a position, explain the tradeoff, and change their mind when the evidence changes.
  • Has technical judgment across software, infrastructure, hardware, professional and managed services, vendor-provided workforces, data, and research.
  • Can run engagements end to end: scoping, assessment, decision, treatment, and verification with responsible owners.
  • Can build and improve bounded tools and workflows from recurring vendor-security problems, rather than only doing one-off reviews.

Tips for this application

  • Map your experience directly to the engagement lifecycle in the job description: business need, scoping, assessment, decision, treatment, and verification. Give one concrete example per stage if you can.
  • Show you can work with vendor-provided workforces and external partners, not just software vendors. The team's scope includes hardware, professional and managed services, data, and research.
  • Give an example where you turned a recurring vendor-security problem into a tool or workflow. State the priority-setting process and who agreed to it.
  • Demonstrate independent judgment: describe a time you took a security position, explained the tradeoff, and changed your mind when new evidence arrived.
  • Because this is a remote US role and an individual-contributor role, show how you deliver without direct authority and how you keep owners accountable until safeguards are verified.

What to cover in your cover letter

['One end-to-end vendor-security engagement you led: the business need, the data and access you investigated, the path you recommended, and how you verified the safeguards.', 'A recurring vendor-security problem you converted into a bounded tool or workflow, including how priorities were agreed with a lead or stakeholder.', 'Your technical judgment across the scope areas in the job description: software, infrastructure, hardware, professional and managed services, vendor-provided workforces, data, and research.', 'Why you want to work on vendor security at a frontier AI research and product company, and how you have weighed the concerns in the 80,000 Hours career review.']

Draft a cover letter

Research before applying

  • Read OpenAI's published work on alignment, policy, and security to understand how the Vendor Security team fits into the company.
  • Read the 80,000 Hours career review on working at an AI lab, which the job posting links to, so you can speak honestly about the concerns.
  • Look at OpenAI's product and research surface area to understand what kinds of vendors, data, and access the team likely handles.
  • Check OpenAI's current vendor or security-related public statements, if any, to see how the company describes its approach to external partners.
OpenAI website

Likely interview topics

Based on the job description, expect questions about:

  • Walk through a vendor-security engagement you owned from business need through verified safeguards. What did you investigate, recommend, and verify?
  • Tell us about a time you took a security position, explained the tradeoff, and later changed your mind because the evidence changed.
  • How would you assess risk for a vendor that provides a workforce, not just software? What data and access questions matter first?
  • Describe a recurring vendor-security problem you turned into a tool or workflow. How did you set priorities with the Vendor Security lead?
  • How do you work with responsible owners to confirm safeguards are in place when you have no direct authority over them?
Practise interview questions

Common mistakes to avoid

  • Treating this as a generic security program manager role. The posting stresses independent leadership of engagements and building bounded tools, not just running a checklist.
  • Ignoring the scope beyond software. The team covers infrastructure, hardware, professional and managed services, vendor-provided workforces, data, and research.
  • Skipping the concerns about working at a frontier AI company. The posting links to the 80,000 Hours career review, so candidates should be ready to discuss it.

Deadline

No deadline is listed. Roles without a deadline usually close once the employer has enough candidates, so apply soon if you are interested.