← All jobs · Sierra

Vendor Security Manager

Sierra ·
32
AI-Agency
B25 U45
📍 San Francisco, US Senior
SOC 2PCI DSSFedRAMPISO 27001ISO 42001
TL;DR

Vendor Security Manager at Sierra building and scaling a vendor security program for an AI platform. Conduct technical assessments of AI/model vendors, manage third-party risk, and develop frameworks for vendor oversight across SaaS, infrastructure, and AI providers.

Apply at Sierra →
share:
you'll be redirected to the company's career page

Job description

About us

The Role

We're looking for a Vendor Security Manager to join Sierra's Security team. The security of our Conversational AI Platform depends on the security of everything connected to it, the vendors, model providers, infrastructure partners, and supply chain dependencies that enable how Sierra operates and scales.

You'll build and scale Sierra's vendor security program from the ground up, conducting deep technical assessments, developing frameworks purpose-built for AI vendor risk, and driving security decisions across all of Sierra's third-party security relationships. This is a hands-on role that requires both technical depth and strong judgment. You’ll help Sierra make informed trade-offs between speed, scale, and security in a business that moves fast and operates in regulated industries.

We value people who are energized by uncertainty and who can form a credible point of view even with incomplete information and can get more rigorous as the situation sharpens.

What You'll Do

Program Ownership & Security Risk Management

Be the interface between Security and Sierra teams on everything vendor security related, drive risk conversations, and keep the program moving.

Own vendor security risk decisions and escalation paths end-to-end, including clear documentation of risk acceptance rationale, mitigation plans, and trade-offs.

Build and continuously improve the vendor security program methodology, tooling, risk tiering, monitoring, and response, scaling it intelligently as Sierra's vendor footprint grows.

Assess and manage security risk across Sierra's full third-party landscape, recognizing that vendors, strategic partners, and contractors carry distinct risk profiles and require tailored oversight. A technology partner with deep API integration is a different security conversation than a SaaS tool or a contractor with scoped environment access — the program you build should reflect that.

Ensure the program meets audit and regulatory expectations across SOC 2, PCI DSS, FedRAMP, ISO 42001, ISO 27001, and emerging AI governance frameworks that hold up under enterprise customer and regulator scrutiny.

Technical Assessment & Supply Chain

Conduct deep, evidence-based security assessments across Sierra's vendor landscape SaaS providers, cloud and infrastructure partners, AI and model providers, and strategic suppliers including reviewing architectures, IAM configurations, access scopes, and vulnerability assessments.

Develop assessment frameworks for AI and model vendors that address risks specific to how these systems actually work including prompt data handling, training data practices, inference infrastructure access, and model supply chain integrity.

Develop and maintain a model provider oversight program that reflects Sierra's reality of working across a constellation of LLM and AI model vendors. That means understanding each provider's data handling commitments, inference infrastructure security, model update and versioning practices, and what contractual and technical controls govern how Sierra's data moves through each. When a model provider changes terms, updates a model, or discloses a security issue, you're the person who understands what it means for Sierra and what to do about it.

Map and monitor Sierra's full supply chain surface, including fourth parties and subprocessors, with visibility into software dependencies, open source components, and AI model provenance.

Think in blast radius. Understand what's reachable if they're compromised data flows, network adjacency, privilege scope, lateral movement paths and let that analysis drive technical controls and contractual requirements.

Automation & Visibility

Build detection logic and automated alerting that fires when a vendor's security posture degrades lapsed certifications, exposed services, configuration drift, or new vulnerability disclosures so Sierra's response is proactive.

Automate evidence collection and control validation across the vendor portfolio, reducing the manual overhead of assessment cycles and creating an audit trail that holds up under scrutiny.

Build integrations between vendor security tooling and Sierra's internal systems, procurement workflows and Slack alerting so risk signals reach the right people quickly and efficiently.

Use AI and tooling to analyze vendor documentation at scale and surface risk signals early and continuously. Develop dashboards and reporting that give leadership real visibility into vendor risk posture, remediation velocity, assessment coverage, and aging findings.

Who You'll Work With

You’ll work with Platform Engineering, Security Engineering, Legal, Operations and Finance teams to understand IAM boundaries, model provider’s API access and infrastructure scaling.

You'll partner on understanding what vendors actually have access to, how third-party components sit inside Sierra's architecture, and how supply chain security gets built into how Sierra ships.

What You'll Bring

Even Better

Our values

What we offer

We want our benefits to reflect our values and offer the following to full-time employees:

These benefits are further detailed in Sierra's policies, may vary by region, and are subject to change at any time, consistent with the terms of any applicable compensation or benefits plans. Eligible full-time employees can participate in Sierra's equity plans subject to the terms of the applicable plans and policies.

Be you, with us

We're working to bring the transformative power of AI to every organization in the world. To do so, it is important to us that the diversity of our employees represents the diversity of our customers. We believe that our work and culture are better when we encourage, support, and respect different skills and experiences represented within our team. We encourage you to apply even if your experience doesn't precisely match the job description. We strive to evaluate all applicants consistently without regard to race, color, religion, gender, national origin, age, disability, veteran status, pregnancy, gender expression or identity, sexual orientation, citizenship, or any other legally protected class.

Apply at Sierra →

More open roles at Sierra

Sierra ⚡ AI-native · 🔄 synced 7h ago
Agent Engineer, TLM
📍 New York, US 🛠 AI tools welcome at work · Manager
Agent Engineer leading a team building production-grade AI agents at Sierra, a platform for enterprise customer experience automation. Manage engineers across the full agent development lifecycle, partner with large enterprises and startups, and shape the platform's evolution.
ReactTypeScriptGoRAG pipelineseval frameworksagent tooling
83
AI-core
Sierra ⚡ AI-native · 🔄 synced 7h ago
Software Engineer, Agent (Thai Speaking)
📍 Singapore, SG 🛠 AI tools welcome at work · Mid
Software engineer at Sierra building production AI agents for enterprise customers. Focus on agent development lifecycle, customer partnerships, and platform evolution across finance, healthcare, and commerce.
ReactTypeScriptGoRAG pipelineseval frameworksagent tooling
83
AI-core
Sierra ⚡ AI-native · 🔄 synced 7h ago
Software Engineer, Agent (Korean Speaking)
📍 Singapore, SG 🛠 AI tools welcome at work · Mid
Software engineer at Sierra building production AI agents for enterprise customers. Role spans agent design, deployment, and iteration across finance, healthcare, and commerce sectors. Direct customer engagement and platform evolution.
ReactTypeScriptGoRAG pipelineseval frameworksprompt engineering
83
AI-core
Sierra ⚡ AI-native · 🔄 synced 7h ago
Software Engineer, Agent
📍 Sydney, AU 🛠 AI tools welcome at work · Mid
Software Engineer building production AI agents at Sierra, a platform for enterprise customer experience automation. Role spans agent design, deployment, and iteration across finance, healthcare, and commerce sectors.
ReactTypeScriptGoRAG pipelineseval frameworksprompt engineering
83
AI-core
Sierra ⚡ AI-native · 🔄 synced 7h ago
Software Engineer, Agent Architecture
📍 San Francisco, US 🛠 AI tools welcome at work · Mid
Software engineer at Sierra building core agent orchestration systems. Focus on Agent SDK, agentic loops, retrieval/grounding, and evaluation frameworks for AI-powered customer experience platform.
GoTypeScript
83
AI-core