Secure Manufacturing & Stealth Partner, Marketing
Serve as the dedicated senior security partner to OpenAI's Marketing team, identifying secrecy risks in launches, events, creative production, and external partners while embedding practical controls that protect sensitive information without slowing execution. Requires 12+ years protecting major product launches and building trusted relationships with executives and creative teams.
About the job
Responsibilities
- Serve as the primary SMS Partner and trusted adviser to Marketing, building a deep understanding of its priorities, planning cycles, launches, events, external partners, and sensitive information flows.
- Identify secrecy and information-exposure risks early, then translate SMS requirements into practical controls that protect sensitive work without unnecessarily slowing execution.
- Build, document, and socialize durable operating mechanisms for compartmentalization, need-to-know access, agencies and vendors, sensitive creative production, events, demonstrations, launch preparation, codenames, watermarking, and password controls.
- Assess and approve Marketing systems and information workflows, identify gaps or duplication, establish secure handling requirements, and advise AI-native Marketing initiatives on permissions, data governance, and operational tracking.
- Coordinate shared SMS capabilities—including investigations, prototype handling, APAC support, and other specialist services—while partnering across Marketing, Legal, Product, Communications, Procurement, IT, and Security.
- Establish clear intake, escalation, reporting, training, and incident-response processes, and continuously improve controls based on recurring needs, incidents, and lessons learned.
Requirements
- 12+ years of experience leading security, product secrecy, information protection, or sensitive-program risk within a global consumer technology, hardware, media, or similarly launch-driven organization.
- Direct experience serving as the senior security partner to Marketing, Communications, Public Relations, Events, or another highly visible business function with access to unreleased products and launch-sensitive information.
- Demonstrated success protecting major product launches, creative campaigns, executive communications, media briefings, events, demonstrations, agencies, production vendors, and other external partners.
- Proven ability to build trusted relationships with senior executives and creative teams, influence without authority, and translate security requirements into practical operating models that preserve speed and effectiveness.
- Deep understanding of product secrecy, compartmentalization, need-to-know access, insider risk, third-party exposure, information flows, incident response, and cross-functional coordination.
- Familiarity with technical information-protection controls, including access and risk governance, secure collaboration, watermarking, monitoring, and data-loss prevention.
- Excellent written and verbal communication skills, including the ability to convert complex secrecy and security requirements into clear, practical guidance for technical and non-technical stakeholders.
- Unimpeachable integrity, sound judgment, discretion, adaptability, and the ability to operate independently in fast-moving, ambiguous, and highly confidential environments.
Nice-to-Haves
- Experience with AI-native Marketing initiatives on permissions, data governance, and operational tracking.
Skills
Product Secrecy, Information Protection, Incident Response, Data Loss Prevention, Watermarking, Access Governance, Secure Collaboration, Risk Assessment, Cross-Functional Coordination, Compartmentalization, Insider Risk, Third-Party Risk
Similar jobs
Security Engineering jobsOwn and scale IT general controls, access governance, segregation of duties, and audit readiness across enterprise applications. The role combines SOX expertise with AI-enabled continuous controls monitoring and requires 10+ years of controls, audit, or enterprise governance experience.
Staff Security Software Engineer leading identity and access strategy, architecture, and hands-on platform development across customer, employee, contractor, and agentic identities. Requires 10+ years of production software experience and deep expertise in identity and authorization systems.
Design and operate distributed, low-latency infrastructure that protects Reddit from DDoS attacks, bots, scraping, and other network threats. The role requires 7+ years of distributed-systems experience plus expertise in security, networking, and production operations.
Staff-level AppSec engineer building secure coding practices and vulnerability management for a commerce platform. Requires 6+ years in application security with deep AWS and Python experience.
Own the technical security function across cloud infrastructure, detection and response, application security, incident response, and automation. The role requires 8+ years of security engineering experience, deep AWS expertise, and the ability to lead security improvements across engineering teams.