Conducts end-to-end security risk assessments for vendors, customers, and partners while maintaining risk tiering, remediation, reassessments, and reporting. The role also matures third-party risk processes and uses AI-assisted workflows to scale assessment operations.
119k – 176k/yr
Hybrid4+ YOESecurity Engineering
About the role
Responsibilities
Run end-to-end vendor security risk assessments, including intake, questionnaire review, risk rating, findings, exceptions, and documentation.
Assess the security posture of customers and partners onboarding to the platform.
Maintain third-party risk tiering, reassessment cadence, remediation tracking, and the risk register.
Track assessment cycle times, backlog, open exceptions, and reassessment coverage; report ecosystem risk to Security and cross-functional stakeholders.
Build and scale AI-assisted workflows for assessment review, questionnaire analysis, and reporting.
Requirements
4+ years of experience in vendor risk management.
Experience conducting third-party security risk assessments, including reviewing questionnaires, SOC 2 and ISO reports, and security documentation.
Familiarity with the third-party risk lifecycle: intake, tiering, exceptions, risk acceptance, remediation tracking, and periodic reassessment.
Working knowledge of SOC 2, ISO 27001, NIST CSF, and common control domains such as access control, encryption, incident response, and business continuity/disaster recovery.
Ability to evaluate control environments, identify genuine gaps, and assess compensating controls.
Experience maturing third-party or vendor risk programs through improved tiering criteria, questionnaires, workflows, and automation.
Track record of running assessments at volume while maintaining rigor.
Strong analytical, documentation, written communication, and verbal communication skills.
Ability to explain security risks clearly to Procurement, Legal, customers, and other stakeholders.
Comfortable working across Security, Legal, Procurement, and go-to-market teams.
Demonstrated ability to apply AI tooling to assessment review, questionnaire analysis, and reporting to increase throughput.
Nice-to-haves
Third-party risk or audit credential such as CTPRP, CISA, or CISSP.
Hands-on ownership of a TPRM platform such as OneTrust, ProcessUnity, Whistic, or SecurityScorecard.
Compensation and Benefits
Annual base salary range: $118,680–$175,800.
Additional compensation may include equity and/or commission, depending on the position offered.
Comprehensive benefits include medical, dental, vision, and 401(k).
Builds security into AI platform through threat modeling, SAST/DAST in CI/CD, code reviews, and secure architecture design. Requires 4+ years app sec experience, programming in Python/Java/Go/JS, and DevSecOps tools expertise.
119k – 210k/yrHybrid4+ YOESecurity Engineering
System Safety Engineer, Autonomy Trucking
Applied IntuitionSunnyvale, CA
Defines and manages safety architecture, requirements, and analysis (FMEA, FTA, STPA) for L4 autonomous trucking software/hardware. Requires 3+ years system safety experience, automotive standards expertise (ISO 26262), and engineering background in ADAS/autonomy.
118k – 250k/yrOn-site3+ YOESecurity Engineering
Identity & Endpoint Security Engineer
Northwood SpaceLos Angeles, CA
Design and own Northwood's identity and endpoint security architecture with deep focus on Okta administration, SSO, RBAC, MDM, and privileged access controls. Ensure compliance with CMMC Level 2, NIST, ITAR and other government standards in a hybrid environment.
120k – 190k/yrOn-site3+ YOESecurity Engineering
Security & Compliance Operations Manager
MintlifySan Francisco, CA
Own and run Mintlify's end-to-end security and compliance programs (SOC 2, ISO 27001/42001, GDPR, Microsoft SSPA) as the first dedicated GRC Program Manager. Administer Drata, manage audits/vendors/evidence, handle customer-facing compliance, and coordinate with engineering.
120k – 180k/yrOn-site3+ YOESecurity Engineering
Product Security Manager
Northwood SpaceLos Angeles, CA
Own the full product security lifecycle for space communications systems, from threat modeling and secure architecture to penetration testing, vulnerability management, cryptography, and compliance with FedRAMP, CMMC, and NIST standards. Requires 5+ years of product/application security leadership, deep expertise in SAST/DAST, secrets management, CI/CD hardening, and applied cryptography; TS/SCI clearance eligibility required.