FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in vendor security risk assessment, including the ability to analyze architectures, data flows, and access management. Proficient in translating security findings into actionable contractual positions and delivering cross-functional programs effectively.
Highest-signal resume keywords
Vendor Security Risk AssessmentISO 27001 KnowledgeNIST 800-53 KnowledgeCodex AI-Assisted ToolsSecurity Principles and Controls
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Data ProtectionAccess ManagementApplication SecurityThreat Information AnalysisControl Effectiveness AssessmentSecurity Findings TranslationWorkflow Improvement DeliverySystemic Risk IdentificationTechnical Requirement TranslationPerformance Ownership
Soft Skills
Clear CommunicationIndependent Decision-MakingProblem-SolvingCollaborationNegotiation
Tools & Technologies
CodexAI-Assisted Development Tools
Certifications & Qualifications
Active Full Scope Polygraph Clearance
Industry Keywords
Supply-Chain SecuritySecurity AddendaContractual PositionsOperational PracticesSecurity Patterns
About the role
Key responsibilities & impact- Own vendor security engagements from business-need understanding through scoping, assessment, decision, treatment, and reassessment
- Make assessment decisions independently and route formal exceptions and risk acceptance to appropriate decision owners
- Analyze vendor use cases, workflows, user journeys, data flows, identities, access, integrations, and supply-chain dependencies
- Identify plausible attack paths and consequences for OpenAI
- Assess architectures, configurations, controls, logs, and operational practices
- Test evidence supporting security claims and clarify gaps and uncertainty
- Develop practical treatments involving operating models, data exposure, access, architecture, vendor choice, controls, or containment
- Drive implementation with responsible owners and verify treatment effectiveness
- Build reusable security patterns with applicability, safeguards, evidence requirements, exceptions, and review triggers
- Work with Legal, Procurement, and vendors on security addenda and contractual positions
- Define requirements, roadmaps, and success measures for bounded programs, products, and services
- Use Codex or comparable AI-assisted tools to improve scoping, evidence checks, routing, decision reuse, and treatment tracking
- Lead delivery across Security and partner teams, translating goals into technical requirements, milestones, and delivery plans
- Identify systemic risks, resolve dependencies and disagreements, and carry commitments through completion
- Use casework, incidents, threat information, and customer feedback to improve decisions and program priorities
Requirements
What you’ll need- Independently assessed consequential third-party, supply-chain, or comparable security risks
- Understanding of security principles and controls, including data protection, access management, application security, prevention, detection, and response
- Ability to reason about architecture, identity, APIs, data flows, logging, integrations, and control effectiveness
- Knowledge of ISO 27001, NIST 800-53, and SOC 2
- Experience translating security findings and requirements into practical contractual positions
- Experience delivering products or workflow improvements, testing expected behavior and failure cases, learning from users, and owning performance after launch
- Ability to use Codex or comparable AI-assisted development tools to build, run, inspect, and test working solutions
- Experience independently delivering cross-functional programs and translating ambiguity into technical requirements and plans
- Ability to judge when to build, use existing systems, or engage partners to resolve blockers
- Ability to communicate complex security issues clearly in writing and conversation, including recommendations, evidence, and tradeoffs
- Active Full Scope Polygraph clearance
- Willingness to work on-site at a client’s office 5 days a week in Maryland, if applicable
Benefits
Comp & perks- Equity
- Performance-related bonus(es) for eligible employees
- Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts
- Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit)
- 401(k) retirement plan with employer match
- Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents)
- Paid medical and caregiver leave (up to 8 weeks)
- Flexible PTO for exempt employees and up to 15 days annually for non-exempt employees
- 13+ paid company holidays
- Multiple paid coordinated company office closures throughout the year
- Paid sick or safe time
- Mental health and wellness support
- Employer-paid basic life and disability coverage
- Annual learning and development stipend
- Daily meals in offices
- Meal delivery credits as eligible
- Relocation support for eligible employees
- Charitable donation matching
- Wellness stipends
- Reasonable accommodations for applicants with disabilities
- Immigration and sponsorship support may be provided based on individual circumstances
