Supplier Security & Assurance, Security GRC

United States Digital Space LLC

United States

Hybrid

USD 255,000 - 270,000

Full time

12 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

United States Digital Space LLC is seeking a Supplier Security & Assurance professional to lead end-to-end assessments of vendor security and risk for the company’s supplier ecosystem.

You will review evidence, determine inherent and residual risk, drive closure with vendors and business owners, and shape tooling and requirements for the program, including maintaining an LLm-powered assessment platform. This hybrid role requires collaborating across security, legal, and procurement.

Qualifications

  • Experience running supplier security assessments end to end
  • Knowledge of risk fundamentals and applying them to evidence
  • Ability to assess vendors across security domains
  • Track record influencing teams to close risks
  • Experience building or tuning LLM-backed workflows
  • Experience with issue management workflows
  • Technical knowledge of SaaS security config and vendor contracts
  • Ability to read SOC 2 or tests and derive findings

Responsibilities

  • Run supplier security assessments end to end
  • Operate supplier issue management with severity, owner, and due date
  • Drive remediation with the vendor and business owner
  • Record risk acceptances and roll issues to the risk register
  • Perform continuous monitoring after approval
  • Improve the program and tooling as you run it
  • Maintain the Claude-powered assessment platform

Skills

Supplier assessments
Risk fundamentals
LLM workflow
Issue management
SaaS security
SOC 2 reading
Vendor management
Cross-team influence
Prompt tuning

Education

Bachelor’s degree

Job description

About the company

the company’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.

About the role

the company's Supplier Security & Assurance (SSA) team sits within Security GRC and is responsible for assessing the security of our suppliers: evaluating whether vendors meet our security requirements, capturing the deviations, and giving the business a clear approval decision it can act on. We assess the vendor population a frontier AI lab actually depends on: SaaS and software, human data operations, compute and data center providers, hardware suppliers, and services firms. The program is designed agent-first so that people spend their time on judgment, remediation, and the vendors that matter most.

As a member of the Supplier Security & Assurance team you will run supplier security assessments end to end: reviewing evidence, verifying agent-drafted evaluations, determining inherent and residual risk, and driving findings to closure with vendors and business owners. You will also carry the work that extends assurance past the approval, from contractual security terms and secure configuration baselines to continuous monitoring and reassessment, and you will help shape the tooling and requirements the program runs on.

Key responsibilities
  • Run supplier security assessments: review agent-prefilled outputs, evaluate vendor controls and evidence, determine residual risk, route to domain reviewers where deeper assessment is warranted
  • Operate supplier issue management and risk treatment: document each finding with a severity, an owner, and a due date, drive remediation with the vendor and the business owner, record risk acceptances, and roll open issues up to the risk register
  • Run continuous monitoring after approval: reopen an assessment on defined triggers (data classification change, new SOC 2 report, new subprocessor, vendor incident), investigate SaaS configuration, data, and use case drift signals, and queue a reassessment where the vendor's scope has moved
  • Improve the program as you run it: identify gaps in coverage, questionnaires, requirements, and tooling that surface during assessments, propose the fix, and carry roadmap items that mature supplier security overall
  • Tune and maintain our Claude-powered assessment platform alongside the team: prompt development, questionnaire and assessment type design, calibration against assessor decisions, and output QA
  • Contribute to KPI and KRI reporting on coverage, cycle time, residual risk, open issues, and reassessments due
Minimum qualifications
  • Experience running supplier security assessments end to end at a technology company: scoping the engagement, determining inherent risk, reviewing controls and evidence, documenting residual risk, and driving findings to closure
  • Working knowledge of risk fundamentals (inherent and residual risk, control effectiveness, compensating controls, risk acceptance) and the judgment to apply them when the evidence is incomplete or the answer isn't in a framework
  • Ability to assess a vendor across security domains, and to recognize which findings you can close yourself and which need a security domain specialist
  • Track record of driving risk treatment to closure through influence across teams with competing priorities
  • Experience building or tuning an LLM-backed workflow, agent, or automation in a risk, compliance, or operations context, including tuning prompts and reviewing model output for accuracy
  • Experience building or operating issue management workflows: logging issues with a clear owner and due date, tracking remediation, and escalating when treatment stalls
  • Working technical knowledge of SaaS security configuration (SSO and SCIM, admin scoping, sharing defaults, audit log export) and of standard vendor security contract terms (DPA, incident notification, subprocessors, audit and testing rights)
  • Ability to read a SOC 2 report or penetration test and turn it into findings: identify control exceptions and carve-outs, map complementary user entity controls, and judge what the evidence does and does not prove
Preferred qualifications
  • Experience assessing cloud infrastructure, data center, or data-pipeline vendors
  • Experience supporting SOX, SOC 2, or ISO 27001 third party or vendor management controls
  • Experience assessing additional, more specialized vendor cohorts from a security risk perspective: human data operations or data labeling vendors, hardware suppliers, compute providers and neoclouds, and others
  • Experience with post-approval supplier continuous monitoring: configuration, data, and use case drift detection, shadow IT & SaaS detection, vendor incident management, or evidence-based vendor audits/site visits

Annual Salary:

$255,000—$270,000 USD

LogisticsMinimum education:

Bachelor’s degree or an equivalent combination of education, training, and/or experience

Required field of study:

A field relevant to the role as demonstrated through coursework, training, or professional experience

Minimum years of experience:

Years of experience required will correlate with the internal job level requirements for the position

Location-based hybrid policy:

Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.

Visa sponsorship:

We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.

Not all strong candidates will be in every qualification as specified. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you're interested in this work. We think AI systems like the ones we're building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team.

Your safety matters to us.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Supplier Security & Assurance, Security GRC
Supplier Security & Assurance, Security GRC

EngineersOfAI • Seattle (WA), Northern (KY)

Hybrid
USD 140,000 - 190,000
Supplier Security & Assurance, Security GRC
Supplier Security & Assurance, Security GRC

Anthropic • Seattle (WA)

Hybrid
USD 255,000 - 270,000
Competitive compensation
Optional equity donation matching
Generous vacation and parental leave
+2
Supplier Security & Assurance, Security GRC
Supplier Security & Assurance, Security GRC

Anthropic • New York (NY)

Hybrid
USD 255,000 - 270,000
Technical Program Manager, Security
Technical Program Manager, Security

United States Digital Space LLC • San Francisco (CA)

Hybrid
USD 290,000 - 365,000
Protective Intelligence Analyst
Protective Intelligence Analyst

United States Digital Space LLC • San Francisco (CA), Washington

Hybrid
USD 230,000 - 280,000
Restaurant not provided
Supplier Security & Assurance, Security GRC
Supplier Security & Assurance, Security GRC

Candidate • San Francisco (CA), Northern (KY)

Hybrid
USD 255,000 - 270,000
Product Manager, Safeguards (Account Integrity & Abuse)
Product Manager, Safeguards (Account Integrity & Abuse)

United States Digital Space LLC • San Francisco (CA), New York (NY)

On-site
USD 385,000 - 460,000
Sr. Security Engineer
Sr. Security Engineer

Procurement Sciences • Lehi (UT)

Hybrid
USD 140,000 - 200,000
Remote work
Stock options
Health insurance
+1
Sr. Security Engineer
Sr. Security Engineer

Procurement Sciences Inc • Lehi (UT), Northern (KY)

Hybrid
USD 125,000 - 180,000
Stock options
Flexible work arrangements (remote)
Professional development
+2
Sr Security Technologist - Risk & Compliance
Sr Security Technologist - Risk & Compliance

United States Digital Space LLC • San Francisco (CA)

On-site
USD 180,000 - 200,000