{"version":"0.1","company":{"name":"YubHub","url":"https://yubhub.co","jobsUrl":"https://yubhub.co/jobs/skill/security-risk-management"},"x-facet":{"type":"skill","slug":"security-risk-management","display":"Security Risk Management","count":3},"x-feed-size-limit":100,"x-feed-sort":"enriched_at desc","x-feed-notice":"This feed contains at most 100 jobs (the most recently enriched). For the full corpus, use the paginated /stats/by-facet endpoint or /search.","x-generator":"yubhub-xml-generator","x-rights":"Free to redistribute with attribution: \"Data by YubHub (https://yubhub.co)\"","x-schema":"Each entry in `jobs` follows https://schema.org/JobPosting. YubHub-native raw fields carry `x-` prefix.","jobs":[{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_70a6eadc-7c1"},"title":"Security Programs - Technical Program Manager","description":"<p>We are seeking a Security Technical Program Manager to join our Product Engineering organization. As a Security Technical Program Manager, you will work across cross-functional teams to ensure our cloud infrastructure is secure and private, while maintaining scalability and delivery of exceptional performance to meet the demands of our customers.</p>\n<p>The ideal candidate will have 8+ years of hands-on experience in Security Technical Program Management, Security Strategy, Security Risk Management and/or Security Compliance roles, ideally within the cloud services industry. They will have a Bachelor&#39;s degree in Information Security, Computer Science, or a related field or equivalent job experience.</p>\n<p>Responsibilities:</p>\n<ul>\n<li>Lead end-to-end program management for critical security engineering and security compliance initiatives, including cross-functional planning, execution, delivery, and retrospectives</li>\n<li>Define program scope, milestones, and success metrics while managing security risks and dependencies</li>\n<li>Partner closely within the security team, and across engineering, product management and operations teams to ensure alignment on priorities and deliverables</li>\n<li>Act as the primary point of contact for security and cross-functional stakeholders, providing regular status updates, addressing risks, and ensuring accountability</li>\n<li>Facilitate and influence technical security, privacy and compliance discussions and decisions to align with long-term infrastructure goals and business objectives</li>\n<li>Develop and implement scalable processes to improve efficiency and predictability in program delivery</li>\n<li>Strategically automate and improve day-to-day operations, processes and reporting</li>\n<li>Tailor communications to a diverse audience and remain adaptable to a wide range of personalities and technical depth</li>\n</ul>\n<p>What We Offer:</p>\n<ul>\n<li>Competitive salary range of $122,000 to $237,000</li>\n<li>Discretionary bonus, equity awards, and a comprehensive benefits program</li>\n<li>Medical, dental, and vision insurance - 100% paid for by CoreWeave</li>\n<li>Company-paid Life Insurance</li>\n<li>Voluntary supplemental life insurance</li>\n<li>Short and long-term disability insurance</li>\n<li>Flexible Spending Account</li>\n<li>Health Savings Account</li>\n<li>Tuition Reimbursement</li>\n<li>Ability to Participate in Employee Stock Purchase Program (ESPP)</li>\n<li>Mental Wellness Benefits through Spring Health</li>\n<li>Family-Forming support provided by Carrot</li>\n<li>Paid Parental Leave</li>\n<li>Flexible, full-service childcare support with Kinside</li>\n<li>401(k) with a generous employer match</li>\n<li>Flexible PTO</li>\n<li>Catered lunch each day in our office and data center locations</li>\n<li>A casual work environment</li>\n<li>A work culture focused on innovative disruption</li>\n</ul>\n<p>Our Workplace:</p>\n<ul>\n<li>While we prioritize a hybrid work environment, remote work may be considered for candidates located more than 30 miles from an office, based on role requirements for specialized skill sets. New hires will be invited to attend onboarding at one of our hubs within their first month. Teams also gather quarterly to support collaboration.</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_70a6eadc-7c1","directApply":true,"hiringOrganization":{"@type":"Organization","name":"CoreWeave","sameAs":"https://www.coreweave.com","logo":"https://logos.yubhub.co/coreweave.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/coreweave/jobs/4556342006","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$122,000 to $237,000","x-skills-required":["Security Technical Program Management","Security Strategy","Security Risk Management","Security Compliance","Cloud Services","Program Management","Cross-Functional Team Collaboration","Communication","Adaptability","Technical Security","Privacy","Compliance"],"x-skills-preferred":["Networking","Storage","Containerization (Kubernetes)","CI/CD Pipelines"],"datePosted":"2026-04-18T15:49:22.921Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Livingston, NJ / New York, NY / Sunnyvale, CA"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Security Technical Program Management, Security Strategy, Security Risk Management, Security Compliance, Cloud Services, Program Management, Cross-Functional Team Collaboration, Communication, Adaptability, Technical Security, Privacy, Compliance, Networking, Storage, Containerization (Kubernetes), CI/CD Pipelines","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":122000,"maxValue":237000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_4f6e3d04-c70"},"title":"Information Security Analyst - GRC","description":"<p>At Synopsys, we drive the innovations that shape the way we live and connect. Our technology is central to the Era of Pervasive Intelligence, from self-driving cars to learning machines. We lead in chip design, verification, and IP integration, empowering the creation of high-performance silicon chips and software content.</p>\n<p>Join us to transform the future through continuous technological innovation.</p>\n<p>As an Information Security Analyst, you will be an integral part of the Synopsys Corporate Information Security group, working within a mature Governance, Risk, and Compliance (GRC) Team. This team collaborates closely with the Director of Information Security, Manager of GRC, and stakeholders across the organization to raise the overall security and compliance posture for Synopsys.</p>\n<p>Your responsibilities will include:</p>\n<ul>\n<li>Identifying, documenting, monitoring, and reporting on risk register items, KPIs/KRIs, including the monitoring of security control efficacy.</li>\n<li>Demonstrating experience with governance, risk, and compliance tools.</li>\n<li>Working with security control frameworks such as ISO 27001, SOC 2 Type II, NIST 800-53, NIST CSF, and similar.</li>\n<li>Presenting security risks to a wide audience, including risk owners and other stakeholders.</li>\n<li>Interacting with Synopsys IT and business stakeholders to understand risks to critical infrastructure by defining potential business impact with the responsibility to apply effective mitigation strategies.</li>\n<li>Providing guidance on control implementations related to governance frameworks, regulations, and corporate security policies.</li>\n<li>Understanding of security functions including Incident Management, Change Management, Identity and Access Management, and Vendor Security Risk Management.</li>\n<li>Conducting third-party (vendor) risk assessments in collaboration with stakeholders.</li>\n<li>Providing security requirements to both internal partners and external third-party providers.</li>\n<li>Effectively communicating and working with a global team.</li>\n<li>Maintaining, enforcing, and tracking the Synopsys Information Security Exception process.</li>\n<li>Staying current with industry, regulatory, and legal requirements relevant to security, compliance, and privacy.</li>\n</ul>\n<p>You will be responsible for enhancing Synopsys&#39; overall security and compliance posture by building and improving the GRC portfolio. You will also enable and transform the risk management program to address the evolving cybersecurity threat landscape. Ensure regulatory compliance as the company continues to grow. Strengthen risk assessments of suppliers and partners, contributing to a robust security framework.</p>\n<p>To be successful in this role, you will need:</p>\n<ul>\n<li>A bachelor&#39;s degree in Computer Science, Information Systems, or a related field.</li>\n<li>Typically, 5-7 years of experience in a related field.</li>\n<li>Knowledge of common certification and attestation programs such as ISO 27001 and SOC 2 Type II, ISO 31000.</li>\n<li>Practical working experience with control frameworks like ISO 27001, NIST 800-53, SOC 2 Type II and NIST CSF.</li>\n<li>Excellent organizational skills with attention to detail and the ability to multitask for project prioritization.</li>\n<li>Effective communication skills with internal and external customers, executive managers, and team members.</li>\n<li>Ability to understand the intent of compliance requirements to provide effective and meaningful examination.</li>\n</ul>\n<p>We offer a comprehensive range of health, wellness, and financial benefits to cater to your needs. Our total rewards include both monetary and non-monetary offerings. Your recruiter will provide more details about the salary range and benefits during the hiring process.</p>\n<p>At Synopsys, we want talented people of every background to feel valued and supported to do their best work. Synopsys considers all applicants for employment without regard to race, color, religion, national origin, gender, sexual orientation, age, military veteran status, or disability.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_4f6e3d04-c70","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Synopsys","sameAs":"https://careers.synopsys.com","logo":"https://logos.yubhub.co/careers.synopsys.com.png"},"x-apply-url":"https://careers.synopsys.com/job/bengaluru/information-security-analyst-grc/44408/93409691360","x-work-arrangement":"onsite","x-experience-level":"mid","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["governance, risk, and compliance","security control frameworks","ISO 27001","SOC 2 Type II","NIST 800-53","NIST CSF","incident management","change management","identity and access management","vendor security risk management"],"x-skills-preferred":[],"datePosted":"2026-04-05T13:16:53.710Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Bengaluru"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"governance, risk, and compliance, security control frameworks, ISO 27001, SOC 2 Type II, NIST 800-53, NIST CSF, incident management, change management, identity and access management, vendor security risk management"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_23a792a8-cc4"},"title":"Vendor Security Program Manager","description":"<p><strong>Job Posting</strong></p>\n<p><strong>Vendor Security Program Manager</strong></p>\n<p><strong>Location</strong></p>\n<p>San Francisco; New York City; Seattle; Washington, DC</p>\n<p><strong>Employment Type</strong></p>\n<p>Full time</p>\n<p><strong>Location Type</strong></p>\n<p>Hybrid</p>\n<p><strong>Department</strong></p>\n<p>Security</p>\n<p><strong>Compensation</strong></p>\n<ul>\n<li>SF, Seattle and NYC: $207K – $335K • Offers Equity</li>\n<li>Zone A: $186K – $301.5K • Offers Equity</li>\n<li>Zone B: $165.6K – $268K • Offers Equity</li>\n</ul>\n<p>The base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. If the role is non-exempt, overtime pay will be provided consistent with applicable laws. In addition to the salary range listed above, total compensation also includes generous equity, performance-related bonus(es) for eligible employees, and the following benefits.</p>\n<ul>\n<li>Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts</li>\n</ul>\n<ul>\n<li>Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit)</li>\n</ul>\n<ul>\n<li>401(k) retirement plan with employer match</li>\n</ul>\n<ul>\n<li>Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents), plus paid medical and caregiver leave (up to 8 weeks)</li>\n</ul>\n<ul>\n<li>Paid time off: flexible PTO for exempt employees and up to 15 days annually for non-exempt employees</li>\n</ul>\n<ul>\n<li>13+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick or safe time (1 hour per 30 hours worked, or more, as required by applicable state or local law)</li>\n</ul>\n<ul>\n<li>Mental health and wellness support</li>\n</ul>\n<ul>\n<li>Employer-paid basic life and disability coverage</li>\n</ul>\n<ul>\n<li>Annual learning and development stipend to fuel your professional growth</li>\n</ul>\n<ul>\n<li>Daily meals in our offices, and meal delivery credits as eligible</li>\n</ul>\n<ul>\n<li>Relocation support for eligible employees</li>\n</ul>\n<ul>\n<li>Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided.</li>\n</ul>\n<p>More details about our benefits are available to candidates during the hiring process.</p>\n<p>This role is at-will and OpenAI reserves the right to modify base pay and other compensation components at any time based on individual performance, team or company results, or market conditions.</p>\n<p><strong>About the Team</strong></p>\n<p>The Vendor Security team sits at the core of our mission to ensure our technology benefits humanity safely and securely. We provide security assurances and robust compliance frameworks for our technology, people, and products. Our mission is to build trust with the world in our products and company. Our work is technical yet highly operational, strategically aligning with security and engineering teams to navigate and mitigate risks proactively. We prioritize impact, enable innovation, and foster a culture of continuous compliance and security awareness.</p>\n<p><strong>About the Role</strong></p>\n<p>As a Program Manager within the Vendor Security team, you will play a crucial role in protecting our organisation against external risks posed by suppliers, vendors, partners, and hardware manufacturers. Your responsibilities will include conducting comprehensive security assessments, building a program to manage global supply chain and vendor risks, and driving security initiatives across all of our third-party relationships. You will be analytical, detail-oriented, and proactive, capable of translating complex security evaluations into clear, actionable strategies.</p>\n<p>The role is expected to operate with a strong point of view on risk. You will be responsible not only for identifying and documenting vendor and supply-chain risk, but for helping the company make informed trade-offs between speed, scale, and security. This role requires exceptional organisational skills, the ability to effectively communicate across different business functions, and a strong commitment to operational excellence in a dynamic environment.</p>\n<p>This role may be based out of one of our US offices (San Francisco, Seattle, NYC or DC.) We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees.</p>\n<p><strong>In this role, you will:</strong></p>\n<ul>\n<li>Be the interface for Security to the rest of the organisation for vendors.</li>\n</ul>\n<ul>\n<li>Own vendor security risk decisions and escalation paths, including clearly documenting risk acceptance, mitigation plans, and executive-level trade-offs when security requirements cannot be fully met.</li>\n</ul>\n<ul>\n<li>Conduct deep, evidence-based security assessments of third parties, including review of architectures, configurations, controls, logs, and operational practices - moving beyond questionnaires and attestations to validate real-world security posture of vendors.</li>\n</ul>\n<ul>\n<li>Assess and manage security risk across a diverse vendor landscape, including SaaS providers, cloud and infrastructure partners, hardware manufacturers, chip suppliers, and other strategic or high-impact suppliers.</li>\n</ul>\n<ul>\n<li>Develop, build, and continuously improve the vendor security program and security supply chain risk management function at OpenAI.</li>\n</ul>\n<ul>\n<li>Develop, propose, and implement effective controls to mitigate identified vendor risks.</li>\n</ul>\n<ul>\n<li>Build and maintain collaborative partnerships with key internal stakeholders including Infrastructure Security, Product, Engineering, Legal, Procurement, and Threat Intelligence to ensure comprehensive security coverage of the vendor and third-party supply chain.</li>\n</ul>\n<ul>\n<li>Streamline and automate vendor and supply chain security processes to increase efficiency and reduce manual overhead.</li>\n</ul>\n<p><strong>You might thrive in this role if you have:</strong></p>\n<ul>\n<li>Proven experience conducting third-party or supply chain security assessments, including building and scaling a vendor management security program.</li>\n</ul>\n<ul>\n<li>An in-depth understanding of information security principles and controls, including data protection, access management, proactive and reactive security measures, and application security.</li>\n</ul>\n<ul>\n<li>Comfort operating in ambiguity, with the ability to form defensible security opinions even when information is incomplete or uncertain.</li>\n</ul>\n<ul>\n<li>Strong analytical and problem-solving skills, with the ability to identify and mitigate complex security risks.</li>\n</ul>\n<ul>\n<li>Excellent communication and interpersonal skills, with the ability to effectively collaborate with cross-functional teams and stakeholders.</li>\n</ul>\n<ul>\n<li>Strong organisational and project management skills, with the ability to prioritise tasks and manage multiple projects simultaneously.</li>\n</ul>\n<ul>\n<li>A strong commitment to operational excellence and continuous improvement, with a focus on delivering high-quality results in a dynamic environment.</li>\n</ul>\n<ul>\n<li>A passion for security and a desire to make a meaningful impact in the field.</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_23a792a8-cc4","directApply":true,"hiringOrganization":{"@type":"Organization","name":"OpenAI","sameAs":"https://jobs.ashbyhq.com","logo":"https://logos.yubhub.co/openai.com.png"},"x-apply-url":"https://jobs.ashbyhq.com/openai/fb1e823e-cfcc-4293-8893-cc77e467c561","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$207K – $335K • Offers Equity","x-skills-required":["information security principles and controls","data protection","access management","proactive and reactive security measures","application security","third-party or supply chain security assessments","vendor management security program","security risk management","compliance frameworks","security awareness","operational excellence","project management","communication and interpersonal skills"],"x-skills-preferred":["cloud security","infrastructure security","threat intelligence","security analytics","incident response","security testing","penetration testing","security consulting","security training","security awareness training"],"datePosted":"2026-03-06T18:37:35.209Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco; New York City; Seattle; Washington, DC"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"information security principles and controls, data protection, access management, proactive and reactive security measures, application security, third-party or supply chain security assessments, vendor management security program, security risk management, compliance frameworks, security awareness, operational excellence, project management, communication and interpersonal skills, cloud security, infrastructure security, threat intelligence, security analytics, incident response, security testing, penetration testing, security consulting, security training, security awareness training","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":207000,"maxValue":335000,"unitText":"YEAR"}}}]}