Lead vendor risk assessments, procurement security reviews, and security-related legal contract negotiations. * Own front-line defenses for a frontier AI company, including physical security and data ...
Lead vendor risk assessments, procurement security reviews, and security-related legal contract negotiations. * Own front-line defenses for a frontier AI company, including physical security and data ...
GRC Engineer
New York, NY · On-site
From continuous controls monitoring to automated vendor risk intake to AI-accelerated policy drafting, you will design a GRC function built for scale. This is a generalist role that spans the full ...
GRC Engineer
New York, NY · On-site
From continuous controls monitoring to automated vendor risk intake to AI-accelerated policy drafting, you will design a GRC function built for scale. This is a generalist role that spans the full ...
Dir, Operational Sourcing
Manhattan, NY · On-site +1
Coordinate with Governance, Legal, Risk, Vendor Lifecycle, Finance, Accounting, and business stakeholders to ensure clean handoffs, complete documentation, required approvals, and compliant execution.
Dir, Operational Sourcing
Manhattan, NY · On-site +1
Coordinate with Governance, Legal, Risk, Vendor Lifecycle, Finance, Accounting, and business stakeholders to ensure clean handoffs, complete documentation, required approvals, and compliant execution.
Senior Compliance Manager
New York, NY · On-site
$130K - $170K/yr
Vendor Risk Management: Own Trovy's third-party risk management program -- conducting initial and ongoing vendor due diligence, maintaining the vendor inventory, assessing compliance and regulatory ...
Quick apply
Senior Compliance Manager
New York, NY · On-site
$130K - $170K/yr
Vendor Risk Management: Own Trovy's third-party risk management program -- conducting initial and ongoing vendor due diligence, maintaining the vendor inventory, assessing compliance and regulatory ...
... risk assessment methodology. Specifically, the staff will support and assist in: All vendor verification procedures to ensure that new vendors, or adjustments to existing vendors, meet Starr ...
... risk assessment methodology. Specifically, the staff will support and assist in: All vendor verification procedures to ensure that new vendors, or adjustments to existing vendors, meet Starr ...
Vendor Services Analyst
New York, NY · On-site
... risk assessment methodology. Specifically, the staff will support and assist in: • All vendor verification procedures to ensure that new vendors, or adjustments to existing vendors, meet Starr ...
Vendor Services Analyst
New York, NY · On-site
... risk assessment methodology. Specifically, the staff will support and assist in: • All vendor verification procedures to ensure that new vendors, or adjustments to existing vendors, meet Starr ...
Senior Manager of Cyber Security
Clark, NJ · On-site
$120K - $140K/yr
Manage security vendor relationships across the technology portfolio and oversee the vendor risk register. Compliance & Governance: * Enforce the organization's compliance posture for ISO 27001 and ...
Quick apply
Senior Manager of Cyber Security
Clark, NJ · On-site
$120K - $140K/yr
Manage security vendor relationships across the technology portfolio and oversee the vendor risk register. Compliance & Governance: * Enforce the organization's compliance posture for ISO 27001 and ...
Senior Technology Vendor Manager
Jersey City, NJ · On-site
$130K - $180K/yr
Risk/Compliance/Governance * Identifies and Tracks vendor risks as appropriate to ensure they are mitigated or accepted. * Ensures documented exit strategies are in place for all high risk Business ...
Senior Technology Vendor Manager
Jersey City, NJ · On-site
$130K - $180K/yr
Risk/Compliance/Governance * Identifies and Tracks vendor risks as appropriate to ensure they are mitigated or accepted. * Ensures documented exit strategies are in place for all high risk Business ...
Senior Manager of Cyber Security
Clark, NJ · On-site
$120 - $140/hr
Manage security vendor relationships across the technology portfolio and oversee the vendor risk register. Compliance & Governance: * Enforce the organization's compliance posture for ISO 27001 and ...
New
Senior Manager of Cyber Security
Clark, NJ · On-site
$120 - $140/hr
Manage security vendor relationships across the technology portfolio and oversee the vendor risk register. Compliance & Governance: * Enforce the organization's compliance posture for ISO 27001 and ...
New
Senior Manager of Cyber Security (Clark)
Clark, NJ · On-site
$114K - $155K/yr
Manage security vendor relationships across the technology portfolio and oversee the vendor risk register. Compliance & Governance: * Enforce the organization's compliance posture for ISO 27001 and ...
Senior Manager of Cyber Security (Clark)
Clark, NJ · On-site
$114K - $155K/yr
Manage security vendor relationships across the technology portfolio and oversee the vendor risk register. Compliance & Governance: * Enforce the organization's compliance posture for ISO 27001 and ...
Own a defined span of control (direct reports and key teams may include incident response, SOC/operations, identity & access, security architecture, risk & assurance, and vendor risk management)
Own a defined span of control (direct reports and key teams may include incident response, SOC/operations, identity & access, security architecture, risk & assurance, and vendor risk management)
Data Security Compliance Director
New York, NY · Remote
$140K - $175K/yr
Lead vendor security assessments, manage VSQ responses (inbound and outbound), and maintain a tiered vendor risk register. - Policy and controls. Author, review, and update security policies ...
Data Security Compliance Director
New York, NY · Remote
$140K - $175K/yr
Lead vendor security assessments, manage VSQ responses (inbound and outbound), and maintain a tiered vendor risk register. - Policy and controls. Author, review, and update security policies ...
Data Security Compliance Director
New York, NY · On-site
$140K - $175K/yr
Lead vendor security assessments, manage VSQ responses (inbound and outbound), and maintain a tiered vendor risk register. - Policy and controls. Author, review, and update security policies ...
Data Security Compliance Director
New York, NY · On-site
$140K - $175K/yr
Lead vendor security assessments, manage VSQ responses (inbound and outbound), and maintain a tiered vendor risk register. - Policy and controls. Author, review, and update security policies ...
QA Engineer (Archer / GRC)
New York, NY · On-site
... and vendor risk processes. Preferred Skills • Experience testing SIG questionnaires and assessment workflows. • Familiarity with Archer Engage integrations. • Exposure to automation testing ...
QA Engineer (Archer / GRC)
New York, NY · On-site
... and vendor risk processes. Preferred Skills • Experience testing SIG questionnaires and assessment workflows. • Familiarity with Archer Engage integrations. • Exposure to automation testing ...
Director, Technology Vendor Management
Manhattan, NY · On-site
$165 - $185/hr
Monitor financial risk and optimize vendor costs, highlighting potential overages early to take corrective action. * Facilitate QBRs for strategic vendors to review performance, discuss progress, and ...
New
Director, Technology Vendor Management
Manhattan, NY · On-site
$165 - $185/hr
Monitor financial risk and optimize vendor costs, highlighting potential overages early to take corrective action. * Facilitate QBRs for strategic vendors to review performance, discuss progress, and ...
New
The team coordinates directly with internal business sponsors on data requirements as well as legal counsel, Technology Risk, Compliance and the Vendor Management Office - to ensure vendor solutions ...
The team coordinates directly with internal business sponsors on data requirements as well as legal counsel, Technology Risk, Compliance and the Vendor Management Office - to ensure vendor solutions ...
Vendor Manager/Professional Services Axon 911
Manhattan, NY · On-site
$146 - $163/hr
The Sr. Commodity Manager will oversee the full vendor lifecycle, including sourcing, onboarding, performance management, risk mitigation, and ongoing relationship management to ensure suppliers ...
New
Vendor Manager/Professional Services Axon 911
Manhattan, NY · On-site
$146 - $163/hr
The Sr. Commodity Manager will oversee the full vendor lifecycle, including sourcing, onboarding, performance management, risk mitigation, and ongoing relationship management to ensure suppliers ...
New
The team coordinates directly with internal business sponsors on data requirements as well as legal counsel, Technology Risk, Compliance and the Vendor Management Office - to ensure vendor solutions ...
The team coordinates directly with internal business sponsors on data requirements as well as legal counsel, Technology Risk, Compliance and the Vendor Management Office - to ensure vendor solutions ...
The team coordinates directly with internal business sponsors on data requirements as well as legal counsel, Technology Risk, Compliance and the Vendor Management Office - to ensure vendor solutions ...
The team coordinates directly with internal business sponsors on data requirements as well as legal counsel, Technology Risk, Compliance and the Vendor Management Office - to ensure vendor solutions ...
Financial risk monitoring optimizing vendor costs * Making sure we are utilizing the vendor effectively * Highlighting potential overages early enough to take corrective action QBR facilitation
Financial risk monitoring optimizing vendor costs * Making sure we are utilizing the vendor effectively * Highlighting potential overages early enough to take corrective action QBR facilitation
Vendor Risk information
See Montclair, NJ salary details
$19.66 is the 25th percentile. Wages below this are outliers.
$14.70 - $20.22
28% of jobs
The median wage is $23.52 / hr.
$20.22 - $25.74
37% of jobs
$25.74 - $31.27
6% of jobs
$34.72 is the 75th percentile. Wages above this are outliers.
$31.27 - $36.79
6% of jobs
$36.79 - $42.31
12% of jobs
$42.31 - $47.83
0% of jobs
$47.83 - $53.36
0% of jobs
$53.36 - $58.88
8% of jobs
$58.88 - $64.40
0% of jobs
$64.40 - $69.92
0% of jobs
$69.92 - $75.45
2% of jobs
$14
$30
$75
How much do vendor risk jobs pay per hour?
What is the difference between Vendor Risk vs Vendor Compliance?
| Aspect | Vendor Risk | Vendor Compliance |
|---|---|---|
| Focus | Identifying and mitigating risks associated with vendors | Ensuring vendors meet regulatory and contractual requirements |
| Certifications | Risk management certifications (e.g., CRISC, FAIR) | Compliance certifications (e.g., ISO 27001, SOC 2) |
| Work Environment | Risk assessment teams, procurement, security departments | Legal, compliance, audit teams |
| Industry Usage | Financial, healthcare, technology sectors | Financial services, healthcare, regulated industries |
Vendor Risk and Vendor Compliance roles often overlap but serve different purposes. Vendor Risk focuses on identifying and mitigating potential risks posed by vendors, while Vendor Compliance ensures vendors adhere to legal and contractual standards. Both are essential for managing vendor relationships effectively and maintaining organizational security and compliance.

Full-time
Medical, Dental, Vision, Life, PTO
Posted 23 days ago
Job description
Reflection is a research lab making intelligence open and accessible for everyone to use, customize, and build on. We build open models that let anyone control their intelligence and help shape the future of AI. Our mission: make intelligence open and accessible to all.
Role Overview
The Head of Technology & Security Engineering is responsible for architecting and operating the security engineering foundation that protects the organization's corporate environment, multi-cloud research infrastructure, and multi-million-dollar GPU training capacity. This leader owns the full technical security stack - from end-user compute and zero-trust access to cloud and container security, detection engineering, and security-as-code - ensuring the organization can move at research speed without sacrificing rigor.
Sitting at the intersection of security engineering, infrastructure, and research operations, this role is uniquely positioned to define how a frontier AI company protects its most sensitive assets - model weights, training data, and GPU capacity - while preserving the low-friction environment researchers and engineers need to do their best work. The ideal candidate brings deep, hands-on technical depth alongside the executive presence to lead a security engineering function, represent the organization's security posture to auditors and enterprise customers, and negotiate vendor and contractual risk.
This is a high-visibility, high-impact role that operates across engineering, infrastructure, legal, and physical security. Success requires the ability to design guardrails rather than gates, build systems that assume compromise, and operate credibly as both an executive leader and a hands-on builder.
What You'll Do
High-Performance End User Compute (EUC)
- Design and manage a highly resilient corporate device fleet spanning Linux, macOS, Windows and specialized hardware such as NVIDIA GPU workstations.
- Shift the fleet away from restrictive MDM policies toward intelligent posture verification and cryptographic device binding, reducing friction without reducing assurance.
- Secure diverse local toolchains and developer environments without breaking the workflows researchers and engineers depend on.
Securing the Research & Training Boundary
- Architect cloud-native security controls across multi-cloud environments that contain multi-million-dollar GPU clusters.
- Establish IAM governance, network segmentation, and isolation boundaries appropriate to the scale and sensitivity of training infrastructure and model assets.
- Partner with infrastructure and research teams to ensure security controls scale with GPU capacity rather than constrain it.
Phishing-Resistant Zero-Trust Access
- Implement continuous, context-aware authorization using modern mesh networks and proxies (e.g., Tailscale, Cloudflare One).
- Enforce hardware-backed authentication (WebAuthn/FIDO2 keys) across every corporate and production plane.
- Eliminate standing and persistent access in favor of just-in-time, verifiable authorization.
Security as Code (SaC)
- Ensure 100% of infrastructure, endpoint configurations, IAM policies, and cloud environments are declared in code (Terraform/Pulumi).
- Eliminate configuration drift through automated CI/CD validation and continuous compliance checks.
- Build repeatable, auditable deployment pipelines that make security posture provable rather than assumed.
Behavioral Detection Engineering
- Build telemetry pipelines that ingest high-fidelity logs into a cloud-native data lake to support detection at scale.
- Detect sophisticated post-exploitation techniques, lateral movement, and living-off-the-land attacks across corporate and production environments.
- Continuously tune detection coverage against an assumed-breach threat model, prioritizing time-to-detect and blast-radius containment.
Compliance, Audit & Vendor Risk
- Support SOC 2, ISO 27001, FedRAMP, ISO 22237, ISO 22301, NIST CSF, customer audits, and enterprise security reviews.
- Lead vendor risk assessments, procurement security reviews, and security-related legal contract negotiations.
- Own front-line defenses for a frontier AI company, including physical security and data center security operations.
What We're Looking For
Experience & Background
- 20+ years of deep engineering experience at high-valuation companies, or in defense-grade environments.
- Battle-tested technical leadership with a track record of building and operating security engineering functions at scale.
- Experience supporting SOC 2, ISO 27001, FedRAMP, ISO 22237, ISO 22301, NIST CSF, customer audits, and enterprise security reviews.
- Experience leading vendor risk, procurement security reviews, and legal contract negotiations.
- Experience with front-line defenses for an AI company, including physical security and data center security operations.
Skills & Capabilities
- Deep familiarity with Linux and macOS internals, including how to secure specialized hardware (NVIDIA GPUs) without breaking developer environments.
- Expert-level knowledge of public cloud architectures, IAM governance at scale, and Kubernetes/container isolation primitives.
- Technical understanding of cloud and infrastructure security, Kubernetes and container security, zero-trust architectures, security operations at scale, identity and access management, detection and response technologies, and security automation and orchestration.
- Ability to operate as both an executive leader and a hands-on builder, moving fluidly between strategy and implementation.
Mindset & Approach
- A "guardrails, not gates" philosophy - understands that blocking a researcher from pulling a Python library or mounting a filesystem means security has failed, and builds accordingly using virtualization, sandboxing, and data isolation.
- An adversarial mindset that designs systems under the assumption the endpoint will be compromised, focusing defenses on limiting blast radius, eliminating persistent access, and detecting post-compromise activity immediately.
- Motivated by building - comfortable operating in ambiguous, fast-moving environments where security infrastructure is maturing alongside a rapidly scaling research organization.
What We Offer:
We believe that to make intelligence open and accessible to all, you need to start at the foundation. Joining Reflection means building from the ground up as part of a talent-dense team. You will help define our future as a company, and help define the future of open foundational models.
We want you to do the most impactful work of your career with the confidence that you and the people you care about most are supported.
- Top-tier compensation: Salary and equity structured to recognize and retain our talent globally.
- Stock options: Everyone who joins and contributes to Reflection's success gets to share in the upside through stock options.
- Health & wellness: Comprehensive medical, dental, vision, and life, with an annual wellness allowance.
- Meals: Lunch and dinner are provided in the office daily.
- Life & family: 22 weeks paid parental leave for all new birthing and non-birthing parents, including adoptive and surrogate journeys.
- Vacation days: Unlimited paid time off in the U.S. and 30 days in the U.K.
- Sponsorship support: We sponsor visas to help exceptional talent join our team and support long-term immigration pathways where applicable.
- Team building: We have regular off-sites, happy hours, and team celebrations.
Export Control Notice: This position may require access to technology or source code subject to the U.S. Export Administration Regulations. Any offer of employment for this role may be conditioned on the Company's ability to provide the candidate with access to such technology or source code in compliance with applicable U.S. export control laws, which may require the Company to seek government authorization.