Vendor Security Lead
Job Summary
This role involves managing and improving Pinterest’s vendor security program by conducting security assessments, collaborating with cross-functional teams, and driving risk mitigation initiatives. The ideal candidate has extensive experience in vendor security risk analysis, program management, and familiarity with compliance frameworks such as GDPR and SOC2. Strong communication, leadership skills, and the ability to work independently are essential. The position offers a hybrid work arrangement with an emphasis on collaboration and includes benefits aligned with Pinterest's inclusive workplace culture.
Required Skills
Benefits
Job Description
About Pinterest:
Millions of people around the world come to our platform to find creative ideas, dream about new possibilities and plan for memories that will last a lifetime. At Pinterest, we’re on a mission to bring everyone the inspiration to create a life they love, and that starts with the people behind the product.
Discover a career where you ignite innovation for millions, transform passion into growth opportunities, celebrate each other’s unique experiences and embrace the flexibility to do your best work. Creating a career you love? It’s Possible.
Pinterest’s Security team (Pinfosec) is seeking an experienced program manager to drive vendor and third-party security initiatives to keep our users, employees, and infrastructure safe from third-party risk. You will have the opportunity to lead and improve our vendor security program and provide meaningful impact in minimizing risk for Pinterest. You’re passionate about security innovation, and able to vet third-party solutions while minimizing employee friction and maximizing productivity.
What you’ll do:
- Perform vendor security assessments in order to minimize risk from third-party services
- Maintain and improve vendor security program while working closely with Security, Legal, IT and other internal stakeholders
- Ensure vendor security issues are identified, communicated, and remediated to an acceptable level of risk
- Interface with other teams and take a leadership role in driving vendor security initiatives
- Manage a team of contractors to deliver the vendor security assessments and have oversight over their Security assessment work
- Conduct periodic reviews of the Vendor Security program to identify areas for improvement and automation and help ensure alignment with key business risks, regulatory requirements, and industry frameworks; revise program documentation as required and communicate program changes to key stakeholders to achieve buy-in
- Drive accurate program metrics through timely updates and thorough documentation of each completed assessment and coaching team members on the same
- Work closely with technology and legal partners and business units to ensure appropriate security and data protection requirements are incorporated into third-party engagements
What we’re looking for:
- 5+ years experience performing vendor security risk analysis for new and existing vendors
- 3+ years of experience managing an effective Vendor Security program
- Experience designing, managing, and building security programs and best practices
- Familiarity with compliance frameworks (e.g. PCI, GDPR, SOC2, ISO27001)
- Good understanding of various security domains
- Strong sense of ownership and comfortable with autonomy and ambiguity
- Great communicator who is comfortable leading meetings and audit type interviews with vendors
- Bachelors level degree in Computer Science or cognitive discipline, or equivalent cyber security industry experience.
In-Office Requirement Statement:
- We let the type of work you do guide the collaboration style. That means we're not always working in an office, but we continue to gather for key moments of collaboration and connection.
- This role will need to be in the office for in-person collaboration 1-2 times every 6-months, and therefore can be situated anywhere in the country.
Relocation Statement:
- This position is not eligible for relocation assistance. Visit our PinFlex page to learn more about our working model.
#LI-HYBRID
#LI-AH2
At Pinterest we believe the workplace should be equitable, inclusive, and inspiring for every employee. In an effort to provide greater transparency, we are sharing the base salary range for this position. The position is also eligible for equity. Final salary is based on a number of factors including location, travel, relevant prior experience, or particular skills and expertise.
Information regarding the culture at Pinterest and benefits available for this position can be found here.
Our Commitment to Inclusion:
Safe Remote Job Search Tips
Verify Employer Thoroughly
Research the company's identity thoroughly before applying. Check for a professional website with contacts, active social media, and LinkedIn profiles. Verify details across platforms and look for reviews on Glassdoor or Trustpilot to confirm legitimacy.
Never Pay to Get a Job
Legitimate employers never require payment for applications, training, background checks, or equipment. Always reject upfront payment requests or demands for bank details, even if they claim it's for purchasing necessary work gear on your behalf.
Safeguard Your Personal Information
Protect sensitive data like SSN, bank details, or ID copies. Share this only after accepting a formal, written job offer. Ensure it's submitted via a secure company system or portal, never through insecure channels like standard email attachments.
Scrutinize Communication & Interviews
Watch for communication red flags: poor grammar, generic emails (@gmail), vague details, or undue pressure. Be highly suspicious of interviews held only via text or chat apps; legitimate companies typically use video or phone calls.
Beware of Unrealistic Offers
If an offer's salary or benefits seem unrealistically high for the work involved, be cautious. Research standard pay for similar roles. Offers that appear 'too good to be true' are often scams designed to lure you into providing information or payment.
Insist on a Formal Contract
Always secure and review a formal, written job offer or employment contract before starting work or sharing final personal details. Ensure it clearly defines your role, compensation, key terms, and conditions to avoid misunderstandings or scams.