Job Title: Vendor Security Management
Location: Sunnyvale, CA
Duration: Contract
Role Summary
Vendor Security Management
Own the end-to-end vendor security onboarding and deployment process from initial risk assessment, security questionnaire, due diligence, approvals, and contractual security requirements through to access provisioning and ongoing monitoring
Maintain and manage the vendor security register collecting, validating, and storing critical vendor data including security certifications (SOC2, ISO 27001), insurance certificates, NDA/DPA agreements, penetration test reports, and compliance documentation
Define and enforce vendor access control policies determining appropriate access levels, access methods, and ensuring least-privilege principles are applied across all vendor engagements
Conduct periodic vendor security reviews, risk reassessments, and compliance audits across the vendor portfolio
Lead vendor offboarding and access revocation processes ensuring clean termination of all access and data handling obligations
Network Access & Connectivity
Design, implement, and manage secure vendor connectivity solutions including:
Client-to-Site VPN for individual vendor users requiring remote access to internal systems
Site-to-Site VPN for vendor organizations requiring persistent network-level connectivity
Perform VPN troubleshooting diagnosing and resolving connectivity issues including tunnel negotiation failures, authentication errors, routing problems, and latency/performance issues
Define and enforce network segmentation policies for vendor access ensuring vendors are isolated to only the systems and data they are authorized to access
Review and approve firewall rules, access control lists (ACLs), and network policies for all vendor connections
Vulnerability & Security Scanning
Utilize security scanning tools such as Qualys, Tenable, or equivalent to assess vendor-connected systems and environments for vulnerabilities
Define scanning schedules and scope for vendor environments and ensure timely remediation tracking and closure of identified vulnerabilities
Analyze scan results, generate reports, and escalate critical findings to stakeholders and vendor contacts