yandex
pinterest
Страна
США
Зарплата
123 696 $ – 216 468 $
+500% приглашений

Откликайтесь
на вакансии с ИИ

Ускорим процесс поиска работы
УдалённоПолная занятость

Vendor Security Analyst

Оценка ИИ

Высокая оценка обусловлена сильным брендом компании, прозрачным и конкурентным диапазоном зарплаты, а также гибким форматом работы (PinFlex). Роль предлагает интересные задачи на стыке безопасности и ИИ.


Вакансия из Quick Offer Global, списка международных компаний
Пожаловаться

Сложность вакансии

ЛегкоСложно
Оценка ИИ

Роль требует более 3 лет опыта в оценке рисков и глубокого знания комплаенс-фреймворков (SOC2, GDPR). Хотя навыки программирования не требуются, необходима высокая автономность и умение работать с MSSP и сложными инструментами вроде Onspring.

Анализ зарплаты

Медиана155 000 $
Рынок115 000 $ – 195 000 $
Оценка ИИ

Предлагаемый диапазон $123k – $216k находится на уровне или выше рыночных показателей для опытных аналитиков по безопасности вендоров в США, особенно учитывая возможность удаленной работы. Верхняя граница диапазона соответствует уровню Senior/Lead в крупных технологических компаниях.

Сопроводительное письмо

I am writing to express my interest in the Vendor Security Analyst position at Pinterest. With over three years of experience in conducting comprehensive third-party risk assessments and a deep understanding of compliance frameworks like SOC2 and ISO27001, I am confident in my ability to strengthen Pinterest’s security posture. My background includes not only identifying and remediating vendor-related risks but also collaborating with cross-functional teams to ensure that security initiatives align with business productivity.

I am particularly drawn to Pinterest’s innovative approach to integrating AI into the security workflow. In my previous roles, I have acted as a subject matter expert for high-priority reviews and managed risk registers to ensure transparency and accountability. I am eager to bring my expertise in GRC and vendor management to Pinfosec, helping to maintain the trust of your global community while fostering a culture of security innovation.

+250% к просмотрам

Составьте идеальное письмо к вакансии с ИИ-агентом

Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в pinterest уже сейчас

Присоединяйтесь к команде безопасности Pinterest и помогите защитить миллионы пользователей, управляя рисками сторонних сервисов!

Описание вакансии

About Pinterest:

Millions of people around the world come to our platform to find creative ideas, dream about new possibilities and plan for memories that will last a lifetime. At Pinterest, we’re on a mission to bring everyone the inspiration to create a life they love, and that starts with the people behind the product.

Discover a career where you ignite innovation for millions, transform passion into growth opportunities, celebrate each other’s unique experiences and embrace the flexibility to do your best work. Creating a career you love? It’s Possible.

At Pinterest, AI isn't just a feature, it's a powerful partner that augments our creativity and amplifies our impact, and we’re looking for candidates who are excited to be a part of that. To get a complete picture of your experience and abilities, we’ll explore your foundational skills and how you collaborate with AI.

Through our interview process, what matters most is that you can always explain your approach, showing us not just what you know, but how you think. You can read more about our AI interview philosophy and how we use AI in our recruiting process here.

Pinterest’s Security team (Pinfosec) is seeking an experienced Vendor Security Analyst to conduct assessments of our vendors and help drive vendor and third-party security initiatives to keep our users, employees, and infrastructure safe from third-party security risk. You will have the opportunity to support the improvement of our vendor security program and GRC initiatives and provide meaningful impact in minimizing risk for Pinterest. You’re passionate about security innovation, and able to vet third-party solutions while minimizing employee friction and maximizing productivity.

What you’ll do:

  • Perform vendor security assessments in order to minimize risk from third-party services
  • Support the Vendor Security lead to Maintain and improve the vendor security program while working closely with Security, Legal, IT and other internal stakeholders
  • Ensure vendor security issues are identified, communicated, and remediated to an acceptable level of risk
  • Act as the SME for High Priority Vendor Security Reviews (e.g. AI related tooling)
  • Interface with other teams and take a leadership role in driving vendor security initiatives
  • Manage the MSSP for Vendor Security when the Vendor Security Lead is unavailable
  • Act as the Vendor Security SME for the Onspring Risk Register and manage the maintenance and updating of Vendor Security related exceptions
  • Support Pinterest’s Security Governance, Risk & Compliance program on an ad hoc basis such as; Be responsible for the monthly review and maintenance of security awareness training metrics, assist in the update of security policies from time to time, assist in the audit evidence gathering for SOC 2 Type 2 compliance as required, assist in the completion of security questionnaires from Pinterest’s advertisers
  • You will be required to have a thorough understanding of security concepts, but you will not need to have coding experience

What we are looking for:

  • 3+ years experience performing vendor security risk analysis for new and existing vendors
  • Experience supporting the design, management, and building of security programs and best practices
  • Familiarity with compliance frameworks (e.g. PCI, GDPR, SOC2, ISO27001, NIST CSF)
  • Good understanding of various security domains
  • Strong sense of ownership and comfortable with autonomy and ambiguity
  • Great communicator who is comfortable leading meetings and audit type interviews with vendors
  • Bachelor’s degree in a relevant field such as Computer Science, Engineering, or other cognitive function, or equivalent experience

In-Office Requirement Statement:

  • We let the type of work you do guide the collaboration style. That means we're not always working in an office, but we continue to gather for key moments of collaboration and connection.
  • This role will need to be in the office for in-person collaboration 1-2 times/quarter and therefore can be situated anywhere in the country.

Relocation Statement:

  • This position is not eligible for relocation assistance. Visit ourPinFlex page to learn more about our working model.

 #LI-HYBRID

#LI-AH2

At Pinterest we believe the workplace should be equitable, inclusive, and inspiring for every employee. In an effort to provide greater transparency, we are sharing the base salary range for this position. The position is also eligible for equity. Final salary is based on a number of factors including location, travel, relevant prior experience, or particular skills and expertise.

Information regarding the culture at Pinterest and benefits available for this position can be found here.

US based applicants only

$123,696—$216,468 USD

Our Commitment to Inclusion:

Pinterest is an equal opportunity employer and makes employment decisions on the basis of merit. We want to have the best qualified people in every job. All qualified applicants will receive consideration for employment without regard to race, color, ancestry, national origin, religion or religious creed, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, age, marital status, status as a protected veteran, physical or mental disability, medical condition, genetic information or characteristics (or those of a family member) or any other consideration made unlawful by applicable federal, state or local laws. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you require a medical or religious accommodation during the job application process, please complete this form for support.

+400% к собеседованиям

Создайте идеальное резюме с помощью ИИ-агента

Создайте идеальное резюме с помощью ИИ-агента

Навыки

  • Vendor Risk Management
  • GRC
  • SOC 2
  • ISO 27001
  • GDPR
  • PCI DSS
  • NIST CSF
  • Cybersecurity
  • Risk Assessment

Возможные вопросы на собеседовании

Проверка практического опыта оценки рисков и понимания стандартов безопасности.

Опишите ваш процесс проведения оценки безопасности нового вендора: на какие ключевые области вы обращаете внимание в первую очередь?

Вакансия предполагает роль SME по безопасности ИИ-инструментов.

Какие специфические риски безопасности вы бы выделили при оценке стороннего сервиса, использующего генеративный ИИ?

Важно уметь находить баланс между безопасностью и потребностями бизнеса.

Как вы поступаете в ситуации, когда бизнес-подразделению критически необходим инструмент вендора, который не прошел вашу проверку безопасности?

Вакансия включает поддержку SOC 2 Type 2 и других аудитов.

Расскажите о вашем опыте подготовки доказательной базы для аудитов соответствия (например, SOC 2 или ISO 27001).

Оценка коммуникативных навыков и способности вести переговоры.

Приведите пример, когда вам пришлось убеждать вендора внедрить дополнительные меры контроля безопасности. Как вы выстраивали аргументацию?

Похожие вакансии

SDOdev
380 000 ₽ – 500 000 ₽

Senior Android Security / Reverse Engineer (HTTPS Traffic, Google Services)

SeniorУдалённоРоссия
Android · iOS · TCP/IP · HTTPS · Cryptography · MITM · Frida · Objection · Apktool · Jadx · Hopper · Smali · Hermes · Swift · Dart · Objective-C · C++ · Reverse Engineering · Cybersecurity
+19 навыков
Operation Zero
450 000 ₽ – 900 000 ₽

Исследователь безопасности Android

УдалённоРоссия
Android · Reverse Engineering · Exploit Development · Kernel Research · C++ · ARM Assembly · Java · Ghidra · IDA Pro · Linux Kernel · Kotlin · JavaScript
+12 навыков
NDA
250 000 ₽ – 450 000 ₽

Эксперт по защите периметра (WAF)

УдалённоРоссия
WAF · Wallarm · Positive Technologies Application Firewall · NGFW · IPS · Vulnerability Assessment · Network Security
+7 навыков
Квазар
до 350 000 ₽

DevOps-инженер/ИБ (devops engineer, information security)

УдалённоРоссия
TCP/IP · DNS · DHCP · HTTPS · SMTP · BGP · OSPF · VLAN · NAT · Zero Trust · RBAC · SIEM · Zabbix · ELK · Wazuh · Grafana · Bash · PowerShell · Python · VMware · Proxmox · Hyper-V · KVM · SoC
+24 навыков
Атом Безопасность
200 000 ₽ – 400 000 ₽

Application Security Еngineer (AppSec)

УдалённоРоссия
C++ · Rust · JavaScript · Python · TypeScript · SAST · DAST · SCA · ASOC · CI/CD · GitLab CI · Docker · Fuzzing · Threat Modeling
+14 навыков
ХАКСКИ КОНСАЛТИНГ
280 000 ₽ – 350 000 ₽

Инженер по сетевой безопасности

УдалённоРоссия
NGFW · UTM · Proxy · IDS · IPS · VPN · ACL · iptables · Routing · Switching · Network Security · IP
+12 навыков
более 1000 офферов получено
4.9

1000+ офферов получено

Устали искать работу? Мы найдём её за вас

Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!

pinterest
Страна
США
Зарплата
123 696 $ – 216 468 $