About the job
About OpenSesame
OpenSesame is your trusted ally in Workforce Reinvention amidst the evolving landscape of AI. We provide integrated software solutions, curated content, and expert services to seamlessly embed learning, HR, and work systems, empowering organizations to harness their human+AI potential and flourish through transformation.
Learn more: www.opensesame.com/about
About the Role
As a Senior Security Analyst on our Compliance team, you will play a pivotal role in enhancing OpenSesame’s security framework in a dynamic, high-growth setting. We seek an individual with profound technical security knowledge, a proactive approach, and the ability to simplify intricate risks into effective, scalable solutions.
This position encompasses vulnerability management, penetration testing, bug bounty programs, cloud and application security, and audit preparedness. Collaborating with teams across Engineering, DevOps, IT, and Compliance, you will enhance security processes, support compliance initiatives, and ensure that security is ingrained in our operations, particularly as we advance our AI security methodology. We value demonstrated experience in your career that showcases your capability to manage penetration testing programs, establish vulnerability management systems, implement security automation, and guide organizations in the secure adoption of modern technologies, including AI.
You will thrive in this role if you are detail-oriented, collaborative, and eager to create programs that mitigate risks, enhance visibility, and foster safe innovation across the organization.
Performance Objectives
- Gain a comprehensive understanding of OpenSesame’s external attack surface, vulnerabilities, and threat landscape by integrating data from CrowdStrike, AWS, GCP, and application security tools.
- Oversee external penetration testing engagements from start to finish, including vendor selection, scope design, execution supervision, remediation validation, and executive reporting.
- Establish and operationalize a structured vulnerability management program in collaboration with DevOps, Engineering, and IT to effectively prioritize and mitigate risks.
- Develop scalable evidence collection and control mapping workflows using Drata to enhance audit readiness and streamline processes.
