Third-Party Risk Analyst

Posted 27 Days Ago
Hiring Remotely in US
Remote
Mid level
Software
The Role
Build and run OpenRouter's third-party risk program for model providers, subprocessors, and SaaS tooling. Perform end-to-end security assessments, evaluate SOC 2/ISO reports and contracts, map vendor risk to compliance obligations (SOC 2, ISO 27001, HIPAA, GDPR, EU AI Act), implement tooling and automation, establish SLAs/tiering/monitoring, and drive risk decisions and remediation.
Summary Generated by Built In
About OpenRouter

OpenRouter is the AI routing and infrastructure layer that AI builders, AI-native startups, and enterprises use to access, manage, and optimize their AI usage through a unified API, billing interface, and analytics platform. We route billions of tokens every month and sit at the center of how organizations operationalize LLMs across research, product, and production workloads.

We are a small team that punches above its weight. Every person here has direct impact on the product and our users.

About the Role

Most third-party risk roles hand you a mature program and ask you to keep the queue moving. This is the opposite.

You'll be the first security risk analyst at OpenRouter, building the vendor risk function from a blank page. The vendors you assess aren't the usual SaaS sprawl — they're the model providers and subprocessors sitting directly in our customers' data path. And you'll do it in a regulatory environment still being written: there's no playbook for how the EU AI Act applies to an AI routing layer and its supply chain. You'll help write ours.

If you've ever finished a vendor review and thought this should take a third as long and catch twice as much — and wanted to be the one to fix it — keep reading.

What You'll Do
  • Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling — and get vendors live without becoming the bottleneck.

  • Read SOC 2 and ISO reports critically: scope, carve-outs, CUECs, exceptions, and whether the testing supports the opinion. Same for pen tests, DPAs, and subprocessor lists.

  • Turn findings into decisions — residual risk and compensating controls, not a spreadsheet of yellow cells.

  • Design and stand up the TPRM program: intake, tiering, SLAs, escalation, exceptions, and risk acceptance.

  • Pitch and implement tooling that compresses time-to-close, integrated with our GRC stack (Drata) and ticketing.

  • Build continuous monitoring for critical vendors and run annual reviews on a real cadence.

  • Map vendor risk to our SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations, including flow-down to subprocessors.

What We're Looking For
  • 4+ years in third-party/vendor security risk or security assessment — real assessment reps, not just program administration.

  • Working fluency across SOC 2, ISO 27001, HIPAA, and GDPR, plus enough command of the EU AI Act to reason about it rather than recite it.

  • Technical literacy — cloud architecture, access models, encryption, data flows — enough to know when a vendor's answer doesn't hold up.

  • Comfort with DPAs, BAAs, and security exhibits, and judgment about which clauses actually matter.

  • A bias toward shipping. You'll pitch solutions and drive implementation yourself; nobody is going to manage your day.

  • Clear writing and a high tolerance for ambiguity. When the precedent doesn't exist, you write the memo.

Nice to Have
  • Experience assessing AI/ML vendors or inference infrastructure

  • ISO 42001 or NIST AI RMF

  • Scripting and automation to eliminate your own toil

  • GRC platform administration (Drata, Vanta, or similar)

  • Time at an early-stage startup where you built the function rather than joined it

  • CISSP, CISA, CRISC, or CTPRP.

If you don't think you meet all of the criteria below but still are interested in the job, please apply. Nobody checks every box, and we're looking for someone who is excited to join the team.

Skills Required

  • 4+ years in third-party/vendor security risk or security assessment
  • Working fluency across SOC 2, ISO 27001, HIPAA, and GDPR
  • Practical familiarity with the EU AI Act sufficient to reason about vendor implications
  • Technical literacy in cloud architecture, access models, encryption, and data flows
  • Experience reading and evaluating SOC 2/ISO reports, pen tests, DPAs, BAAs, and security exhibits
  • Ability to design and stand up TPRM processes: intake, tiering, SLAs, escalation, exceptions, acceptance
  • Experience selecting or integrating tooling with a GRC stack (e.g., Drata) and ticketing systems
  • Strong written communication and comfort with ambiguity; able to draft memos and policy where precedent lacks
  • Bias toward shipping: drive implementations and close vendor reviews without heavy oversight
  • Experience assessing AI/ML vendors or inference infrastructure
  • Familiarity with ISO 42001 or NIST AI RMF
  • Scripting and automation skills to reduce manual toil
  • GRC platform administration experience (Drata, Vanta, or similar)
  • Prior experience building a function at an early-stage startup
  • Relevant certifications (CISSP, CISA, CRISC, or CTPRP)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
8 Employees
Year Founded: 2023

What We Do

A router for LLMs. 180+ models, explorable data, private chat, & a unified API. https://openrouter.ai/discord

Similar Jobs

Samsara Logo Samsara

Third-Party Risk Management Analyst

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
United States
4000 Employees
111K-167K Annually

Coursera + Udemy  Logo Coursera + Udemy

Fp&a Manager

Artificial Intelligence • Consumer Web • Edtech • Enterprise Web • HR Tech • Social Impact • Generative AI
Remote or Hybrid
United States
1500 Employees
111K-162K Annually

Alaffia Health Logo Alaffia Health

Strategic Account Manager

Artificial Intelligence • Healthtech • Insurance • Machine Learning • Payments
Remote
United States
59 Employees
90K-120K Annually

Dropbox Logo Dropbox

Software Engineering Intern (Summer 2027)

Artificial Intelligence • Cloud • Consumer Web • Productivity • Software • App development • Data Privacy
Remote
United States
2500 Employees
9K-10K Annually

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account