OpenRouter Logo

OpenRouter

Third-Party Risk Analyst

Posted One Month Ago
Remote
Hiring Remotely in US
Mid level
Remote
Hiring Remotely in US
Mid level
Build and run OpenRouter's third-party risk program for model providers, subprocessors, and SaaS tooling. Perform end-to-end security assessments, evaluate SOC 2/ISO reports and contracts, map vendor risk to compliance obligations (SOC 2, ISO 27001, HIPAA, GDPR, EU AI Act), implement tooling and automation, establish SLAs/tiering/monitoring, and drive risk decisions and remediation.
The summary above was generated by AI
About OpenRouter

OpenRouter is the AI routing and infrastructure layer that AI builders, AI-native startups, and enterprises use to access, manage, and optimize their AI usage through a unified API, billing interface, and analytics platform. We route billions of tokens every month and sit at the center of how organizations operationalize LLMs across research, product, and production workloads.

We are a small team that punches above its weight. Every person here has direct impact on the product and our users.

About the Role

Most third-party risk roles hand you a mature program and ask you to keep the queue moving. This is the opposite.

You'll be the first security risk analyst at OpenRouter, building the vendor risk function from a blank page. The vendors you assess aren't the usual SaaS sprawl — they're the model providers and subprocessors sitting directly in our customers' data path. And you'll do it in a regulatory environment still being written: there's no playbook for how the EU AI Act applies to an AI routing layer and its supply chain. You'll help write ours.

If you've ever finished a vendor review and thought this should take a third as long and catch twice as much — and wanted to be the one to fix it — keep reading.

What You'll Do
  • Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling — and get vendors live without becoming the bottleneck.

  • Read SOC 2 and ISO reports critically: scope, carve-outs, CUECs, exceptions, and whether the testing supports the opinion. Same for pen tests, DPAs, and subprocessor lists.

  • Turn findings into decisions — residual risk and compensating controls, not a spreadsheet of yellow cells.

  • Design and stand up the TPRM program: intake, tiering, SLAs, escalation, exceptions, and risk acceptance.

  • Pitch and implement tooling that compresses time-to-close, integrated with our GRC stack (Drata) and ticketing.

  • Build continuous monitoring for critical vendors and run annual reviews on a real cadence.

  • Map vendor risk to our SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations, including flow-down to subprocessors.

What We're Looking For
  • 4+ years in third-party/vendor security risk or security assessment — real assessment reps, not just program administration.

  • Working fluency across SOC 2, ISO 27001, HIPAA, and GDPR, plus enough command of the EU AI Act to reason about it rather than recite it.

  • Technical literacy — cloud architecture, access models, encryption, data flows — enough to know when a vendor's answer doesn't hold up.

  • Comfort with DPAs, BAAs, and security exhibits, and judgment about which clauses actually matter.

  • A bias toward shipping. You'll pitch solutions and drive implementation yourself; nobody is going to manage your day.

  • Clear writing and a high tolerance for ambiguity. When the precedent doesn't exist, you write the memo.

Nice to Have
  • Experience assessing AI/ML vendors or inference infrastructure

  • ISO 42001 or NIST AI RMF

  • Scripting and automation to eliminate your own toil

  • GRC platform administration (Drata, Vanta, or similar)

  • Time at an early-stage startup where you built the function rather than joined it

  • CISSP, CISA, CRISC, or CTPRP.

If you don't think you meet all of the criteria below but still are interested in the job, please apply. Nobody checks every box, and we're looking for someone who is excited to join the team.

Similar Jobs

Yesterday
Easy Apply
Remote or Hybrid
United States
Easy Apply
70K-138K Annually
Mid level
70K-138K Annually
Mid level
Big Data • Cloud • Software • Database
Supports the third-party risk management lifecycle by applying risk methodologies, assessing standard vendor relationships, reviewing documentation, coordinating stakeholder and subject matter expert reviews, tracking remediation, maintaining assessment records, and preparing status reports. The role performs data-quality checks, communicates with third parties regarding lower-risk gaps, escalates complex or high-risk issues, and contributes to TPRM process improvements and audit readiness.
Top Skills: CaiqCcpaDoraFedrampGdprGraphite ConnectIso 27001JIRANis2Nist Sp 800-53OccPci-DssSig Core/LiteSoc 2
19 Days Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
111K-167K Annually
Senior level
111K-167K Annually
Senior level
Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Own end-to-end third-party security risk assessments, vendor tiering, reassessments, remediation tracking, and contract security reviews. Partner with Legal, Procurement, and business owners; support ISO, SOC, and FedRAMP audits; escalate unresolved risks; and maintain dashboards reporting third-party risk posture. The role also supports automation and AI-enabled vendor risk workflows and mentors junior team members.
Top Skills: Ai-Enabled AutomationArcherFedrampIso 27001Nist CsfOnetrustServicenowSoc 2VantaZip
6 Minutes Ago
Remote
Texas, USA
150K-170K Annually
Senior level
150K-170K Annually
Senior level
Artificial Intelligence • Fintech • Information Technology • Logistics • Payments • Business Intelligence • Generative AI
The Senior Account Director, Enterprise role at Coupa focuses on managing enterprise customer accounts and driving adoption of Coupa’s AI-powered total spend management platform. The provided description contains limited role-specific responsibilities, but the position likely involves strategic account leadership, customer relationship management, and supporting business growth within enterprise accounts.
Top Skills: AITotal Spend Management Platform

What you need to know about the Seattle Tech Scene

Home to tech titans like Microsoft and Amazon, Seattle punches far above its weight in innovation. But its surrounding mountains, sprinkled with world-famous hiking trails and climbing routes, make the city a destination for outdoorsy types as well. Established as a logging town before shifting to shipbuilding and logistics, the Emerald City is now known for its contributions to aerospace, software, biotech and cloud computing. And its status as a thriving tech ecosystem is attracting out-of-town companies looking to establish new tech and engineering hubs.

Key Facts About Seattle Tech

  • Number of Tech Workers: 287,000; 13% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Amazon, Microsoft, Meta, Google
  • Key Industries: Artificial intelligence, cloud computing, software, biotechnology, game development
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Madrona, Fuse, Tola, Maveron
  • Research Centers and Universities: University of Washington, Seattle University, Seattle Pacific University, Allen Institute for Brain Science, Bill & Melinda Gates Foundation, Seattle Children’s Research Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account