OpenRouter Logo

OpenRouter

Third-Party Risk Analyst

Posted One Month Ago
Remote
Hiring Remotely in US
Mid level
Remote
Hiring Remotely in US
Mid level
Build and run OpenRouter's third-party risk program for model providers, subprocessors, and SaaS tooling. Perform end-to-end security assessments, evaluate SOC 2/ISO reports and contracts, map vendor risk to compliance obligations (SOC 2, ISO 27001, HIPAA, GDPR, EU AI Act), implement tooling and automation, establish SLAs/tiering/monitoring, and drive risk decisions and remediation.
The summary above was generated by AI
About OpenRouter

OpenRouter is the AI routing and infrastructure layer that AI builders, AI-native startups, and enterprises use to access, manage, and optimize their AI usage through a unified API, billing interface, and analytics platform. We route billions of tokens every month and sit at the center of how organizations operationalize LLMs across research, product, and production workloads.

We are a small team that punches above its weight. Every person here has direct impact on the product and our users.

About the Role

Most third-party risk roles hand you a mature program and ask you to keep the queue moving. This is the opposite.

You'll be the first security risk analyst at OpenRouter, building the vendor risk function from a blank page. The vendors you assess aren't the usual SaaS sprawl — they're the model providers and subprocessors sitting directly in our customers' data path. And you'll do it in a regulatory environment still being written: there's no playbook for how the EU AI Act applies to an AI routing layer and its supply chain. You'll help write ours.

If you've ever finished a vendor review and thought this should take a third as long and catch twice as much — and wanted to be the one to fix it — keep reading.

What You'll Do
  • Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling — and get vendors live without becoming the bottleneck.

  • Read SOC 2 and ISO reports critically: scope, carve-outs, CUECs, exceptions, and whether the testing supports the opinion. Same for pen tests, DPAs, and subprocessor lists.

  • Turn findings into decisions — residual risk and compensating controls, not a spreadsheet of yellow cells.

  • Design and stand up the TPRM program: intake, tiering, SLAs, escalation, exceptions, and risk acceptance.

  • Pitch and implement tooling that compresses time-to-close, integrated with our GRC stack (Drata) and ticketing.

  • Build continuous monitoring for critical vendors and run annual reviews on a real cadence.

  • Map vendor risk to our SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations, including flow-down to subprocessors.

What We're Looking For
  • 4+ years in third-party/vendor security risk or security assessment — real assessment reps, not just program administration.

  • Working fluency across SOC 2, ISO 27001, HIPAA, and GDPR, plus enough command of the EU AI Act to reason about it rather than recite it.

  • Technical literacy — cloud architecture, access models, encryption, data flows — enough to know when a vendor's answer doesn't hold up.

  • Comfort with DPAs, BAAs, and security exhibits, and judgment about which clauses actually matter.

  • A bias toward shipping. You'll pitch solutions and drive implementation yourself; nobody is going to manage your day.

  • Clear writing and a high tolerance for ambiguity. When the precedent doesn't exist, you write the memo.

Nice to Have
  • Experience assessing AI/ML vendors or inference infrastructure

  • ISO 42001 or NIST AI RMF

  • Scripting and automation to eliminate your own toil

  • GRC platform administration (Drata, Vanta, or similar)

  • Time at an early-stage startup where you built the function rather than joined it

  • CISSP, CISA, CRISC, or CTPRP.

If you don't think you meet all of the criteria below but still are interested in the job, please apply. Nobody checks every box, and we're looking for someone who is excited to join the team.

Similar Jobs

8 Days Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
70K-138K Annually
Mid level
70K-138K Annually
Mid level
Big Data • Cloud • Software • Database
Supports the third-party risk management lifecycle by applying risk methodologies, assessing standard vendor relationships, reviewing documentation, coordinating stakeholder and subject matter expert reviews, tracking remediation, maintaining assessment records, and preparing status reports. The role performs data-quality checks, communicates with third parties regarding lower-risk gaps, escalates complex or high-risk issues, and contributes to TPRM process improvements and audit readiness.
Top Skills: CaiqCcpaDoraFedrampGdprGraphite ConnectIso 27001JIRANis2Nist Sp 800-53OccPci-DssSig Core/LiteSoc 2
32 Minutes Ago
Remote or Hybrid
192K-300K Annually
Expert/Leader
192K-300K Annually
Expert/Leader
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Chief of Staff to the GVP of Moveworks Sales, owning sales strategy, operating metrics, specialist productivity, sales plays, forecasting cadence, cross-functional alignment, and executive narratives. The role drives Employee Experience revenue performance, accelerates specialist ramp, coordinates Product, Marketing, Enablement, and Customer Success dependencies, and provides data-backed recommendations to senior leaders and board forums. It is remote within a major U.S. metro with approximately monthly travel.
Top Skills: AI
33 Minutes Ago
Remote or Hybrid
172K-301K Annually
Senior level
172K-301K Annually
Senior level
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Architect, develop, optimize, and maintain AI-enhanced access security features and backend services. Integrate LLMs and AI workflows for identity intelligence, risk detection, and remediation. Lead architecture, design, testing, performance, reliability, and production readiness for enterprise systems. Deliver features end to end, collaborate cross-functionally, conduct code reviews, and mentor engineers while improving scalability, maintainability, and security.
Top Skills: AnthropicAWSAzureCi/CdDockerGCPGoGoogle AiGraphQLGrpcIdentity And Access ManagementIdentity Governance And AdministrationJavaKubernetesLlm FrameworksNeo4JOpenaiPostgresPrivileged Access ManagementPythonRestSQL

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account