OpenRouter Logo

OpenRouter

Third-Party Risk Analyst

Posted One Month Ago
Remote
Hiring Remotely in US
Mid level
Remote
Hiring Remotely in US
Mid level
Build and run OpenRouter's third-party risk program for model providers, subprocessors, and SaaS tooling. Perform end-to-end security assessments, evaluate SOC 2/ISO reports and contracts, map vendor risk to compliance obligations (SOC 2, ISO 27001, HIPAA, GDPR, EU AI Act), implement tooling and automation, establish SLAs/tiering/monitoring, and drive risk decisions and remediation.
The summary above was generated by AI
About OpenRouter

OpenRouter is the AI routing and infrastructure layer that AI builders, AI-native startups, and enterprises use to access, manage, and optimize their AI usage through a unified API, billing interface, and analytics platform. We route billions of tokens every month and sit at the center of how organizations operationalize LLMs across research, product, and production workloads.

We are a small team that punches above its weight. Every person here has direct impact on the product and our users.

About the Role

Most third-party risk roles hand you a mature program and ask you to keep the queue moving. This is the opposite.

You'll be the first security risk analyst at OpenRouter, building the vendor risk function from a blank page. The vendors you assess aren't the usual SaaS sprawl — they're the model providers and subprocessors sitting directly in our customers' data path. And you'll do it in a regulatory environment still being written: there's no playbook for how the EU AI Act applies to an AI routing layer and its supply chain. You'll help write ours.

If you've ever finished a vendor review and thought this should take a third as long and catch twice as much — and wanted to be the one to fix it — keep reading.

What You'll Do
  • Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling — and get vendors live without becoming the bottleneck.

  • Read SOC 2 and ISO reports critically: scope, carve-outs, CUECs, exceptions, and whether the testing supports the opinion. Same for pen tests, DPAs, and subprocessor lists.

  • Turn findings into decisions — residual risk and compensating controls, not a spreadsheet of yellow cells.

  • Design and stand up the TPRM program: intake, tiering, SLAs, escalation, exceptions, and risk acceptance.

  • Pitch and implement tooling that compresses time-to-close, integrated with our GRC stack (Drata) and ticketing.

  • Build continuous monitoring for critical vendors and run annual reviews on a real cadence.

  • Map vendor risk to our SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations, including flow-down to subprocessors.

What We're Looking For
  • 4+ years in third-party/vendor security risk or security assessment — real assessment reps, not just program administration.

  • Working fluency across SOC 2, ISO 27001, HIPAA, and GDPR, plus enough command of the EU AI Act to reason about it rather than recite it.

  • Technical literacy — cloud architecture, access models, encryption, data flows — enough to know when a vendor's answer doesn't hold up.

  • Comfort with DPAs, BAAs, and security exhibits, and judgment about which clauses actually matter.

  • A bias toward shipping. You'll pitch solutions and drive implementation yourself; nobody is going to manage your day.

  • Clear writing and a high tolerance for ambiguity. When the precedent doesn't exist, you write the memo.

Nice to Have
  • Experience assessing AI/ML vendors or inference infrastructure

  • ISO 42001 or NIST AI RMF

  • Scripting and automation to eliminate your own toil

  • GRC platform administration (Drata, Vanta, or similar)

  • Time at an early-stage startup where you built the function rather than joined it

  • CISSP, CISA, CRISC, or CTPRP.

If you don't think you meet all of the criteria below but still are interested in the job, please apply. Nobody checks every box, and we're looking for someone who is excited to join the team.

Similar Jobs

2 Days Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
70K-138K Annually
Mid level
70K-138K Annually
Mid level
Big Data • Cloud • Software • Database
Supports the third-party risk management lifecycle by applying risk methodologies, assessing standard vendor relationships, reviewing documentation, coordinating stakeholder and subject matter expert reviews, tracking remediation, maintaining assessment records, and preparing status reports. The role performs data-quality checks, communicates with third parties regarding lower-risk gaps, escalates complex or high-risk issues, and contributes to TPRM process improvements and audit readiness.
Top Skills: CaiqCcpaDoraFedrampGdprGraphite ConnectIso 27001JIRANis2Nist Sp 800-53OccPci-DssSig Core/LiteSoc 2
20 Days Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
111K-167K Annually
Senior level
111K-167K Annually
Senior level
Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Own end-to-end third-party security risk assessments, vendor tiering, reassessments, remediation tracking, and contract security reviews. Partner with Legal, Procurement, and business owners; support ISO, SOC, and FedRAMP audits; escalate unresolved risks; and maintain dashboards reporting third-party risk posture. The role also supports automation and AI-enabled vendor risk workflows and mentors junior team members.
Top Skills: Ai-Enabled AutomationArcherFedrampIso 27001Nist CsfOnetrustServicenowSoc 2VantaZip
55 Minutes Ago
Remote or Hybrid
3 Locations
97K-134K Annually
Entry level
97K-134K Annually
Entry level
Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Assess information security risks, test security systems, apply cybersecurity standards and policies, implement security technologies, and provide day-to-day business support. Analyze logs, support SOC operations, document findings, assist with compliance and risk management, manage third-party security providers when applicable, and deliver security awareness training. Collaborate with technical teams and leaders to maintain the security of information and IT assets.
Top Skills: Information Security SystemsLog AnalysisNetworkingSIEMSoar

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account