First Vendor Risk Analyst for AI Infrastructure

OpenRouter

New York (NY)

On-site

USD 140,000 - 190,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

OpenRouter is seeking its first security risk analyst to build the vendor risk function from scratch and accelerate risk reviews for model providers, subprocessors, and SaaS tooling.

You will own end-to-end assessments, read SOC 2 and ISO reports critically, and translate findings into concrete decisions with residual risk and compensating controls. You’ll design the TPRM program and drive tooling adoption across our GRC stack.

Qualifications

  • 4+ years in third-party/vendor security risk or security assessment.
  • Fluency across SOC 2, ISO 27001, HIPAA, and GDPR; able to reason about EU AI Act.
  • Technical literacy in cloud architecture, access models, encryption, and data flows.
  • Comfort with DPAs, BAAs, and security exhibits.
  • Bias toward shipping; own and implement solutions.

Responsibilities

  • Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling.
  • Critically read SOC 2 and ISO reports, tests, and subprocessor lists.
  • Turn findings into decisions with residual risk and compensating controls.
  • Design and stand up the TPRM program with intake, tiering, SLAs, and risk acceptance.
  • Pitch and implement tooling integrated with the GRC stack (Drata) and ticketing.
  • Build continuous monitoring for critical vendors and annual reviews.
  • Map vendor risk to SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations.

Skills

Vendor risk experience
SOC 2 / ISO 27001 knowledge
Technical literacy
Clear writing

Tools

Drata
Vanta

Job description

OpenRouter is seeking its first security risk analyst to build the vendor risk function from scratch and accelerate risk reviews for model providers, subprocessors, and SaaS tooling.

You will own end-to-end assessments, read SOC 2 and ISO reports critically, and translate findings into concrete decisions with residual risk and compensating controls. You’ll design the TPRM program and drive tooling adoption across our GRC stack.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Third-Party Risk Analyst
Third-Party Risk Analyst

OpenRouter • New York (NY)

On-site
USD 140,000 - 190,000
Senior Third-Party Risk Analyst – Security GRC
Senior Third-Party Risk Analyst – Security GRC

Anthropic • United States

Hybrid
USD 255,000 - 270,000
Competitive compensation
Generous vacation & parental leave
Equity donation matching
+1
AI Vendor Security Program Lead
AI Vendor Security Program Lead

Sierra • California (MO)

On-site
USD 180,000 - 240,000
Unlimited PTO
Medical, dental, vision benefits
Life insurance
+3
Senior Enterprise AI Product Manager
Senior Enterprise AI Product Manager

OpenRouter • New York (NY)

On-site
USD 160,000 - 230,000
TPRM Security Analyst: Ecosystem Risk
TPRM Security Analyst: Ecosystem Risk

Plaid Inc • New York (NY)

On-site
USD 120,000 - 180,000
Senior TPRM & AI Security Analyst
Senior TPRM & AI Security Analyst

DoorDash • San Francisco (CA)

On-site
USD 132,000 - 195,000
401(k) with employer matching
Paid parental leave
Wellness benefits
+7
Senior TPRM & AI Security Analyst
Senior TPRM & AI Security Analyst

DoorDash • New York (NY)

On-site
USD 132,000 - 195,000
AI‑Powered Third-Party Risk Analyst
AI‑Powered Third-Party Risk Analyst

Plaid • North Carolina

On-site
USD 119,000 - 176,000
Equity
401(k) plan
Medical benefits
+2
Remote Security Risk Architect TPRM & Automation
Remote Security Risk Architect TPRM & Automation

Affirm • Madison (WI)

On-site
USD 115,000 - 165,000
Health care coverage
Flexible Spending Wallets
Time off
+1
Remote TPRM Security Risk Engineer
Remote TPRM Security Risk Engineer

Affirm • St. Louis (MO)

On-site
USD 115,000 - 165,000
Health coverage
Dental & vision
ESPP
+1