Turn this role into an interview — a resume and cover letter built around what this employer wants.
OpenRouter seeks a hands-on compliance leader to own the program day to day, driving SOC 2, HIPAA, PCI DSS, GDPR, CCPA, BIPA and the EU AI Act. You’ll partner with Engineering, HR, Legal, and Finance to embed controls into product development and everyday operations.
You’ll manage audits, evidence collection, and ongoing training, turning evolving regulations into practical security rhythm across the company. This is a strategic builder role that rolls up sleeves.
OpenRouter is the leading AI routing and infrastructure layer that enterprises use to access, manage, and optimize the best large language models across providers—without lock-in, capacity constraints, or unnecessary cost. We power the most advanced AI teams in the world by giving them the flexibility to move fast, scale confidently, and stay future-proof as models evolve.
As enterprise adoption of AI accelerates, OpenRouter sits at the center of how organizations operationalize LLMs across research, product, and production workloads.
You own our compliance program day to day. Drata and Safebase are yours. SOC 2, HIPAA, PCI DSS, GDPR, CCPA, BIPA, and the EU AI Act are yours. You'll report to the Head of IT & Security, and you'll run the program with very little daily management.
The controls are the easy part. The real work is getting an engineer mid-sprint to pull evidence, getting the whole company through training before the deadline, and doing it in a way that makes people take your next request seriously instead of ignoring it. If your ideal job is overseeing a program that someone else operates, this is not the role for you. We are looking for a strategic builder ready to roll up their sleeves.
We also work in a space where the regulation is still being written. A meaningful share of what you'll face has no established playbook, and you'll be the person deciding what a novel requirement actually means for our business.