Third-Party Risk Analyst

OpenRouter

New York (NY)

On-site

USD 140,000 - 190,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

OpenRouter is seeking its first security risk analyst to build the vendor risk function from scratch and accelerate risk reviews for model providers, subprocessors, and SaaS tooling.

You will own end-to-end assessments, read SOC 2 and ISO reports critically, and translate findings into concrete decisions with residual risk and compensating controls. You’ll design the TPRM program and drive tooling adoption across our GRC stack.

Qualifications

  • 4+ years in third-party/vendor security risk or security assessment.
  • Fluency across SOC 2, ISO 27001, HIPAA, and GDPR; able to reason about EU AI Act.
  • Technical literacy in cloud architecture, access models, encryption, and data flows.
  • Comfort with DPAs, BAAs, and security exhibits.
  • Bias toward shipping; own and implement solutions.

Responsibilities

  • Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling.
  • Critically read SOC 2 and ISO reports, tests, and subprocessor lists.
  • Turn findings into decisions with residual risk and compensating controls.
  • Design and stand up the TPRM program with intake, tiering, SLAs, and risk acceptance.
  • Pitch and implement tooling integrated with the GRC stack (Drata) and ticketing.
  • Build continuous monitoring for critical vendors and annual reviews.
  • Map vendor risk to SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations.

Skills

Vendor risk experience
SOC 2 / ISO 27001 knowledge
Technical literacy
Clear writing

Tools

Drata
Vanta

Job description

About OpenRouter

OpenRouter is the AI routing and infrastructure layer that AI builders, AI-native startups, and enterprises use to access, manage, and optimize their AI usage through a unified API, billing interface, and analytics platform. We route billions of tokens every month and sit at the center of how organizations operationalize LLMs across research, product, and production workloads.

We are a small team that punches above its weight. Every person here has direct impact on the product and our users.

About the Role

Most third-party risk roles hand you a mature program and ask you to keep the queue moving. This is the opposite.

You’ll be the first security risk analyst at OpenRouter, building the vendor risk function from a blank page. The vendors you assess aren't the usual SaaS sprawl — they're the model providers and subprocessors sitting directly in our customers' data path. And you'll do it in a regulatory environment still being written: there's no playbook for how the EU AI Act applies to an AI routing layer and its supply chain. You'll help write ours.

If you've ever finished a vendor review and thought this should take a third as long and catch twice as much — and wanted to be the one to fix it — keep reading.

What You'll Do
  • Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling — and get vendors live without becoming the bottleneck.

  • Read SOC 2 and ISO reports critically: scope, carve-outs, CUECs, exceptions, and whether the testing supports the opinion. Same for pen tests, DPAs, and subprocessor lists.

  • Turn findings into decisions — residual risk and compensating controls, not a spreadsheet of yellow cells.

  • Design and stand up the TPRM program: intake, tiering, SLAs, escalation, exceptions, and risk acceptance.

  • Pitch and implement tooling that compresses time-to-close, integrated with our GRC stack (Drata) and ticketing.

  • Build continuous monitoring for critical vendors and run annual reviews on a real cadence.

  • Map vendor risk to our SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations, including flow-down to subprocessors.

What We’re Looking For
  • 4+ years in third-party/vendor security risk or security assessment — real assessment reps, not just program administration.

  • Working fluency across SOC 2, ISO 27001, HIPAA, and GDPR, plus enough command of the EU AI Act to reason about it rather than recite it.

  • Technical literacy — cloud architecture, access models, encryption, data flows — enough to know when a vendor's answer doesn't hold up.

  • Comfort with DPAs, BAAs, and security exhibits, and judgment about which clauses actually matter.

  • A bias toward shipping. You'll pitch solutions and drive implementation yourself; nobody is going to manage your day.

  • Clear writing and a high tolerance for ambiguity. When the precedent doesn't exist, you write the memo.

Nice to Have
  • Experience assessing AI/ML vendors or inference infrastructure

  • ISO 42001 or NIST AI RMF

  • Scripting and automation to eliminate your own toil

  • GRC platform administration (Drata, Vanta, or similar)

  • Time at an early-stage startup where you built the function rather than joined it

  • CISSP, CISA, CRISC, or CTPRP.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

First Vendor Risk Analyst for AI Infrastructure
First Vendor Risk Analyst for AI Infrastructure

OpenRouter • New York (NY)

On-site
USD 140,000 - 190,000
Third Party Risk Management Lead
Third Party Risk Management Lead

Jobtailor • Foster City (CA)

On-site
USD 150,000 - 230,000
Lead Security Analyst
Lead Security Analyst

Jobtailor • Illinois

On-site
USD 90,000 - 120,000
Director, 3rd Party Security Risk
Director, 3rd Party Security Risk

HealthEquity • United States

On-site
USD 180,000 - 260,000
Sr. Manager, Third Party Risk Management
Sr. Manager, Third Party Risk Management

Asurion • United States

On-site
USD 120,000 - 150,000
Security Third Party Risk Management Lead
Security Third Party Risk Management Lead

Cloudflare • Austin (TX)

On-site
USD 150,000 - 190,000
Manager, Third Party Risk Management
Manager, Third Party Risk Management

CrowdStrike • United States

On-site
USD 130,000 - 150,000
Market leader in compensation and equity awards
Comprehensive wellness programs
Paid parental and adoption leaves
Risk Management Analyst
Risk Management Analyst

Jobtailor • Atlanta (TX)

On-site
USD 90,000 - 130,000
Third Party Risk Management and Customer Trust Lead
Third Party Risk Management and Customer Trust Lead

Replit • Foster City (CA)

On-site
USD 180,000 - 230,000
Competitive Salary & Equity
401(k) with 4% match
Health, Dental, Vision, Life Insurance
+8
Senior Manager, Third Party Risk Management
Senior Manager, Third Party Risk Management

Jobtailor • Sterling (VA)

On-site
USD 140,000 - 190,000