OpenRouter logo

Third-Party Risk Analyst (Remote)

OpenRouter
Remote
Remote· about 2 hours ago

Straight from OpenRouter’s careers page. Apply on the company site — no recruiter, no middleman.

Third-Party Risk Analyst

Department: Engineering

Location: Remote (US)

Employment Type: FullTime

About OpenRouter

OpenRouter is the AI routing and infrastructure layer that AI builders, AI-native startups, and enterprises use to access, manage, and optimize their AI usage through a unified API, billing interface, and analytics platform. We route billions of tokens every month and sit at the center of how organizations operationalize LLMs across research, product, and production workloads.

We are a small team that punches above its weight. Every person here has direct impact on the product and our users.

About the Role

Most third-party risk roles hand you a mature program and ask you to keep the queue moving. This is the opposite.

Youll be the first security risk analyst at OpenRouter, building the vendor risk function from a blank page. The vendors you assess arent the usual SaaS sprawl — theyre the model providers and subprocessors sitting directly in our customers data path. And youll do it in a regulatory environment still being written: theres no playbook for how the EU AI Act applies to an AI routing layer and its supply chain. Youll help write ours.

If youve ever finished a vendor review and thought this should take a third as long and catch twice as much — and wanted to be the one to fix it — keep reading.

What Youll Do

  • Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling — and get vendors live without becoming the bottleneck.

  • Read SOC 2 and ISO reports critically: scope, carve-outs, CUECs, exceptions, and whether the testing supports the opinion. Same for pen tests, DPAs, and subprocessor lists.

  • Turn findings into decisions — residual risk and compensating controls, not a spreadsheet of yellow cells.

  • Design and stand up the TPRM program: intake, tiering, SLAs, escalation, exceptions, and risk acceptance.

  • Pitch and implement tooling that compresses time-to-close, integrated with our GRC stack (Drata) and ticketing.

  • Build continuous monitoring for critical vendors and run annual reviews on a real cadence.

  • Map vendor risk to our SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations, including flow-down to subprocessors.

What Were Looking For

  • 4+ years in third-party/vendor security risk or security assessment — real assessment reps, not just program administration.

  • Working fluency across SOC 2, ISO 27001, HIPAA, and GDPR, plus enough command of the EU AI Act to reason about it rather than recite it.

  • Technical literacy — cloud architecture, access models, encryption, data flows — enough to know when a vendors answer doesnt hold up.

  • Comfort with DPAs, BAAs, and security exhibits, and judgment about which clauses actually matter.

  • A bias toward shipping. Youll pitch solutions and drive implementation yourself; nobody is going to manage your day.

  • Clear writing and a high tolerance for ambiguity. When the precedent doesnt exist, you write the memo.

Nice to Have

  • Experience assessing AI/ML vendors or inference infrastructure

  • ISO 42001 or NIST AI RMF

  • Scripting and automation to eliminate your own toil

  • GRC platform administration (Drata, Vanta, or similar)

  • Time at an early-stage startup where you built the function rather than joined it

  • CISSP, CISA, CRISC, or CTPRP.

If you dont think you meet all of the criteria below but still are interested in the job, please apply. Nobody checks every box, and were looking for someone who is excited to join the team.

Similar remote jobs

More like this →
Root Insurance logo

Root Insurance

Senior Security Engineer

Remote
$112k–$139k
✓ From careers page· about 3 hours ago
Datavant logo

Datavant

Senior Site Reliability Engineer (Remote)

Remote
$168k–$200k
✓ From careers page· about 5 hours ago
Lob logo

Lob

Staff Security Engineer

Remote
$198k–$220k
✓ From careers page· about 6 hours ago
FusionAuth logo

FusionAuth

Principal Software Engineer

Remote
Denver, CO$225k–$270k
✓ From careers page· about 6 hours ago

Discover More than 100,000 Hidden Remote Jobs Before Everyone Else

Unlock All Remote Jobs Today

Simple pricing. Big savings on Quarterly and Yearly.

Monthly Access

$19/month
  • Instant access to fresh remote jobs from 500+ companies
  • New opportunities added hourly, often 3-7 days before anywhere else
  • Advanced filtering by role type, stack, pay, and location
  • Priority customer support
Start 7-day trial — $2.95
Most Popular

Yearly Access

$59/year
  • Everything in Monthly
  • Save $169 (~74%) vs paying monthly
  • Average job search takes ~6 months - get covered for the whole journey
  • Less than the cost of one lunch per month for competitive advantage
  • Equivalent to just ~$4.92/month
Start 7-day trial — $2.95