Third-Party Risk Analyst

OpenRouter
United States
Workplace: RemoteFull timeFunction: Legal, Risk & ComplianceExperience: 4+ yearsSkills: ["Clear writing","Judgment","Bias toward shipping","Working with ambiguity"]

Build OpenRouter’s vendor/third-party risk function from scratch as its first security risk analyst. Own end-to-end security assessments for model providers and subprocessors, critically review SOC 2/ISO artifacts and pen test/DPAs, and convert findings into residual risk and compensating controls. Stand up a TPRM program, integrate tooling with Drata and ticketing, and map vendor risk to SOC 2, ISO 27001, HIPAA, GDPR, and the EU AI Act.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
OpenRouter
OpenRouter
7 hours ago

Third-Party Risk Analyst

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 6 hours agoStatus: Live

Job Summary

Build OpenRouter’s vendor/third-party risk function from scratch as its first security risk analyst. Own end-to-end security assessments for model providers and subprocessors, critically review SOC 2/ISO artifacts and pen test/DPAs, and convert findings into residual risk and compensating controls. Stand up a TPRM program, integrate tooling with Drata and ticketing, and map vendor risk to SOC 2, ISO 27001, HIPAA, GDPR, and the EU AI Act.
Location: United States
Workplace: Remote
Employment Type: Full time
Job Function: Legal, Risk & Compliance
Seniority: Mid level

Key Responsibilities

  • •Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling so vendors can go live without becoming a bottleneck.
  • •Critically review SOC 2 and ISO reports (including scope, carve-outs, exceptions, and support for the opinion) and assess pen tests, DPAs, and subprocessor lists.
  • •Convert assessment findings into decisions via residual risk and compensating controls.
  • •Design and stand up a TPRM program including intake, tiering, SLAs, escalation, exceptions, and risk acceptance.
  • •Implement continuous monitoring and annual reviews; map vendor risk to SOC 2, ISO 27001, HIPAA, GDPR, and the EU AI Act with flow-down to subprocessors.

Key Requirements

  • •4+ years in third-party/vendor security risk or security assessment with hands-on assessment experience.
  • •Working fluency across SOC 2, ISO 27001, HIPAA, and GDPR, plus the ability to reason about the EU AI Act.
  • •Technical literacy across cloud architecture, access models, encryption, and data flows to validate vendor responses.
  • •Comfort reviewing DPAs/BAAs and security exhibits with judgment about which clauses matter.
  • •Strong writing skills and tolerance for ambiguity, with a willingness to build the function without being managed.
Experience:4+ yearsThird-party riskVendor securityGRCAI/ML vendorsInference infrastructure
Skills:Clear writingJudgmentBias toward shippingWorking with ambiguity
Certifications:CISSPCISACRISCCTPRP
Tech Stack:SOC 2ISO 27001HIPAAGDPREU AI ActDrata

Company Brief

OpenRouter
Provides a unified, standards-compatible API and marketplace to route requests to 400+ large language models and cloud hosts, optimizing for cost, performance, and reliability for developers and enterprises.
Industry: API Platforms
Company Size: Micro (1 to 10 employees)
Revenue: USD 1M to 5M
Growth: Scaleup
Valuation: USD 250M to 500M
Funding: Series A
Headquarters: New York, United States
Founded: 2023
WebsiteLinkedIn