Third-Party Risk Analyst
United States
Workplace: RemoteFull timeFunction: Legal, Risk & ComplianceExperience: 4+ yearsSkills: ["Clear writing","Judgment","Bias toward shipping","Working with ambiguity"]Build OpenRouter’s vendor/third-party risk function from scratch as its first security risk analyst. Own end-to-end security assessments for model providers and subprocessors, critically review SOC 2/ISO artifacts and pen test/DPAs, and convert findings into residual risk and compensating controls. Stand up a TPRM program, integrate tooling with Drata and ticketing, and map vendor risk to SOC 2, ISO 27001, HIPAA, GDPR, and the EU AI Act.
Loading
Loading job details...
Preparing the role view and application actions.

