Third-Party Risk Analyst

OpenRouter, Inc

$110K — $130K *
US-AnywhereRemote in United States
Finance & Insurance
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 4+ years in third-party/vendor security risk or security assessment experience
  • Fluency in SOC 2, ISO 27001, HIPAA, GDPR, and theoretical understanding of the EU AI Act
  • Technical understanding of cloud architecture, access models, encryption, and data flows
  • Familiar with DPAs, BAAs, and important compliance clauses
  • Ability to self-manage projects and drive implementation without direct oversight
  • Strong writing skills and tolerance for dealing with ambiguity

Responsibilities

  • Own and streamline security assessments for model providers and subprocessors
  • Critically analyze SOC 2 and ISO reports for compliance and exceptions
  • Translate assessment findings into actionable risk decisions
  • Establish and manage the third-party risk management (TPRM) program framework
  • Propose and implement tooling to expedite vendor assessments and integrate with existing systems
  • Create continuous monitoring systems for high-risk vendors and conduct annual reviews
  • Align vendor risk management with regulatory obligations across multiple frameworks

Benefits

  • Flexible working environment
  • Opportunities for growth and innovation
  • Chance to build a new function from the ground up
  • Collaboration in a dynamic and evolving regulatory landscape
  • Engagement in cutting-edge AI routing technologies
Full Job Description
About the Role

Most third-party risk roles hand you a mature program and ask you to keep the queue moving. This is the opposite.

You'll be the first security risk analyst at OpenRouter, building the vendor risk function from a blank page. The vendors you assess aren't the usual SaaS sprawl - they're the model providers and subprocessors sitting directly in our customers' data path. And you'll do it in a regulatory environment still being written: there's no playbook for how the EU AI Act applies to an AI routing layer and its supply chain. You'll help write ours.

If you've ever finished a vendor review and thought this should take a third as long and catch twice as much - and wanted to be the one to fix it - keep reading.

What You'll Do
  • Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling - and get vendors live without becoming the bottleneck.
  • Read SOC 2 and ISO reports critically: scope, carve-outs, CUECs, exceptions, and whether the testing supports the opinion. Same for pen tests, DPAs, and subprocessor lists.
  • Turn findings into decisions - residual risk and compensating controls, not a spreadsheet of yellow cells.
  • Design and stand up the TPRM program: intake, tiering, SLAs, escalation, exceptions, and risk acceptance.
  • Pitch and implement tooling that compresses time-to-close, integrated with our GRC stack (Drata) and ticketing.
  • Build continuous monitoring for critical vendors and run annual reviews on a real cadence.
  • Map vendor risk to our SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations, including flow-down to subprocessors.


What We're Looking For
  • 4+ years in third-party/vendor security risk or security assessment - real assessment reps, not just program administration.
  • Working fluency across SOC 2, ISO 27001, HIPAA, and GDPR, plus enough command of the EU AI Act to reason about it rather than recite it.
  • Technical literacy - cloud architecture, access models, encryption, data flows - enough to know when a vendor's answer doesn't hold up.
  • Comfort with DPAs, BAAs, and security exhibits, and judgment about which clauses actually matter.
  • A bias toward shipping. You'll pitch solutions and drive implementation yourself; nobody is going to manage your day.
  • Clear writing and a high tolerance for ambiguity. When the precedent doesn't exist, you write the memo.


Nice to Have
  • Experience assessing AI/ML vendors or inference infrastructure
  • ISO 42001 or NIST AI RMF
  • Scripting and automation to eliminate your own toil
  • GRC platform administration (Drata, Vanta, or similar)
  • Time at an early-stage startup where you built the function rather than joined it
  • CISSP, CISA, CRISC, or CTPRP.


If you don't think you meet all of the criteria below but still are interested in the job, please apply. Nobody checks every box, and we're looking for someone who is excited to join the team.

Similar Jobs

More Jobs at OpenRouter, Inc

More Finance & Insurance Jobs

Find similar Third-Party Risk Analyst jobs: