# Third-Party Risk Analyst

Hiring organization: [OpenRouter](https://career.thegoodapps.co/organizations/openrouter)

Canonical page: https://career.thegoodapps.co/jobs/447a6081-5cf8-4429-89e1-4fede825aff8

Listed on OpenRouter's own careers site. Applications go to them directly.

- Seniority: Mid
- Location: Remote (US)
- Remote: yes

## Summary

OpenRouter is looking for their first vendor risk analyst to build a third-party risk program from the ground up, focusing on assessing AI model providers and infrastructure partners in a rapidly evolving regulatory landscape. This role suits someone who wants autonomy to design efficient risk processes and implement tooling rather than maintain an existing program.

_Our summary, not OpenRouter's wording._

## Skills named

GDPR, HIPAA

## Required

- 4+ years in third-party or vendor security risk assessment
- Working knowledge of SOC 2, ISO 27001, HIPAA, and GDPR
- Technical literacy in cloud architecture, access models, encryption, and data flows
- Ability to evaluate DPAs, BAAs, and security exhibits
- Self-directed execution and ability to drive implementation
- Clear writing and comfort with regulatory ambiguity

## Nice to have

- Experience assessing AI/ML vendors or inference infrastructure
- ISO 42001 or NIST AI RMF knowledge
- Scripting and automation skills
- GRC platform administration experience
- Background building functions at early-stage startups
- CISSP, CISA, CRISC, or CTPRP certification

Apply on OpenRouter's site: https://jobs.ashbyhq.com/openrouter/99aa680f-19e2-49f1-acd5-b56c4aaa679f/application
