Skip to main content
CareerApp

Third-Party Risk Analyst

OpenRouter

Remote (US) · Remote · Mid

Listed on OpenRouter’s own careers site. You apply with them directly — we never stand between you and the employer.

What this role is

OpenRouter is looking for their first vendor risk analyst to build a third-party risk program from the ground up, focusing on assessing AI model providers and infrastructure partners in a rapidly evolving regulatory landscape. This role suits someone who wants autonomy to design efficient risk processes and implement tooling rather than maintain an existing program.

Our summary, not OpenRouter’s wording. The full posting is on their site.

Skills this role names

Log in to see which of these are already on your profile.

What they ask for

Required

  • 4+ years in third-party or vendor security risk assessment
  • Working knowledge of SOC 2, ISO 27001, HIPAA, and GDPR
  • Technical literacy in cloud architecture, access models, encryption, and data flows
  • Ability to evaluate DPAs, BAAs, and security exhibits
  • Self-directed execution and ability to drive implementation
  • Clear writing and comfort with regulatory ambiguity

Nice to have

  • Experience assessing AI/ML vendors or inference infrastructure
  • ISO 42001 or NIST AI RMF knowledge
  • Scripting and automation skills
  • GRC platform administration experience
  • Background building functions at early-stage startups
  • CISSP, CISA, CRISC, or CTPRP certification

Turn on analytics and we load Google Analytics: Google gets the pages you open and what you do here — searches, jobs you view, jobs you apply to — and sets its own cookies. Leave it off and the only cookies we set are your login, your theme, and this answer. Accept All also records a yes to advertising, which nothing uses yet. Privacy Policy.