Listed on OpenRouter’s own careers site. You apply with them directly — we never stand between you and the employer.
What this role is
OpenRouter is looking for their first vendor risk analyst to build a third-party risk program from the ground up, focusing on assessing AI model providers and infrastructure partners in a rapidly evolving regulatory landscape. This role suits someone who wants autonomy to design efficient risk processes and implement tooling rather than maintain an existing program.
Our summary, not OpenRouter’s wording. The full posting is on their site.
What they ask for
Required
- 4+ years in third-party or vendor security risk assessment
- Working knowledge of SOC 2, ISO 27001, HIPAA, and GDPR
- Technical literacy in cloud architecture, access models, encryption, and data flows
- Ability to evaluate DPAs, BAAs, and security exhibits
- Self-directed execution and ability to drive implementation
- Clear writing and comfort with regulatory ambiguity
Nice to have
- Experience assessing AI/ML vendors or inference infrastructure
- ISO 42001 or NIST AI RMF knowledge
- Scripting and automation skills
- GRC platform administration experience
- Background building functions at early-stage startups
- CISSP, CISA, CRISC, or CTPRP certification