Third Party Risk Analyst
AI model gateway and marketplace offering a unified API to access, route, and manage models from multiple providers.
Funding history
Projects
About OpenRouter
OpenRouter provides developers and businesses with a single, OpenAI-compatible API for hundreds of AI models. It supports provider failover, routing for price, latency and reliability, plus enterprise controls and observability.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will build the vendor-risk function and conduct end-to-end security assessments for model providers, subprocessors, and SaaS vendors. You will evaluate security evidence, turn findings into risk decisions, establish TPRM processes, automate workflows, monitor critical vendors, and map vendor risk to compliance obligations.
Requirements
- 4+ years in third-party or vendor security risk or security assessment
- SOC 2
- ISO 27001
- HIPAA
- GDPR
- EU AI Act
- Cloud architecture
- Access model
- Encryption
- Data flow
- DPA
- BAA
- Security exhibit
- Written communication
Responsibilities
- Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling
- Review SOC 2, ISO reports, penetration tests, DPAs, and subprocessor lists
- Turn findings into residual-risk and compensating-control decisions
- Design and implement TPRM intake, tiering, SLAs, escalation, exceptions, and risk acceptance
- Implement tooling integrated with Drata and ticketing
- Build continuous monitoring and conduct annual vendor reviews
- Map vendor risk to SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations
