Third Party Risk Analyst

AI model gateway and marketplace offering a unified API to access, route, and manage models from multiple providers.

Distributed
About OpenRouter

OpenRouter provides developers and businesses with a single, OpenAI-compatible API for hundreds of AI models. It supports provider failover, routing for price, latency and reliability, plus enterprise controls and observability.

View jobs by OpenRouter

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will build the vendor-risk function and conduct end-to-end security assessments for model providers, subprocessors, and SaaS vendors. You will evaluate security evidence, turn findings into risk decisions, establish TPRM processes, automate workflows, monitor critical vendors, and map vendor risk to compliance obligations.

Requirements

  • 4+ years in third-party or vendor security risk or security assessment
  • SOC 2
  • ISO 27001
  • HIPAA
  • GDPR
  • EU AI Act
  • Cloud architecture
  • Access model
  • Encryption
  • Data flow
  • DPA
  • BAA
  • Security exhibit
  • Written communication

Responsibilities

  • Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling
  • Review SOC 2, ISO reports, penetration tests, DPAs, and subprocessor lists
  • Turn findings into residual-risk and compensating-control decisions
  • Design and implement TPRM intake, tiering, SLAs, escalation, exceptions, and risk acceptance
  • Implement tooling integrated with Drata and ticketing
  • Build continuous monitoring and conduct annual vendor reviews
  • Map vendor risk to SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations
Third Party Risk Analyst at OpenRouter | JobStash