Build and operate OpenRouter’s third-party risk program, assessing model providers, subprocessors, and SaaS vendors across security, privacy, and AI regulatory requirements. The role requires 4+ years of vendor security risk experience, technical fluency, and strong independent judgment.
Salary not listed
Remote4+ YOESecurity Engineering
About the role
Responsibilities
Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling, helping vendors go live without creating bottlenecks.
Critically review SOC 2 and ISO reports, including scope, carve-outs, complementary user entity controls (CUECs), exceptions, and testing support for the opinion.
Review penetration tests, data processing agreements (DPAs), and subprocessor lists.
Translate findings into residual-risk decisions and compensating controls.
Design and establish the third-party risk management (TPRM) program, including intake, tiering, SLAs, escalation, exceptions, and risk acceptance.
Select and implement tooling integrated with the Drata GRC platform and ticketing systems.
Build continuous monitoring for critical vendors and conduct annual reviews.
Map vendor risk to SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations, including flow-down requirements for subprocessors.
Requirements
4+ years of experience in third-party/vendor security risk or security assessment.
Working fluency with SOC 2, ISO 27001, HIPAA, and GDPR, plus sufficient knowledge of the EU AI Act to apply it in practice.
Technical literacy in cloud architecture, access models, encryption, and data flows.
Comfort with DPAs, business associate agreements (BAAs), and security exhibits.
Ability to independently propose and implement solutions in an ambiguous, early-stage environment.
Clear writing and strong judgment.
Nice to Have
Experience assessing AI/ML vendors or inference infrastructure.
ISO 42001 or NIST AI RMF knowledge.
Scripting and automation experience.
GRC platform administration experience with Drata, Vanta, or similar tools.
Experience building a function at an early-stage startup.
CISSP, CISA, CRISC, or CTPRP certification.
Skills
third-party risk managementsecurity assessmentsSOC 2ISO 27001HIPAAGDPReu ai actcloud architectureencryptiondata flowsdrataScriptingiso 42001nist ai rmfgrc platforms
Conducts end-to-end security risk assessments for vendors, customers, and partners while maintaining risk tiering, remediation, reassessments, and reporting. The role also matures third-party risk processes and uses AI-assisted workflows to scale assessment operations.
119k – 176k/yrHybrid4+ YOESecurity Engineering
Manager, Security Operations
VantaUnited States
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.
178k – 209k/yrRemote5+ YOESecurity Engineering
Security Engineer
AlertMediaUnited States
Hands-on Security Engineer responsible for securing cloud applications and AWS infrastructure, strengthening detection and incident response, embedding controls into CI/CD, and supporting audits and enterprise customer security reviews. Requires 3+ years of security experience and practical AWS security expertise.
Salary not listedRemote3+ YOESecurity Engineering
Governance, Risk, and Compliance Manager
DecagonSan Francisco, CA
Manages Decagon’s governance, risk, and compliance program, including enterprise certifications, audit evidence, vendor risk, customer security assessments, and RFP responses. Requires 3–5 years of GRC experience, strong communication and project management skills, and familiarity with technical security controls and privacy regulations.
190k – 275k/yrOn-site5+ YOESecurity Engineering
AI Security Research & Red Team Engineer
CloudflareAustin, TX +1
Conducts AI-focused security research, agent and LLM testing, adversary simulation, and detection-efficacy validation. The role requires 4+ years of offensive or application security experience, strong penetration-testing or cloud-security fundamentals, and knowledge of AI attack vectors and MITRE ATT&CK.