Skip to content

Third-Party Risk Analyst

Build and operate OpenRouter’s third-party risk program, assessing model providers, subprocessors, and SaaS vendors across security, privacy, and AI regulatory requirements. The role requires 4+ years of vendor security risk experience, technical fluency, and strong independent judgment.

About the job

Responsibilities

  • Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling, helping vendors go live without creating bottlenecks.
  • Critically review SOC 2 and ISO reports, including scope, carve-outs, complementary user entity controls (CUECs), exceptions, and testing support for the opinion.
  • Review penetration tests, data processing agreements (DPAs), and subprocessor lists.
  • Translate findings into residual-risk decisions and compensating controls.
  • Design and establish the third-party risk management (TPRM) program, including intake, tiering, SLAs, escalation, exceptions, and risk acceptance.
  • Select and implement tooling integrated with the Drata GRC platform and ticketing systems.
  • Build continuous monitoring for critical vendors and conduct annual reviews.
  • Map vendor risk to SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations, including flow-down requirements for subprocessors.

Requirements

  • 4+ years of experience in third-party/vendor security risk or security assessment.
  • Working fluency with SOC 2, ISO 27001, HIPAA, and GDPR, plus sufficient knowledge of the EU AI Act to apply it in practice.
  • Technical literacy in cloud architecture, access models, encryption, and data flows.
  • Comfort with DPAs, business associate agreements (BAAs), and security exhibits.
  • Ability to independently propose and implement solutions in an ambiguous, early-stage environment.
  • Clear writing and strong judgment.

Nice to Have

  • Experience assessing AI/ML vendors or inference infrastructure.
  • ISO 42001 or NIST AI RMF knowledge.
  • Scripting and automation experience.
  • GRC platform administration experience with Drata, Vanta, or similar tools.
  • Experience building a function at an early-stage startup.
  • CISSP, CISA, CRISC, or CTPRP certification.

Skills

Third-Party Risk Management, Security Assessments, SOC 2, ISO 27001, HIPAA, GDPR, Eu Ai Act, Cloud Architecture, Encryption, Data Flows, Drata, Scripting, Iso 42001, Nist Ai Rmf, Grc Platforms

OpenAI

OpenAI

San Francisco, CA

Software Engineer, HSM Infrastructure Security, Consumer Devices
$347k+/yrOn-site5+ YOESecurity Engineering

Design and ship security-critical software and firmware at the boundary between policy systems and hardware-backed cryptographic protection. The role requires 5+ years of secure embedded development and deep C, C++, or Rust experience.

Mercor

Mercor

San Francisco, CA
Security Engineer, Application Security
$130k+/yrOn-site5+ YOESecurity Engineering

Owns application security by embedding review workflows in SDLC, building SAST/DAST pipelines in CI/CD, managing vulnerability remediation, and operating bug bounty programs. Requires 5+ years experience finding/fixing vulnerabilities, strong skills in Python/TypeScript/Go, and SAST/DAST tooling.

Writer

Writer

New York, NY
Security Engineer, Application Security
$132k+/yrHybrid4+ YOESecurity Engineering

Build and scale application security for an enterprise AI platform, including threat modeling, secure architecture, automated controls, code review, and penetration testing. Requires at least four years of application security experience, programming expertise, and knowledge of DevSecOps and security-testing practices.

Ether.Fi

Ether.Fi

New York, NY
Fraud Engineer
No salary listedHybridSecurity Engineering

Own fraud monitoring, threat hunting, detection rules, scoring logic, and mitigation systems for Ether.fi’s financial products and card program. The role requires strong analytical pattern recognition, cross-functional ownership, and familiarity with payment or crypto fraud as a plus.

Stripe

Stripe

United States

Investigator
No salary listedRemote3+ YOESecurity Engineering

Investigates and responds to complex fraud and product-abuse incidents, analyzes high-risk accounts and threat patterns, and improves detection and response at scale. Requires 3+ years of incident response and data analysis experience, strong Python and SQL skills, and expertise in security investigations.