# Third-Party Risk Analyst

**Company:** [OpenRouter](https://hotfix.jobs/companies/openrouter)
**Location:** Remote
**Role:** Security Engineering
**Experience:** 4+ years
**Skills:** third-party risk management, security assessments, SOC 2, ISO 27001, HIPAA, GDPR, eu ai act, cloud architecture, encryption, data flows, drata, Scripting, iso 42001, nist ai rmf, grc platforms
**Posted:** 2026-08-11

> Build and operate OpenRouter’s third-party risk program, assessing model providers, subprocessors, and SaaS vendors across security, privacy, and AI regulatory requirements. The role requires 4+ years of vendor security risk experience, technical fluency, and strong independent judgment.

## Job Description

## Responsibilities
- Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling, helping vendors go live without creating bottlenecks.
- Critically review SOC 2 and ISO reports, including scope, carve-outs, complementary user entity controls (CUECs), exceptions, and testing support for the opinion.
- Review penetration tests, data processing agreements (DPAs), and subprocessor lists.
- Translate findings into residual-risk decisions and compensating controls.
- Design and establish the third-party risk management (TPRM) program, including intake, tiering, SLAs, escalation, exceptions, and risk acceptance.
- Select and implement tooling integrated with the Drata GRC platform and ticketing systems.
- Build continuous monitoring for critical vendors and conduct annual reviews.
- Map vendor risk to SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations, including flow-down requirements for subprocessors.

## Requirements
- 4+ years of experience in third-party/vendor security risk or security assessment.
- Working fluency with SOC 2, ISO 27001, HIPAA, and GDPR, plus sufficient knowledge of the EU AI Act to apply it in practice.
- Technical literacy in cloud architecture, access models, encryption, and data flows.
- Comfort with DPAs, business associate agreements (BAAs), and security exhibits.
- Ability to independently propose and implement solutions in an ambiguous, early-stage environment.
- Clear writing and strong judgment.

## Nice to Have
- Experience assessing AI/ML vendors or inference infrastructure.
- ISO 42001 or NIST AI RMF knowledge.
- Scripting and automation experience.
- GRC platform administration experience with Drata, Vanta, or similar tools.
- Experience building a function at an early-stage startup.
- CISSP, CISA, CRISC, or CTPRP certification.

## Similar roles

- [Security Analyst, Third-Party Ecosystem Risk Management](https://hotfix.jobs/jobs/04d279a2-cca0-4b85-9c84-c8fb7b794013) - Plaid - New York, NY - $119k – $176k/yr
- [Manager, Security Operations](https://hotfix.jobs/jobs/0a4637da-6072-4ec3-a0a9-8b6d4a412d45) - Vanta - Remote - $178k – $209k/yr
- [Security Engineer](https://hotfix.jobs/jobs/1e77fe13-74e5-4087-ba99-691ee95d0e2a) - AlertMedia - Remote
- [Governance, Risk, and Compliance Manager](https://hotfix.jobs/jobs/5e407075-824a-4639-96f7-821772a6f497) - Decagon - San Francisco, CA - $190k – $275k/yr
- [AI Security Research & Red Team Engineer](https://hotfix.jobs/jobs/4134cbdd-6f89-4850-864d-7d93f5d3cb97) - Cloudflare - Austin, TX - $166k – $208k/yr

**Apply:** https://hotfix.jobs/jobs/04264cf4-1589-4c8e-a154-029c4db08751
**Canonical:** https://hotfix.jobs/jobs/04264cf4-1589-4c8e-a154-029c4db08751