Third-Party Risk Analyst

Posted 1ds ago

Employment Information

Industry
Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Third-Party Risk Analyst building OpenRouter’s vendor security program for AI infrastructure. Assessing model providers and subprocessors against security, privacy, and AI regulations.

Responsibilities:

  • Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling
  • Read and critically evaluate SOC 2 and ISO reports, including scope, carve-outs, CUECs, exceptions, testing, pen tests, DPAs, and subprocessor lists
  • Turn findings into residual-risk decisions and compensating controls
  • Design and establish the third-party risk management program, including intake, tiering, SLAs, escalation, exceptions, and risk acceptance
  • Evaluate and implement tooling integrated with the Drata GRC stack and ticketing system
  • Build continuous monitoring for critical vendors and run annual reviews
  • Map vendor risk to SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations, including flow-down to subprocessors

Requirements:

  • 4+ years in third-party/vendor security risk or security assessment
  • Working fluency across SOC 2, ISO 27001, HIPAA, and GDPR
  • Sufficient command of the EU AI Act to reason about its application
  • Technical literacy in cloud architecture, access models, encryption, and data flows
  • Comfort with DPAs, BAAs, and security exhibits
  • Ability to pitch solutions and drive implementation independently
  • Clear writing and high tolerance for ambiguity
  • Nice to have: experience assessing AI/ML vendors or inference infrastructure
  • Nice to have: ISO 42001 or NIST AI RMF experience
  • Nice to have: scripting and automation experience
  • Nice to have: GRC platform administration, such as Drata or Vanta
  • Nice to have: early-stage startup experience building a function
  • Nice to have: CISSP, CISA, CRISC, or CTPRP certification