Third-Party Risk Analyst
Posted 1ds ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Third-Party Risk Analyst building OpenRouter’s vendor security program for AI infrastructure. Assessing model providers and subprocessors against security, privacy, and AI regulations.
Responsibilities:
- Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling
- Read and critically evaluate SOC 2 and ISO reports, including scope, carve-outs, CUECs, exceptions, testing, pen tests, DPAs, and subprocessor lists
- Turn findings into residual-risk decisions and compensating controls
- Design and establish the third-party risk management program, including intake, tiering, SLAs, escalation, exceptions, and risk acceptance
- Evaluate and implement tooling integrated with the Drata GRC stack and ticketing system
- Build continuous monitoring for critical vendors and run annual reviews
- Map vendor risk to SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations, including flow-down to subprocessors
Requirements:
- 4+ years in third-party/vendor security risk or security assessment
- Working fluency across SOC 2, ISO 27001, HIPAA, and GDPR
- Sufficient command of the EU AI Act to reason about its application
- Technical literacy in cloud architecture, access models, encryption, and data flows
- Comfort with DPAs, BAAs, and security exhibits
- Ability to pitch solutions and drive implementation independently
- Clear writing and high tolerance for ambiguity
- Nice to have: experience assessing AI/ML vendors or inference infrastructure
- Nice to have: ISO 42001 or NIST AI RMF experience
- Nice to have: scripting and automation experience
- Nice to have: GRC platform administration, such as Drata or Vanta
- Nice to have: early-stage startup experience building a function
- Nice to have: CISSP, CISA, CRISC, or CTPRP certification

















