Third-Party Risk Analyst
Build a third-party risk program from scratch for AI model providers
As the first security risk analyst at OpenRouter, you will own end-to-end security assessments for model providers, subprocessors, and SaaS tooling. You will read SOC 2 and ISO reports critically, turn findings into risk decisions, and design and stand up the TPRM program including intake, tiering, SLAs, and risk acceptance. You will also build continuous monitoring for critical vendors and map vendor risk to SOC 2, ISO 27001, HIPAA, GDPR, and...
Why This Role?
Be the first to build the vendor risk function at an AI routing layer shaping how organizations use LLMs
Key Responsibilities
- Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling
- Read and critically evaluate SOC 2, ISO, pen test, DPA, and subprocessor reports
- Turn assessment findings into risk decisions with residual risk and compensating controls
- Design and implement the TPRM program including intake, tiering, SLAs, escalation, and exceptions
- Pitch and implement tooling to compress time-to-close, integrated with Drata and ticketing systems
- Build continuous monitoring for critical vendors and conduct annual reviews on a real cadence
Requirements
- 4+ years in third-party or vendor security risk or security assessment
- Working fluency across SOC 2, ISO 27001, HIPAA, and GDPR
- Ability to reason about the EU AI Act rather than just recite it
- Technical literacy in cloud architecture and access models
Required Skills
Indonesia Context
- Working Hours Overlap:
- Flexible — work your own hours
View Original Description from Ashby Job Boards
Original description from Ashby Job Boards
ABOUT OPENROUTER OpenRouter is the AI routing and infrastructure layer that AI builders, AI-native startups, and enterprises use to access, manage, and optimize their AI usage through a unified API, billing interface, and analytics platform. We route billions of tokens every month and sit at the center of how organizations operationalize LLMs across research, product, and production workloads. We are a small team that punches above its weight. Every person here has direct impact on the product and our users. ABOUT THE ROLE Most third-party risk roles hand you a mature program and ask you to keep the queue moving. This is the opposite. You'll be the first security risk analyst at OpenRouter, building the vendor risk function from a blank page. The vendors you assess aren't the usual SaaS sprawl — they're the model providers and subprocessors sitting directly in our customers' data path. And you'll do it in a regulatory environment still being written: there's no playbook for how the EU AI Act applies to an AI routing layer and its supply chain. You'll help write ours. If you've ever finished a vendor review and thought this should take a third as long and catch twice as much — and wanted to be the one to fix it — keep reading. WHAT YOU'LL DO - Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling — and get vendors live without becoming the bottleneck. - Read SOC 2 and ISO reports critically: scope, carve-outs, CUECs, exceptions, and whether the testing supports the opinion. Same for pen tests, DPAs, and subprocessor lists. - Turn findings into decisions — residual risk and compensating controls, not a spreadsheet of yellow cells. - Design and stand up the TPRM program: intake, tiering, SLAs, escalation, exceptions, and risk acceptance. - Pitch and implement tooling that compresses time-to-close, integrated with our GRC stack (Drata) and ticketing. - Build continuous monitoring for critical vendors and run annual reviews on a real cadence. - Map vendor risk to our SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations, including flow-down to subprocessors. WHAT WE'RE LOOKING FOR - 4+ years in third-party/vendor security risk or security assessment — real assessment reps, not just program administration. - Working fluency across SOC 2, ISO 27001, HIPAA, and GDPR, plus enough command of the EU AI Act to reason about it rather than recite it. - Technical literacy — cloud architecture, access models, encryption, data flows — enough to know when a vendor's answer doesn't hold up. - Comfort with DPAs, BAAs, and security exhibits, and judgment about which clauses actually matter. - A bias toward shipping. You'll pitch solutions and drive implementation yourself; nobody is going to manage your day. - Clear writing and a high tolerance for ambiguity. When the precedent doesn't exist, you write the memo. NICE TO HAVE - Experience assessing AI/ML vendors or inference infrastructure - ISO 42001 or NIST AI RMF - Scripting and automation to eliminate your own toil - GRC platform administration (Drata, Vanta, or similar) - Time at an early-stage startup where you built the function rather than joined it - CISSP, CISA, CRISC, or CTPRP. If you don't think you meet all of the criteria below but still are interested in the job, please apply. Nobody checks every box, and we're looking for someone who is excited to join the team.
Salary Context
Similar Data & Analytics roles on LokerDollar pay around $135k/yr (range $26.292k–999.999k/yr, n=95 active listings).
Hiring at OpenRouter
OpenRouter has 19 other active roles on LokerDollar and has been hiring here since Jul 3, 2026 — across Data & Analytics, Engineering, Marketing.
View all OpenRouter openings →Openness not stated by employer — check the listing
Frequently asked questions
- Is Third-Party Risk Analyst at OpenRouter a remote job?
- Yes. Third-Party Risk Analyst at OpenRouter is a fully remote role open to candidates worldwide.
- What type of employment is Third-Party Risk Analyst at OpenRouter?
- This is a full time position.
- How do I apply?
- Click the "Apply" button on this page to go to the official application at OpenRouter.
Explore related
Market data & reports
Salary & skill-demand research built from our own listings data.
- Indonesia IT Jobs vs Global Remote (2026)Primary analysis of 2,049 listings: methodology, classification rules, downloadable datasets.
- AI-Skill Demand: Indonesia vs Global Remote (2026)10,000+ postings, taxonomy-first classifier, Wilson CIs, pre-registered before analysis.
- Remote ≠ Remote: The Skills That Open Global Work to Indonesians (2026)12,891 remote listings: the highest-paid coding skills are the most geo-locked for Indonesia-based applicants. CC BY 4.0 aggregate dataset.
- Indonesia Hiring Report: Tech vs Non-TechJob demand by field from aggregate open-job counts — never individual listings.
- Indonesia Salary BenchmarkAggregate salary ranges across roles, with open methodology and dataset.
- Indonesian Remote Work Salary & Demand IndexHow much of the global remote job corpus is open to Indonesia, and what it pays (USD) by role.
- Indonesia Quarterly Labor Market ReportLayoffs, funding, salaries & skills per quarter — open aggregates.
- Remote Market Reports by RoleAuto-generated per role family — skills, seniority, companies, salary.
- Global Remote Salary BenchmarkAnnual salary by role & currency, plus the share of listings open worldwide.
From the blog
- Funding Down 43%, But Global Remote Jobs AreGlobal startup funding dipped 43% in H1 2026. Yet, top-tier global companies are aggressively hiring remote talent worldwide, paying in USD.
- The Rise of Mandarin and AI in Remote JobsAugust 2026 remote job trends: Mandarin skills in demand, AI jobs abound, but salary transparency is lacking.
- 7 Top Remote USD Jobs in August 2026Explore 7 high-paying remote USD jobs in August 2026, from AI to database roles, with salaries up to $325,000/year.