Langsung ke konten utama
Kembali ke Lowongan

Third-Party Risk Analyst

Bangun program manajemen risiko vendor dari awal untuk OpenRouter

Kamu akan menjadi analis risiko keamanan pertama di OpenRouter, membangun program manajemen risiko vendor dari awal. Kamu akan menilai vendor seperti penyedia model dan subprosesor yang langsung terlibat dalam jalur data pelanggan. Kamu juga akan membantu menulis pedoman untuk penerapan EU AI Act pada lapisan routing AI dan rantai pasokannya.

Kenapa Menarik?

Kamu akan memiliki dampak langsung pada produk dan pengguna di tim kecil yang efisien

Tanggung Jawab Utama

  • Melakukan penilaian keamanan end-to-end untuk penyedia model, subprosesor, dan alat SaaS
  • Membaca laporan SOC 2 dan ISO secara kritis untuk menentukan skop, pengecualian, dan dukungan pengujian
  • Mengubah temuan menjadi keputusan tentang risiko sisa dan kontrol kompensasi
  • Membangun program TPRM termasuk intake, tiering, SLA, dan eskalasi
  • Mengimplementasikan alat yang mempersingkat waktu penutupan, terintegrasi dengan stack GRC dan tiket

Persyaratan

  • Pernah bekerja di bidang risiko keamanan vendor selama 4+ tahun
  • Memiliki pemahaman mendalam tentang SOC 2, ISO 27001, HIPAA, GDPR, dan EU AI Act
  • Memiliki literasi teknis dalam arsitektur cloud dan model akses

Skills Wajib

security risk assessmentsoc 2iso 27001gdprcloud architecture

Konteks Indonesia

Overlap Jam Kerja:
Fleksibel — atur jam kerjamu sendiri
Lihat selisih gaji remote (USD) vs lokal →
Lihat Deskripsi Asli dari Ashby Job Boards

Deskripsi asli dari Ashby Job Boards

ABOUT OPENROUTER OpenRouter is the AI routing and infrastructure layer that AI builders, AI-native startups, and enterprises use to access, manage, and optimize their AI usage through a unified API, billing interface, and analytics platform. We route billions of tokens every month and sit at the center of how organizations operationalize LLMs across research, product, and production workloads. We are a small team that punches above its weight. Every person here has direct impact on the product and our users. ABOUT THE ROLE Most third-party risk roles hand you a mature program and ask you to keep the queue moving. This is the opposite. You'll be the first security risk analyst at OpenRouter, building the vendor risk function from a blank page. The vendors you assess aren't the usual SaaS sprawl — they're the model providers and subprocessors sitting directly in our customers' data path. And you'll do it in a regulatory environment still being written: there's no playbook for how the EU AI Act applies to an AI routing layer and its supply chain. You'll help write ours. If you've ever finished a vendor review and thought this should take a third as long and catch twice as much — and wanted to be the one to fix it — keep reading. WHAT YOU'LL DO - Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling — and get vendors live without becoming the bottleneck. - Read SOC 2 and ISO reports critically: scope, carve-outs, CUECs, exceptions, and whether the testing supports the opinion. Same for pen tests, DPAs, and subprocessor lists. - Turn findings into decisions — residual risk and compensating controls, not a spreadsheet of yellow cells. - Design and stand up the TPRM program: intake, tiering, SLAs, escalation, exceptions, and risk acceptance. - Pitch and implement tooling that compresses time-to-close, integrated with our GRC stack (Drata) and ticketing. - Build continuous monitoring for critical vendors and run annual reviews on a real cadence. - Map vendor risk to our SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations, including flow-down to subprocessors. WHAT WE'RE LOOKING FOR - 4+ years in third-party/vendor security risk or security assessment — real assessment reps, not just program administration. - Working fluency across SOC 2, ISO 27001, HIPAA, and GDPR, plus enough command of the EU AI Act to reason about it rather than recite it. - Technical literacy — cloud architecture, access models, encryption, data flows — enough to know when a vendor's answer doesn't hold up. - Comfort with DPAs, BAAs, and security exhibits, and judgment about which clauses actually matter. - A bias toward shipping. You'll pitch solutions and drive implementation yourself; nobody is going to manage your day. - Clear writing and a high tolerance for ambiguity. When the precedent doesn't exist, you write the memo. NICE TO HAVE - Experience assessing AI/ML vendors or inference infrastructure - ISO 42001 or NIST AI RMF - Scripting and automation to eliminate your own toil - GRC platform administration (Drata, Vanta, or similar) - Time at an early-stage startup where you built the function rather than joined it - CISSP, CISA, CRISC, or CTPRP. If you don't think you meet all of the criteria below but still are interested in the job, please apply. Nobody checks every box, and we're looking for someone who is excited to join the team.

Konteks Gaji

Posisi Data & Analytics serupa di LokerDollar dibayar sekitar $128.75k/yr (kisaran $26.292k–999.999k/yr, dari 94 listing aktif).

Perekrutan di OpenRouter

OpenRouter punya 19 lowongan aktif lain di LokerDollar dan telah merekrut di sini sejak 3 Jul 2026 — di kategori Data & Analytics, Engineering, Marketing.

Lihat semua lowongan OpenRouter →

Pemberi kerja tidak menyatakan keterbukaan lokasi — cek langsung lowongannya

Perusahaan
OpenRouter
Sumber
Ashby Job Boards
Tipe Pekerjaan
full time
Lokasi
Remote · null
Level
mid
DipostingNewBaru & terverifikasi
11 Agu 2026

Bagikan lowongan ini

Bantu temanmu nemu kerja remote berikutnya.

Pertanyaan yang sering diajukan

Apakah Third-Party Risk Analyst di OpenRouter bisa dikerjakan remote?
Ya. Third-Party Risk Analyst di OpenRouter adalah posisi remote yang terbuka untuk kandidat di seluruh dunia.
Jenis pekerjaan apa Third-Party Risk Analyst di OpenRouter?
Posisi ini adalah pekerjaan full time.
Bagaimana cara melamar?
Klik tombol "Lamar" pada halaman ini untuk menuju halaman aplikasi resmi OpenRouter.

Jelajahi lebih lanjut

Data & laporan pasar

Riset gaji & permintaan skill dari data lowongan kami sendiri.

Dari blog kami