Third-Party Risk Analyst
Bangun program manajemen risiko vendor dari awal untuk OpenRouter
Kamu akan menjadi analis risiko keamanan pertama di OpenRouter, membangun program manajemen risiko vendor dari awal. Kamu akan menilai vendor seperti penyedia model dan subprosesor yang langsung terlibat dalam jalur data pelanggan. Kamu juga akan membantu menulis pedoman untuk penerapan EU AI Act pada lapisan routing AI dan rantai pasokannya.
Kenapa Menarik?
Kamu akan memiliki dampak langsung pada produk dan pengguna di tim kecil yang efisien
Tanggung Jawab Utama
- Melakukan penilaian keamanan end-to-end untuk penyedia model, subprosesor, dan alat SaaS
- Membaca laporan SOC 2 dan ISO secara kritis untuk menentukan skop, pengecualian, dan dukungan pengujian
- Mengubah temuan menjadi keputusan tentang risiko sisa dan kontrol kompensasi
- Membangun program TPRM termasuk intake, tiering, SLA, dan eskalasi
- Mengimplementasikan alat yang mempersingkat waktu penutupan, terintegrasi dengan stack GRC dan tiket
Persyaratan
- Pernah bekerja di bidang risiko keamanan vendor selama 4+ tahun
- Memiliki pemahaman mendalam tentang SOC 2, ISO 27001, HIPAA, GDPR, dan EU AI Act
- Memiliki literasi teknis dalam arsitektur cloud dan model akses
Skills Wajib
Konteks Indonesia
- Overlap Jam Kerja:
- Fleksibel — atur jam kerjamu sendiri
Lihat Deskripsi Asli dari Ashby Job Boards
Deskripsi asli dari Ashby Job Boards
ABOUT OPENROUTER OpenRouter is the AI routing and infrastructure layer that AI builders, AI-native startups, and enterprises use to access, manage, and optimize their AI usage through a unified API, billing interface, and analytics platform. We route billions of tokens every month and sit at the center of how organizations operationalize LLMs across research, product, and production workloads. We are a small team that punches above its weight. Every person here has direct impact on the product and our users. ABOUT THE ROLE Most third-party risk roles hand you a mature program and ask you to keep the queue moving. This is the opposite. You'll be the first security risk analyst at OpenRouter, building the vendor risk function from a blank page. The vendors you assess aren't the usual SaaS sprawl — they're the model providers and subprocessors sitting directly in our customers' data path. And you'll do it in a regulatory environment still being written: there's no playbook for how the EU AI Act applies to an AI routing layer and its supply chain. You'll help write ours. If you've ever finished a vendor review and thought this should take a third as long and catch twice as much — and wanted to be the one to fix it — keep reading. WHAT YOU'LL DO - Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling — and get vendors live without becoming the bottleneck. - Read SOC 2 and ISO reports critically: scope, carve-outs, CUECs, exceptions, and whether the testing supports the opinion. Same for pen tests, DPAs, and subprocessor lists. - Turn findings into decisions — residual risk and compensating controls, not a spreadsheet of yellow cells. - Design and stand up the TPRM program: intake, tiering, SLAs, escalation, exceptions, and risk acceptance. - Pitch and implement tooling that compresses time-to-close, integrated with our GRC stack (Drata) and ticketing. - Build continuous monitoring for critical vendors and run annual reviews on a real cadence. - Map vendor risk to our SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations, including flow-down to subprocessors. WHAT WE'RE LOOKING FOR - 4+ years in third-party/vendor security risk or security assessment — real assessment reps, not just program administration. - Working fluency across SOC 2, ISO 27001, HIPAA, and GDPR, plus enough command of the EU AI Act to reason about it rather than recite it. - Technical literacy — cloud architecture, access models, encryption, data flows — enough to know when a vendor's answer doesn't hold up. - Comfort with DPAs, BAAs, and security exhibits, and judgment about which clauses actually matter. - A bias toward shipping. You'll pitch solutions and drive implementation yourself; nobody is going to manage your day. - Clear writing and a high tolerance for ambiguity. When the precedent doesn't exist, you write the memo. NICE TO HAVE - Experience assessing AI/ML vendors or inference infrastructure - ISO 42001 or NIST AI RMF - Scripting and automation to eliminate your own toil - GRC platform administration (Drata, Vanta, or similar) - Time at an early-stage startup where you built the function rather than joined it - CISSP, CISA, CRISC, or CTPRP. If you don't think you meet all of the criteria below but still are interested in the job, please apply. Nobody checks every box, and we're looking for someone who is excited to join the team.
Konteks Gaji
Posisi Data & Analytics serupa di LokerDollar dibayar sekitar $128.75k/yr (kisaran $26.292k–999.999k/yr, dari 94 listing aktif).
Perekrutan di OpenRouter
OpenRouter punya 19 lowongan aktif lain di LokerDollar dan telah merekrut di sini sejak 3 Jul 2026 — di kategori Data & Analytics, Engineering, Marketing.
Lihat semua lowongan OpenRouter →Pemberi kerja tidak menyatakan keterbukaan lokasi — cek langsung lowongannya
Pertanyaan yang sering diajukan
- Apakah Third-Party Risk Analyst di OpenRouter bisa dikerjakan remote?
- Ya. Third-Party Risk Analyst di OpenRouter adalah posisi remote yang terbuka untuk kandidat di seluruh dunia.
- Jenis pekerjaan apa Third-Party Risk Analyst di OpenRouter?
- Posisi ini adalah pekerjaan full time.
- Bagaimana cara melamar?
- Klik tombol "Lamar" pada halaman ini untuk menuju halaman aplikasi resmi OpenRouter.
Jelajahi lebih lanjut
Data & laporan pasar
Riset gaji & permintaan skill dari data lowongan kami sendiri.
- Lowongan IT Indonesia vs Remote Global (2026)Analisis data primer 2.049 lowongan: metodologi, klasifikasi, dataset bisa diunduh.
- Permintaan Skill AI: Indonesia vs Global (2026)10.000+ lowongan, classifier taxonomy-first, Wilson CI, pra-registrasi sebelum analisis.
- Remote ≠ Remote: Skill yang Membuka Kerja Global untuk Indonesia (2026)12.891 lowongan remote: skill coding bergaji tertinggi justru paling terkunci untuk pelamar Indonesia. Dataset agregat CC BY 4.0.
- Laporan Hiring Indonesia: Tech vs Non-TechPermintaan lowongan per bidang dari hitungan agregat — bukan listing per-listing.
- Benchmark Gaji IndonesiaKisaran gaji agregat lintas peran, dengan metodologi dan dataset terbuka.
- Indeks Gaji & Permintaan Kerja Remote untuk IndonesiaBerapa banyak lowongan remote global yang terbuka untuk Indonesia, dan gajinya (USD) per bidang.
- Laporan Kuartalan Pasar Kerja IndonesiaPHK, pendanaan, gaji & skill per kuartal — agregat terbuka.
- Laporan Pasar Remote per PeranLaporan otomatis per kelompok peran — skill, senioritas, perusahaan, gaji.
- Benchmark Gaji Remote GlobalGaji tahunan per bidang & mata uang, plus porsi lowongan terbuka untuk seluruh dunia.
Dari blog kami
- Lowongan Radiologi Remote: Update Ags 2026Analisis lowongan radiologi remote terbaru di Agustus 2026: gaji, tren, dan tips apply. Peluang kerja dokter spesialis radiologi remote.
- 3 Secret WebsitesTahu 3 situs rahasia untuk menghasilkan dolar dengan bekerja online.
- Funding Turun 43%, Malah Buka Lowongan?Pendanaan startup Indonesia turun 43% di H1 2026. Tapi perusahaan global justru buka lowongan remote untuk talenta Indonesia.