SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
OpenRouter is the leading AI routing and infrastructure layer that enterprises use to access, manage, and optimize large language models across providers. As enterprise adoption of AI accelerates, OpenRouter sits at the center of how organizations operationalize LLMs across research, product, and production workloads.
You will own OpenRouter's compliance program day to day, reporting to the Head of IT & Security. This is a hands-on role where you'll build and run the program with minimal daily management oversight. You'll manage Drata and Safebase, maintain audit readiness across SOC 2, HIPAA, PCI DSS, GDPR, CCPA, BIPA, and the EU AI Act, and translate emerging AI regulation into operationalizable controls.
Key responsibilities include:
- Own Drata end to end: administration, integrations, monitoring test health, and manual evidence collection
- Curate the SafeBase knowledge base for sales self-service on customer security questionnaires, with escalation support
- Drive personnel compliance: policy acknowledgments, device compliance, and recurring security and compliance training
- Lead recurring ceremonies: user access reviews, penetration tests, BCDR and incident response tabletops, annual policy reviews, and risk assessments
- Work directly with Engineering on product-related compliance questions, from data handling to customer commitments
- Partner with HR, Legal, Customer Support, and Finance to integrate compliance into existing workflows
- Navigate novel regulatory requirements where established playbooks don't yet exist
The role emphasizes strategic building and hands-on execution. Success requires getting engineers mid-sprint to pull evidence, driving company-wide training completion, and building credibility so teams take your requests seriously. You'll be the person deciding what novel requirements actually mean for the business.
REQUIREMENTS:
- Several years of hands-on GRC or compliance experience; you've built and run programs, not just governed them
- At least one complete SOC 2 audit cycle owned end to end, from evidence through fieldwork
- Admin-level fluency in a compliance automation platform (Drata strongly preferred)
- Technical depth sufficient to hold substantive conversations with engineers about architecture and data flows
- Proven cross-functional influence without becoming the person everyone avoids
- Comfort navigating shifting requirements and situations without established precedent
NICE TO HAVE:
- PCI DSS experience in a startup environment
- HIPAA experience as a Business Associate
- EU AI Act or other emerging AI regulation experience
- CISA, CISSP, or CIPP certification
- First compliance hire experience
- Scripting capability for evidence collection