SlipstreamJobsFresh Startup & VC-Backed Jobs

Third-Party Risk Analyst

OpenRouter - Remote - Remote - posted 2026-08-11

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

OpenRouter is building the AI routing and infrastructure layer that powers how organizations operationalize large language models at scale. The company routes billions of tokens monthly and sits at the center of AI infrastructure for research, product, and production workloads. You'll be the first security risk analyst at OpenRouter, building the vendor risk management function from scratch. Unlike mature TPRM programs, you'll have the opportunity to design and implement a best-in-class program tailored to the unique challenges of AI infrastructure. Your vendors aren't typical SaaS tools—they're model providers and subprocessors sitting directly in customers' data paths, operating in a regulatory environment still being written (EU AI Act, HIPAA, GDPR, SOC 2, ISO 27001). Key responsibilities include: conducting end-to-end security assessments for model providers, subprocessors, and SaaS vendors; critically evaluating SOC 2, ISO, pen test, and DPA documentation; translating findings into risk decisions and compensating controls; designing the TPRM program intake, tiering, SLAs, and escalation workflows; selecting and implementing GRC tooling (integrated with Drata); establishing continuous monitoring for critical vendors; and mapping vendor risk to regulatory obligations including EU AI Act flow-down requirements. You'll need 4+ years of hands-on third-party/vendor security risk assessment experience (not just program administration), working fluency with SOC 2, ISO 27001, HIPAA, and GDPR, technical literacy in cloud architecture and data flows, comfort with DPAs and security exhibits, and a bias toward shipping solutions. Nice-to-haves include AI/ML vendor assessment experience, ISO 42001 or NIST AI RMF knowledge, scripting/automation skills, GRC platform administration, early-stage startup experience, and relevant certifications (CISSP, CISA, CRISC, CTPRP).

Similar roles