402,911open jobs
14,044companies
78,108added this week
Browse all
Location
Remote (United States)
Seniority
Middle · 4+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
The unified interface for LLMs. Find the best models & prices for your prompts

About OpenRouter

OpenRouter is the AI routing and infrastructure layer that AI builders, AI-native startups, and enterprises use to access, manage, and optimize their AI usage through a unified API, billing interface, and analytics platform. We route billions of tokens every month and sit at the center of how organizations operationalize LLMs across research, product, and production workloads.

We are a small team that punches above its weight. Every person here has direct impact on the product and our users.

About the Role

Most third-party risk roles hand you a mature program and ask you to keep the queue moving. This is the opposite.

You'll be the first security risk analyst at OpenRouter, building the vendor risk function from a blank page. The vendors you assess aren't the usual SaaS sprawl - they're the model providers and subprocessors sitting directly in our customers' data path. And you'll do it in a regulatory environment still being written: there's no playbook for how the EU AI Act applies to an AI routing layer and its supply chain. You'll help write ours.

If you've ever finished a vendor review and thought this should take a third as long and catch twice as much - and wanted to be the one to fix it - keep reading.

What You'll Do

  • Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling - and get vendors live without becoming the bottleneck.

  • Read SOC 2 and ISO reports critically: scope, carve-outs, CUECs, exceptions, and whether the testing supports the opinion. Same for pen tests, DPAs, and subprocessor lists.

  • Turn findings into decisions - residual risk and compensating controls, not a spreadsheet of yellow cells.

  • Design and stand up the TPRM program: intake, tiering, SLAs, escalation, exceptions, and risk acceptance.

  • Pitch and implement tooling that compresses time-to-close, integrated with our GRC stack (Drata) and ticketing.

  • Build continuous monitoring for critical vendors and run annual reviews on a real cadence.

  • Map vendor risk to our SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations, including flow-down to subprocessors.

What We're Looking For

  • 4+ years in third-party/vendor security risk or security assessment - real assessment reps, not just program administration.

  • Working fluency across SOC 2, ISO 27001, HIPAA, and GDPR, plus enough command of the EU AI Act to reason about it rather than recite it.

  • Technical literacy - cloud architecture, access models, encryption, data flows - enough to know when a vendor's answer doesn't hold up.

  • Comfort with DPAs, BAAs, and security exhibits, and judgment about which clauses actually matter.

  • A bias toward shipping. You'll pitch solutions and drive implementation yourself; nobody is going to manage your day.

  • Clear writing and a high tolerance for ambiguity. When the precedent doesn't exist, you write the memo.

Nice to Have

  • Experience assessing AI/ML vendors or inference infrastructure

  • ISO 42001 or NIST AI RMF

  • Scripting and automation to eliminate your own toil

  • GRC platform administration (Drata, Vanta, or similar)

  • Time at an early-stage startup where you built the function rather than joined it

  • CISSP, CISA, CRISC, or CTPRP.

If you don't think you meet all of the criteria below but still are interested in the job, please apply. Nobody checks every box, and we're looking for someone who is excited to join the team.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
402,911 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
Remote/Hybrid • 10+ years exp • Bachelor's Degree • Hyderabad
AI/ML
ISO 42001
DevOps
Incident Management
Cybersecurity
GDPR
HIPAA
ISO 27001
NIST 800-171
SOC 2
Apply
$81k – $193k per year (Estimated) • Remote/Hybrid • Master's Degree • London
Java
Python
AI/ML
AI Agents
Explainable AI
NLP
RAG
Cybersecurity
GDPR
Apply
Remote/Hybrid • 5+ years exp • Bachelor's Degree • Bucharest
DevOps
GitHub
Cybersecurity
GDPR
Marketing
LinkedIn
Apply
Remote/Hybrid • 5+ years exp • Bachelor's Degree • São Paulo
DevOps
GitHub
Cybersecurity
GDPR
Marketing
LinkedIn
Apply
In office • 1+ year exp
C++
SQL
Databases
PostgreSQL
DevOps
Red Hat
Cybersecurity
GDPR
Apply
$169k – $330k per year (Estimated) • Remote • Full-Time • 3+ years exp
AI/ML
OpenAI
OpenRouter
Management
Discord
Marketing
Reddit
X (Twitter)
Apply
Data Scientist 24 days ago
$180k – $240k per year • Remote • Full-Time • 4+ years exp
Python
SQL
TypeScript
Databases
ClickHouse
Google BigQuery
AI/ML
AI Agents
dbt
Embeddings
LLM
NLP
OpenRouter
Prompt Engineering
Human-in-the-Loop
LLM Guardrails
Model Context Protocol
Apply
Customer Engineer 30 days ago
$160k – $190k per year • Remote • Full-Time • 5+ years exp
AI/ML
LLM
OpenRouter
Apply
$210k – $240k per year • Remote • Full-Time • 10+ years exp
AI/ML
AI Agents
OpenAI
OpenRouter
Apply
$148k – $342k per year (Estimated) • Remote • Full-Time
AI/ML
OpenRouter
Marketing
Salesforce
Apply
See all jobs
This is one of many
402,911 more open roles from verified company boards, updated every day.