# Third-Party Risk Analyst at OpenRouter

- Company: OpenRouter
- What the company does: The unified interface for every model. Find the best models & prices for your prompts. Backed by a16z and Menlo.
- Company website: https://openrouter.ai
- Type: Startups (AI role)
- Level: Analyst
- Location: Remote (US)
- Work setup: Remote
- Posted: 2026-08-11
- Apply by: 2026-10-08
- Apply: https://jobs.ashbyhq.com/openrouter/99aa680f-19e2-49f1-acd5-b56c4aaa679f
- Page: https://www.1752.vc/careers/jobs/openrouter-third-party-risk-analyst/

## About the role

Most third-party risk roles hand you a mature program and ask you to keep the queue moving. This is the opposite.

## What they're looking for

- 4+ years in third-party/vendor security risk or security assessment — real assessment reps, not just program administration
- Working fluency across SOC 2, ISO 27001, HIPAA, and GDPR, plus enough command of the EU AI Act to reason about it rather than recite it
- Technical literacy — cloud architecture, access models, encryption, data flows — enough to know when a vendor's answer doesn't hold up
- Comfort with DPAs, BAAs, and security exhibits, and judgment about which clauses actually matter
- A bias toward shipping. You'll pitch solutions and drive implementation yourself, nobody is going to manage your day
- Clear writing and a high tolerance for ambiguity. When the precedent doesn't exist, you write the memo

Tags: Engineering
