Build and own the vendor risk management program from scratch.
•You'll be the first security risk analyst at OpenRouter, building the vendor risk function from a blank page.
•The vendors you assess aren't the usual SaaS sprawl
•they're the model providers and subprocessors sitting directly in our customers' data path.
•And you'll do it in a regulatory environment still being written: there's no playbook for how the EU AI Act applies to an AI routing layer and its supply chain.
•You'll help write ours.
•Key Responsibilities Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling.
•Read SOC 2 and ISO reports critically.
•Design and stand up the TPRM program: intake, tiering, SLAs, escalation, exceptions, and risk acceptance.
•Map vendor risk to our SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations.
•Build continuous monitoring for critical vendors and run annual reviews.
•Requirements 4+ years in third-party/vendor security risk or security assessment.
•Working fluency across SOC 2, ISO 27001, HIPAA, and GDPR.
•Technical literacy
•cloud architecture, access models, encryption, data flows.
•Comfort with DPAs, BAAs, and security exhibits.
•A bias toward shipping and driving implementation yourself.