Relomote
Remote JobsRelocation Jobs
Add companySaved
Relomote

Relomote is a job board for remote, hybrid, and relocation jobs — every listing AI-classified for the countries it actually hires from, or the visa and relocation support it offers.

LinkedInCrunchbase

Remote jobs by category

  • Remote Engineering & Development jobs
  • Remote Customer Support jobs
  • Remote Design jobs
  • Remote Marketing jobs
  • Remote Sales jobs
  • Remote Product jobs
  • Remote Data & Analytics jobs
  • Remote People & Talent jobs
  • Remote Writing & Content Creation jobs
  • Remote Finance jobs
  • Remote Legal & Compliance jobs
  • Remote Operations & Admin jobs
  • Remote Data Entry jobs
  • Remote Virtual Assistant jobs
  • Remote Education/Training jobs
  • Remote Healthcare/Clinical jobs
  • Remote Other jobs

Remote jobs by location

  • Work from anywhere jobs
  • Remote jobs in Africa
  • Remote jobs in Asia
  • Remote jobs in Europe
  • Remote jobs in Latin America
  • Remote jobs in Middle East
  • Remote jobs in North America
  • Remote jobs in Oceania
  • All remote jobs →

Relocation & visa sponsorship

  • Visa sponsorship jobs
  • Relocation package jobs
  • Relocate to Europe
  • Relocate to Germany
  • Relocate to Netherlands
  • Relocate to Spain
  • Relocate to Portugal
  • Relocate to Greece
  • Relocate to United Kingdom
  • Relocate to Canada
  • Relocate to Australia
  • Relocate to Sweden
  • Relocate to Switzerland
  • Relocate to Japan
  • Relocate to United Arab Emirates
  • All relocation jobs →

© 2026 RelomoteAboutPrivacyTerms

Contact [email protected] · Built by Mahmoud

Relomote
Remote JobsRelocation Jobs
Add companySaved
OpenRouter logo

Third-Party Risk Analyst

OpenRouter
Posted 4 hours ago
🇺🇸United States🏠Remote📁Legal & Compliance
Is this job info correct?

About OpenRouter OpenRouter is the AI routing and infrastructure layer that AI builders, AI-native startups, and enterprises use to access, manage, and optimize their AI usage through a unified API, billing interface, and analytics platform. We route billions of tokens every month and sit at the center of how organizations operationalize LLMs across research, product, and production workloads. We are a small team that punches above its weight. Every person here has direct impact on the product and our users. About the Role Most third-party risk roles hand you a mature program and ask you to keep the queue moving. This is the opposite. You'll be the first security risk analyst at OpenRouter, building the vendor risk function from a blank page. The vendors you assess aren't the usual SaaS sprawl — they're the model providers and subprocessors sitting directly in our customers' data path. And you'll do it in a regulatory environment still being written: there's no playbook for how the EU AI Act applies to an AI routing layer and its supply chain. You'll help write ours. If you've ever finished a vendor review and thought this should take a third as long and catch twice as much — and wanted to be the one to fix it — keep reading. What You'll Do Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling — and get vendors live without becoming the bottleneck. Read SOC 2 and ISO reports critically: scope, carve-outs, CUECs, exceptions, and whether the testing supports the opinion. Same for pen tests, DPAs, and subprocessor lists. Turn findings into decisions — residual risk and compensating controls, not a spreadsheet of yellow cells. Design and stand up the TPRM program: intake, tiering, SLAs, escalation, exceptions, and risk acceptance. Pitch and implement tooling that compresses time-to-close, integrated with our GRC stack (Drata) and ticketing. Build continuous monitoring for critical vendors and run annual reviews on a real cadence. Map vendor risk to our SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations, including flow-down to subprocessors. What We're Looking For 4+ years in third-party/vendor security risk or security assessment — real assessment reps, not just program administration. Working fluency across SOC 2, ISO 27001, HIPAA, and GDPR, plus enough command of the EU AI Act to reason about it rather than recite it. Technical literacy — cloud architecture, access models, encryption, data flows — enough to know when a vendor's answer doesn't hold up. Comfort with DPAs, BAAs, and security exhibits, and judgment about which clauses actually matter. A bias toward shipping. You'll pitch solutions and drive implementation yourself; nobody is going to manage your day. Clear writing and a high tolerance for ambiguity. When the precedent doesn't exist, you write the memo. Nice to Have Experience assessing AI/ML vendors or inference infrastructure ISO 42001 or NIST AI RMF Scripting and automation to eliminate your own toil GRC platform administration (Drata, Vanta, or similar) Time at an early-stage startup where you built the function rather than joined it CISSP, CISA, CRISC, or CTPRP. If you don't think you meet all of the criteria below but still are interested in the job, please apply. Nobody checks every box, and we're looking for someone who is excited to join the team.

Similar jobs

Similar jobs

FiveBy logo

Associate Risk Intelligence Analyst (Advanced fluency in both English and Mandarin Chinese)

FiveBy

🇺🇸United States3 hours ago
Becu logo

Sr Credit Risk Analyst

Becu

🇺🇸United States3 hours ago
Candidate Experience site logo

Third Party Risk Sr Analyst

Candidate Experience site

🇺🇸United States4 hours ago
Massgeneralbrigham logo

Risk Score Data Analyst

Massgeneralbrigham

🇺🇸United States19 hours ago
BILL logo

Risk Data Analyst, Staff

BILL

🇺🇸United States20 hours ago
First National Bank logo

Sr. Analyst, Operational Risk Management

First National Bank

🇺🇸United States20 hours ago