Third-Party Risk Analyst

Job not on LinkedIn

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of OpenRouter

OpenRouter

1 - 10 employees

Founded 2023

💼 Consulting

📣 Marketing

🤖 Artificial Intelligence

Consulting • Marketing • Artificial Intelligence

OpenRouter is a platform providing a unified interface for interacting with various large language models (LLMs). It focuses on delivering better prices and uptime without the need for subscriptions. The platform supports multiple AI tasks and showcases models like Mistral Small 3 and DeepSeek R1 Distill Qwen 32B, which are designed for fast performance and high accuracy. OpenRouter also features gaming and coding tools that enhance usability across different sectors such as marketing, finance, and education.

📋 Description

• Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling • Read and critically evaluate SOC 2 and ISO reports, including scope, carve-outs, CUECs, exceptions, testing, pen tests, DPAs, and subprocessor lists • Turn findings into residual-risk decisions and compensating controls • Design and establish the third-party risk management program, including intake, tiering, SLAs, escalation, exceptions, and risk acceptance • Evaluate and implement tooling integrated with the Drata GRC stack and ticketing system • Build continuous monitoring for critical vendors and run annual reviews • Map vendor risk to SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations, including flow-down to subprocessors

🎯 Requirements

• 4+ years in third-party/vendor security risk or security assessment • Working fluency across SOC 2, ISO 27001, HIPAA, and GDPR • Sufficient command of the EU AI Act to reason about its application • Technical literacy in cloud architecture, access models, encryption, and data flows • Comfort with DPAs, BAAs, and security exhibits • Ability to pitch solutions and drive implementation independently • Clear writing and high tolerance for ambiguity • Nice to have: experience assessing AI/ML vendors or inference infrastructure • Nice to have: ISO 42001 or NIST AI RMF experience • Nice to have: scripting and automation experience • Nice to have: GRC platform administration, such as Drata or Vanta • Nice to have: early-stage startup experience building a function • Nice to have: CISSP, CISA, CRISC, or CTPRP certification

Apply Now

Similar Jobs

🔥 5 hours ago

Paylocity

5001 - 10000

👥 HR Tech

☁️ SaaS

🤝 B2B

Senior Manager mitigating fraud across Paylocity’s cloud HR, payroll, and payments platforms. Leading investigators, detection systems, chargebacks, regulatory reporting, and cross-functional risk strategy.

🇺🇸 United States – Remote

💵 $118.1k - $140k / year

💰 $10M Venture Round - Paylocity on 2008-05

⏰ Full Time

🟠 Senior

🎲 Risk

🔥 14 hours ago

Extend

201 - 500

🛡️ Insurance

📦 Logistics

🛍️ eCommerce

Risk Analytics Manager pricing insurance risk for Extend’s AI-powered post-purchase platform. Owning pricing methodology, risk strategy, data foundations, and team development.

🔥 18 hours ago

Guild Mortgage

1001 - 5000

🏗️ Construction

💸 Finance

🏠 Real Estate

Senior Data Governance Analyst advancing governance for Guild Mortgage’s home-financing data platform. Managing metadata, data quality, lineage, PII controls, and governance automation across enterprise teams.

🔥 18 hours ago

Autodesk

10,000+ employees

🏗️ Construction

🏭 Manufacturing

💼 Consulting

Trust Risk Manager leading Autodesk’s enterprise security, privacy, AI, resilience, and third-party risk program. Modernizing risk operations with AI while guiding product and engineering teams.

🔥 21 hours ago

Fiserv

10,000+ employees

💼 Consulting

📦 Logistics

📣 Marketing

High-risk merchant sales specialist driving fintech payments growth for Fiserv. Building C-suite relationships, acquiring clients, and launching integrated acquiring, risk, and deposits solutions.