Third Party Risk Analyst Jobs

32 jobs found — updated daily

About The Position

OpenRouter is seeking the first security risk analyst to build the vendor risk function from the ground up. This role will focus on assessing model providers and subprocessors that are critical to customer data paths, operating within a novel regulatory environment, particularly concerning the EU AI Act. The ideal candidate will have a strong background in security risk assessments and a desire to innovate and improve the efficiency and effectiveness of vendor risk management processes.

Requirements

  • 4+ years of experience in third-party/vendor security risk or security assessment, with a focus on performing actual assessments rather than just program administration.
  • Working fluency in SOC 2, ISO 27001, HIPAA, and GDPR.
  • Sufficient understanding of the EU AI Act to reason about its application.
  • Technical literacy in areas such as cloud architecture, access models, encryption, and data flows to evaluate vendor responses effectively.
  • Comfort with Data Processing Agreements (DPAs), Business Associate Agreements (BAAs), and security exhibits, with the ability to discern the importance of specific clauses.
  • A proactive approach to implementation and problem-solving, with the ability to drive initiatives independently.
  • Excellent written communication skills and a high tolerance for ambiguity, with the ability to document and create precedent when necessary.

Nice To Haves

  • Experience assessing AI/ML vendors or inference infrastructure.
  • Familiarity with ISO 42001 or NIST AI RMF.
  • Scripting and automation skills to improve efficiency.
  • Experience with GRC platform administration (e.g., Drata, Vanta).
  • Experience at an early-stage startup, specifically in building a function from scratch.
  • Relevant certifications such as CISSP, CISA, CRISC, or CTPRP.

Responsibilities

  • Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling, ensuring vendors are onboarded efficiently without becoming a bottleneck.
  • Critically review SOC 2 and ISO reports, including scope, carve-outs, CUECs, exceptions, and the validity of testing supporting the opinion. Also review pen tests, DPAs, and subprocessor lists.
  • Translate assessment findings into actionable decisions, focusing on residual risk and compensating controls rather than simply documenting issues.
  • Design and implement the Third-Party Risk Management (TPRM) program, including intake processes, vendor tiering, Service Level Agreements (SLAs), escalation procedures, exception handling, and risk acceptance.
  • Propose and implement tooling to reduce assessment closure times, integrating with the existing GRC stack (Drata) and ticketing systems.
  • Establish continuous monitoring for critical vendors and manage annual review cadences.
  • Map vendor risks to OpenRouter's compliance obligations, including SOC 2, ISO 27001, HIPAA, GDPR, and the EU AI Act, ensuring these obligations flow down to subprocessors.

Build a Resume for Third Party Risk Analyst

The resume builder that gets results.

  • Get clear feedback so you look as qualified as you are
  • Align your resume with the job to get further in the process, faster
  • Take the guesswork out of resume writing

Explore Related Job Searches

Frequently Asked Questions

Common questions about Third Party Risk Analyst careers and jobs.

Based on current job postings on Teal, the average Third Party Risk Analyst salary in the US is approximately $86,000 per year, with a typical range of $45,000 to $132,000.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service