Назад
Company hidden
2 дня назад

Security Risk Analyst (AI)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Risk Analyst (AI): Building OpenRouter's third-party risk management function for model providers, subprocessors, and SaaS vendors with an accent on security assessments, regulatory mapping, and risk-based decision-making. Focus on designing TPRM workflows, critically reviewing SOC 2 and ISO 27001 evidence, implementing GRC automation, and addressing vendor risk across AI infrastructure and data flows.

Location: Remote (US)

Company

hirify.global provides an AI routing and infrastructure layer for accessing, managing, and optimizing AI usage through a unified API, billing interface, and analytics platform.

What you will do

  • Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling.
  • Critically review SOC 2 and ISO reports, penetration tests, DPAs, and subprocessor lists.
  • Evaluate residual risk, compensating controls, exceptions, and risk acceptance decisions.
  • Design and implement the third-party risk management program, including intake, tiering, SLAs, escalation, and annual reviews.
  • Implement tooling integrated with Drata and ticketing systems to reduce assessment time.
  • Build continuous monitoring for critical vendors and map vendor risk to compliance obligations.

Requirements

  • 4+ years of experience in third-party/vendor security risk or security assessments.
  • Working fluency with SOC 2, ISO 27001, HIPAA, and GDPR, plus practical knowledge of the EU AI Act.
  • Technical literacy in cloud architecture, access models, encryption, and data flows.
  • Experience with DPAs, BAAs, and security exhibits, including the ability to assess material contract clauses.
  • Strong writing skills, independent execution, and comfort working with ambiguity.
  • Must be based in the United States for this remote role.

Nice to have

  • Experience assessing AI/ML vendors or inference infrastructure.
  • ISO 42001 or NIST AI RMF experience.
  • Scripting and automation experience.
  • GRC platform administration experience with Drata, Vanta, or similar tools.
  • Early-stage startup experience or CISSP, CISA, CRISC, or CTPRP certification.

Culture & Benefits

  • Small team with direct individual impact on the product and users.
  • Bias toward shipping and independently driving implementation.
  • Opportunity to build a security risk function from the ground up in an evolving AI regulatory environment.
  • Full-time remote employment in the United States.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →